This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible rootkit infection [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

it was redirecting and running slow about 2 weeks ago and i took it to a local computer shop to check it out, he ran some programs and told me i have a rootkit, id like to make sure what he told me is either correct or incorrect.
Malwarebytes,spybot and superantispyware scans are clean, avast is also clean.
I also noticed in the logs that java is there, i uninstalled java about a month ago, but it is still there.
Thank you for any assistance.

OTL logfile created on: 1/26/2013 7:18:05 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\home\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.50 Gb Available Physical Memory | 66.76% Memory free
7.50 Gb Paging File | 6.14 Gb Available in Paging File | 81.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 921.72 Gb Total Space | 867.56 Gb Free Space | 94.12% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Windows\SysWOW64\AsHookDevice.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe (ASUSTeK Computer Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\ASUS\EPU-4 Engine\pngio.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Device Handle Service) – C:\Windows\SysWOW64\AsHookDevice.exe (ASUSTeK Computer Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (ahcix64s) – C:\Windows\SysNative\drivers\ahcix64s.sys (Advanced Micro Devices, Inc)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (netr28x) – C:\Windows\SysNative\drivers\netr28x.sys (Ralink Technology, Corp.)
DRV:64bit: - (AtiPcie) – C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASInsHelp) – C:\Windows\SysWOW64\drivers\AsInsHelp64.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value error.
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com/
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/11/04 19:42:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/01/18 18:58:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/10/26 21:52:57 | 000,000,000 | —D | M] (No name found) – C:\Users\home\AppData\Roaming\Mozilla\Extensions
[2012/11/29 13:14:43 | 000,000,000 | —D | M] (No name found) – C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\nbq0g91w.default-1351376498826\extensions
[2012/12/27 20:47:15 | 000,000,000 | —D | M] (No name found) – C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\r7alwd3i.Default User\extensions
[2012/12/27 20:47:15 | 000,804,627 | —- | M] () (No name found) – C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\r7alwd3i.Default User\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/11/29 13:06:04 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\Extensions
[2013/01/18 18:58:31 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

O1 HOSTS File: ([2013/01/25 12:21:03 | 000,445,430 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15296 more lines…
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5CD5CC2B-960F-4E87-B2FA-A1998EEF73A4}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (sdnclean64.exe)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/26 19:15:46 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\home\Desktop\OTL.exe
[2013/01/26 18:54:04 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/01/25 11:49:22 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/01/25 11:25:20 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/01/24 23:30:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/01/22 12:52:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2013/01/22 12:52:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2013/01/20 13:13:03 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX2
[2013/01/20 13:13:03 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonEPP
[2013/01/20 13:11:11 | 000,361,472 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMXLMAA.DLL
[2013/01/20 13:10:43 | 000,000,000 | —D | C] – C:\ProgramData\CanonIJMSetup
[2013/01/20 13:10:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP280 series User Registration
[2013/01/20 13:05:50 | 000,000,000 | —D | C] – C:\ProgramData\CanonIJWSpt
[2013/01/20 13:04:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2013/01/20 13:04:27 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/20 13:03:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP280 series Manual
[2013/01/20 13:03:47 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonBJ
[2013/01/20 13:03:41 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2013/01/20 13:03:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP280 series
[2013/01/20 13:03:36 | 001,354,240 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNC280C.dll
[2013/01/20 13:03:36 | 000,348,672 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNC280L.dll
[2013/01/20 13:03:36 | 000,307,200 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC280L.dll
[2013/01/20 13:03:36 | 000,112,128 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNC280I.dll
[2013/01/20 13:03:36 | 000,106,496 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC280U.dll
[2013/01/20 13:03:36 | 000,017,920 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNHMCA6.dll
[2013/01/20 13:03:36 | 000,015,872 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNHMCA.dll
[2013/01/20 13:03:27 | 000,361,472 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMLMAA.DLL
[2013/01/20 13:03:22 | 000,103,424 | —- | C] (Canon Inc.) – C:\Windows\SysNative\CNC280O.dll
[2013/01/20 13:03:18 | 000,248,320 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMIUAA.DLL
[2013/01/20 13:03:11 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/20 13:02:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2013/01/18 15:08:32 | 004,987,488 | —- | C] (Krzysztof Kowalczyk) – C:\Users\home\Desktop\SumatraPDF-2.2.1-install(1).exe
[2013/01/18 15:08:22 | 004,987,488 | —- | C] (Krzysztof Kowalczyk) – C:\Users\home\Desktop\SumatraPDF-2.2.1-install.exe
[2013/01/09 13:58:54 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/01/09 13:58:48 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/01/09 13:58:47 | 000,750,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/01/09 13:58:47 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/01/09 13:55:54 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/01/09 13:55:54 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/01/01 12:14:22 | 000,000,000 | —D | C] – C:\Users\home\Desktop\members
[2012/12/31 12:49:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\stinger
[2012/12/31 12:48:29 | 010,569,912 | —- | C] (McAfee Inc.) – C:\Users\home\Desktop\stinger.exe
[2012/12/29 08:37:25 | 000,000,000 | —D | C] – C:\Users\home\Desktop\Logos
[2012/12/29 08:35:41 | 000,000,000 | —D | C] – C:\Users\home\Desktop\Screenshots
[2012/12/29 08:26:00 | 000,000,000 | —D | C] – C:\Users\home\Desktop\PHPBB
[2012/12/27 23:28:58 | 000,000,000 | —D | C] – C:\Users\home\AppData\Roaming\JGsoft
[2012/12/27 23:28:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPad Lite
[2012/12/27 23:28:48 | 000,000,000 | —D | C] – C:\Program Files\Just Great Software

========== Files - Modified Within 30 Days ==========

[2013/01/26 19:16:36 | 000,625,664 | —- | M] () – C:\Users\home\Desktop\dds.scr
[2013/01/26 19:15:49 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\home\Desktop\OTL.exe
[2013/01/26 19:01:40 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/26 19:01:40 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/26 18:58:40 | 000,795,080 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/26 18:58:40 | 000,671,924 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/01/26 18:58:40 | 000,124,934 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/01/26 18:53:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/26 18:53:49 | 971,112,485 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/26 18:53:49 | 3019,247,616 | -HS- | M] () – C:\hiberfil.sys
[2013/01/26 11:11:14 | 000,000,512 | —- | M] () – C:\Users\home\Desktop\MBR.dat
[2013/01/25 12:21:03 | 000,445,430 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/01/22 12:54:07 | 000,445,430 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130125-122103.backup
[2013/01/22 12:52:29 | 000,001,286 | —- | M] () – C:\Users\home\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/01/22 12:52:29 | 000,001,262 | —- | M] () – C:\Users\home\Desktop\Spybot - Search & Destroy.lnk
[2013/01/20 13:05:50 | 000,002,079 | —- | M] () – C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
[2013/01/20 13:04:14 | 000,002,358 | —- | M] () – C:\Users\Public\Desktop\Canon MP280 series On-screen Manual.lnk
[2013/01/19 10:18:16 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/01/18 15:08:52 | 004,987,488 | —- | M] (Krzysztof Kowalczyk) – C:\Users\home\Desktop\SumatraPDF-2.2.1-install(1).exe
[2013/01/18 15:08:39 | 004,987,488 | —- | M] (Krzysztof Kowalczyk) – C:\Users\home\Desktop\SumatraPDF-2.2.1-install.exe
[2013/01/14 20:05:52 | 000,046,922 | —- | M] () – C:\Users\home\Desktop\business cards.jpg
[2013/01/11 13:31:03 | 000,445,126 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130122-125407.backup
[2013/01/09 15:18:07 | 000,274,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/09 14:11:03 | 000,788,804 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/09 13:55:54 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/01/09 13:55:54 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/01/04 11:12:38 | 000,001,700 | —- | M] () – C:\Users\home\Desktop\members3.rtf
[2013/01/03 18:13:22 | 000,000,284 | —- | M] () – C:\Users\home\Desktop\file.dat
[2013/01/01 16:10:42 | 000,445,068 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130111-133103.backup
[2013/01/01 12:37:43 | 000,445,068 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20130101-161042.backup
[2012/12/31 12:49:07 | 010,569,912 | —- | M] (McAfee Inc.) – C:\Users\home\Desktop\stinger.exe
[2012/12/30 10:03:59 | 000,007,375 | —- | M] () – C:\Users\home\Desktop\Paypal payment logo.jpg
[2012/12/30 10:02:24 | 000,027,276 | —- | M] () – C:\Users\home\Desktop\Paypal payment logo.GIF
[2012/12/30 09:56:34 | 000,004,435 | —- | M] () – C:\Users\home\Desktop\lunapic_13568831103297_1.gif
[2012/12/30 09:56:02 | 000,010,062 | —- | M] () – C:\Users\home\Desktop\Illustration.png(1).png
[2012/12/28 11:41:37 | 000,000,218 | —- | M] () – C:\Users\home\Desktop\colours.css
[2012/12/27 23:40:07 | 000,000,627 | —- | M] () – C:\Users\home\Desktop\stylesheet.css
[2012/12/27 23:28:49 | 000,001,620 | —- | M] () – C:\Users\Public\Desktop\EditPad Lite 7.lnk
[2012/12/27 22:38:20 | 000,006,585 | —- | M] () – C:\Users\home\Desktop\forms.css

========== Files Created - No Company Name ==========

[2013/01/26 19:16:34 | 000,625,664 | —- | C] () – C:\Users\home\Desktop\dds.scr
[2013/01/26 18:53:49 | 971,112,485 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/26 11:11:14 | 000,000,512 | —- | C] () – C:\Users\home\Desktop\MBR.dat
[2013/01/22 12:52:29 | 000,001,286 | —- | C] () – C:\Users\home\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2013/01/22 12:52:29 | 000,001,262 | —- | C] () – C:\Users\home\Desktop\Spybot - Search & Destroy.lnk
[2013/01/20 13:05:50 | 000,002,079 | —- | C] () – C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
[2013/01/20 13:04:14 | 000,002,358 | —- | C] () – C:\Users\Public\Desktop\Canon MP280 series On-screen Manual.lnk
[2013/01/20 13:03:36 | 000,012,800 | —- | C] () – C:\Windows\SysWow64\CNC1746D.TBL
[2013/01/20 13:03:36 | 000,012,800 | —- | C] () – C:\Windows\SysNative\CNC1746D.TBL
[2013/01/14 20:05:49 | 000,046,922 | —- | C] () – C:\Users\home\Desktop\business cards.jpg
[2013/01/04 11:12:35 | 000,001,700 | —- | C] () – C:\Users\home\Desktop\members3.rtf
[2013/01/03 18:13:18 | 000,000,284 | —- | C] () – C:\Users\home\Desktop\file.dat
[2012/12/30 10:03:48 | 000,007,375 | —- | C] () – C:\Users\home\Desktop\Paypal payment logo.jpg
[2012/12/30 10:00:05 | 000,027,276 | —- | C] () – C:\Users\home\Desktop\Paypal payment logo.GIF
[2012/12/30 09:56:32 | 000,004,435 | —- | C] () – C:\Users\home\Desktop\lunapic_13568831103297_1.gif
[2012/12/30 09:51:35 | 000,010,062 | —- | C] () – C:\Users\home\Desktop\Illustration.png(1).png
[2012/12/30 09:49:26 | 000,116,046 | —- | C] () – C:\Users\home\Desktop\illustration.png
[2012/12/27 23:42:30 | 000,000,218 | —- | C] () – C:\Users\home\Desktop\colours.css
[2012/12/27 23:40:07 | 000,000,627 | —- | C] () – C:\Users\home\Desktop\stylesheet.css
[2012/12/27 23:28:49 | 000,001,620 | —- | C] () – C:\Users\Public\Desktop\EditPad Lite 7.lnk
[2012/12/27 22:38:20 | 000,006,585 | —- | C] () – C:\Users\home\Desktop\forms.css
[2012/11/29 15:06:35 | 000,000,853 | —- | C] () – C:\Users\home\.recently-used.xbel
[2012/09/27 18:37:38 | 000,008,192 | —- | C] () – C:\Users\home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/24 05:53:25 | 000,788,804 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/21 20:15:03 | 000,013,368 | —- | C] () – C:\Windows\SysWow64\drivers\AsUpIO.sys
[2011/04/21 20:14:34 | 000,221,184 | —- | C] () – C:\Windows\SysWow64\drivers\ServiceHelp.dll
[2011/04/21 20:11:13 | 000,013,931 | —- | C] () – C:\Windows\SysWow64\RaCoInst.dat
[2011/04/21 20:10:57 | 000,013,440 | —- | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2011/04/21 20:10:56 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011/04/21 20:10:56 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011/04/21 20:07:31 | 000,024,078 | —- | C] () – C:\Windows\Ascd_log.ini
[2011/04/21 20:07:30 | 000,017,302 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2011/04/21 20:07:30 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2011/04/21 20:07:30 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2011/04/21 20:05:58 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/04/21 19:55:56 | 000,001,035 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 00:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/10/02 12:31:21 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\AnvSoft
[2012/12/29 15:18:23 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\FileZilla
[2012/12/27 23:28:58 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\JGsoft
[2013/01/17 20:34:36 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\SoftGrid Client
[2012/10/04 13:18:39 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\SumatraPDF
[2012/09/24 05:54:28 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\TP
[2012/09/27 11:56:39 | 000,000,000 | —D | M] – C:\Users\home\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 02:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 02:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 02:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 02:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 02:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Programme\Internet Explorer\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\erdnt\cache86\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2012/08/24 06:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/10/08 07:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/08/24 05:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010/11/20 22:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programme\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011/04/21 20:00:27 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2010/11/20 22:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2011/04/21 20:00:27 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/10/08 06:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011/04/21 20:01:06 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=0272AAC78F0D1CC205B893CCF5835DC5 – C:\Program Files (x86)\Internet Explorer\de-DE\iexplore.exe.mui
[2011/04/21 20:01:06 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=0272AAC78F0D1CC205B893CCF5835DC5 – C:\Programme\Internet Explorer\de-DE\iexplore.exe.mui
[2011/04/21 20:01:06 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=0272AAC78F0D1CC205B893CCF5835DC5 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_de-de_6865046bfd99819c\iexplore.exe.mui
[2011/04/21 20:00:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/04/21 20:00:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/04/21 20:01:20 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=490CD18CE5FB8C3CBFFD63A5314250D9 – C:\Program Files\Internet Explorer\es-ES\iexplore.exe.mui
[2011/04/21 20:01:20 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=490CD18CE5FB8C3CBFFD63A5314250D9 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_es-es_06cc8cf6b83dbd0b\iexplore.exe.mui
[2011/04/21 20:00:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/04/21 20:00:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Programme\Internet Explorer\en-US\iexplore.exe.mui
[2011/04/21 20:00:27 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2011/04/21 20:01:06 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=6D22C11D8D81000CAEA25B213F1CDD63 – C:\Program Files\Internet Explorer\de-DE\iexplore.exe.mui
[2011/04/21 20:01:06 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=6D22C11D8D81000CAEA25B213F1CDD63 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_de-de_5e105a19c938bfa1\iexplore.exe.mui
[2011/04/21 20:01:48 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=6F8514737B2AA1852BE2119407061300 – C:\Program Files\Internet Explorer\nl-NL\iexplore.exe.mui
[2011/04/21 20:01:48 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=6F8514737B2AA1852BE2119407061300 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nl-nl_c00d2171411ec76d\iexplore.exe.mui
[2011/04/21 20:01:48 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=822219278256AE31002C0B83610D4292 – C:\Program Files (x86)\Internet Explorer\nl-NL\iexplore.exe.mui
[2011/04/21 20:01:48 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=822219278256AE31002C0B83610D4292 – C:\Programme\Internet Explorer\nl-NL\iexplore.exe.mui
[2011/04/21 20:01:48 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=822219278256AE31002C0B83610D4292 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nl-nl_ca61cbc3757f8968\iexplore.exe.mui
[2011/04/21 20:01:34 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=B5ED0B02C0CF0B9B72801814688D5A00 – C:\Program Files\Internet Explorer\fr-FR\iexplore.exe.mui
[2011/04/21 20:01:34 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=B5ED0B02C0CF0B9B72801814688D5A00 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fr-fr_a98402f5ab0fd36d\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011/04/21 20:01:20 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=CF5D2D3D54DE91D2C66796D33E4D6431 – C:\Program Files (x86)\Internet Explorer\es-ES\iexplore.exe.mui
[2011/04/21 20:01:20 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=CF5D2D3D54DE91D2C66796D33E4D6431 – C:\Programme\Internet Explorer\es-ES\iexplore.exe.mui
[2011/04/21 20:01:20 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=CF5D2D3D54DE91D2C66796D33E4D6431 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_es-es_11213748ec9e7f06\iexplore.exe.mui
[2011/04/21 20:01:34 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=F19C598721DC3B8FC08EF800D7F9C1AF – C:\Program Files (x86)\Internet Explorer\fr-FR\iexplore.exe.mui
[2011/04/21 20:01:34 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=F19C598721DC3B8FC08EF800D7F9C1AF – C:\Programme\Internet Explorer\fr-FR\iexplore.exe.mui
[2011/04/21 20:01:34 | 000,006,144 | —- | M] (Microsoft Corporation) MD5=F19C598721DC3B8FC08EF800D7F9C1AF – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fr-fr_b3d8ad47df709568\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 02:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 02:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 02:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 02:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 02:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 02:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.SBS >
[2011/03/01 08:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy\Includes\Services.sbs
[2011/03/01 08:58:44 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Programme\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: WINLOGON.ADML >
[2010/11/21 02:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 22:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Programme\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 02:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 02:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 02:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 02:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2010/11/20 22:23:51 | 000,383,786 | R-S- | M] () – C:\bootmgr
[2011/03/15 16:24:15 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2013/01/26 18:53:49 | 3019,247,616 | -HS- | M] () – C:\hiberfil.sys
[2013/01/26 18:53:49 | 4025,667,584 | -HS- | M] () – C:\pagefile.sys
[2013/01/26 16:31:58 | 000,003,488 | —- | M] () – C:\TDSSKiller.2.8.15.0_26.01.2013_16.30.50_log.txt
[2013/01/26 16:37:39 | 000,910,494 | —- | M] () – C:\TDSSKiller.2.8.15.0_26.01.2013_16.33.58_log.txt
[2013/01/26 16:45:54 | 000,602,278 | —- | M] () – C:\TDSSKiller.2.8.15.0_26.01.2013_16.38.25_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/10/30 18:51:07 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/09/12 14:57:44 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/09/24 06:02:22 | 000,000,221 | -HS- | M] () – C:\Users\home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/10/04 21:08:43 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\home\Desktop\ATF-Cleaner.exe
[2012/10/02 09:05:58 | 003,782,822 | —- | M] (DownloadHelper ) – C:\Users\home\Desktop\ConvertHelperSetup.exe
[2012/09/24 06:58:33 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\home\Desktop\HijackThis.exe
[2013/01/26 19:15:49 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\home\Desktop\OTL.exe
[2012/10/02 17:27:20 | 005,563,840 | —- | M] (Microsoft Corporation) – C:\Users\home\Desktop\SkyDriveSetup.exe
[2012/12/31 12:49:07 | 010,569,912 | —- | M] (McAfee Inc.) – C:\Users\home\Desktop\stinger.exe
[2013/01/18 15:08:52 | 004,987,488 | —- | M] (Krzysztof Kowalczyk) – C:\Users\home\Desktop\SumatraPDF-2.2.1-install(1).exe
[2013/01/18 15:08:39 | 004,987,488 | —- | M] (Krzysztof Kowalczyk) – C:\Users\home\Desktop\SumatraPDF-2.2.1-install.exe
[2012/10/04 21:09:09 | 000,448,512 | —- | M] (OldTimer Tools) – C:\Users\home\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2011/12/19 02:04:46 | 000,000,698 | —- | M] () – C:\Windows\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 9/24/2012 6:25:31 AM
System Uptime: 1/26/2013 6:53:36 PM (1 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | CM1730,CM1830
Processor: AMD Athlon™ II X2 220 Processor | AM3 | 2800/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 922 GiB total, 866.875 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP86: 1/25/2013 11:39:16 AM - ComboFix created restore point
RP87: 1/25/2013 2:16:00 PM - Windows Update
RP88: 1/26/2013 11:18:53 AM - Installed Sophos Virus Removal Tool.
RP89: 1/26/2013 11:57:41 AM - Removed Sophos Virus Removal Tool.
.
==== Installed Programs ======================
.
.
Adobe Flash Player 11 Plugin
AI Manager
AMD USB Filter Driver
Any Video Converter 3.5.5
Apple Application Support
Apple Software Update
ASUS Backup Wizard
ASUSUpdate
AsusVibe2.0
avast! Free Antivirus
Canon Easy-PhotoPrint EX
Canon Easy-WebPrint EX
Canon MP Navigator EX 4.0
Canon MP280 series User Registration
Canon My Printer
Canon Solution Menu EX
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
D3DX10
EPU-4 Engine
FileZilla Client 3.6.0.2
Fotogalerie
Galerie de photos
Galería de fotos
Junk Mail filter update
Malwarebytes Anti-Malware version 1.65.1.1000
Microsoft Application Error Reporting
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Movie Maker
Mozilla Firefox 18.0.1 (x86 en-US)
MSVCRT
MSVCRT_amd64
MSVCRT110
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser (KB2721691)
MSXML 4.0 SP3 Parser (KB2758694)
MSXML 4.0 SP3 Parser (KB973685)
Photo Common
Photo Gallery
Platform
QuickTime
Ralink RT2860 Wireless LAN Card
Realtek Ethernet Controller Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Spybot - Search & Destroy
SpywareBlaster 4.6
SumatraPDF
VIA Platform Device Manager
Windows Live
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
1/26/2013 6:54:09 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000009f (0x0000000000000004, 0x0000000000000258, 0xfffffa80036dbb50, 0xfffff80000b9c510). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 012613-29250-01.
1/25/2013 2:12:51 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
1/25/2013 11:23:08 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
1/24/2013 11:33:19 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Installer service, but this action failed with the following error: An instance of the service is already running.
1/24/2013 11:31:22 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/24/2013 11:31:19 PM, Error: Service Control Manager [7034] - The Volume Shadow Copy service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:31:19 PM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/24/2013 11:31:19 PM, Error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
1/24/2013 11:31:19 PM, Error: Service Control Manager [7031] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
1/24/2013 11:31:19 PM, Error: Service Control Manager [7031] - The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
1/24/2013 11:31:19 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/24/2013 11:31:19 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/24/2013 11:27:47 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/24/2013 11:27:46 PM, Error: Service Control Manager [7034] - The Application Virtualization Client service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:46 PM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
1/24/2013 11:27:45 PM, Error: Service Control Manager [7034] - The MBAMScheduler service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:45 PM, Error: Service Control Manager [7034] - The Device Handle Service service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:45 PM, Error: Service Control Manager [7034] - The Client Virtualization Handler service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:45 PM, Error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:45 PM, Error: Service Control Manager [7034] - The Application Virtualization Service Agent service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:45 PM, Error: Service Control Manager [7034] - The AMD External Events Utility service terminated unexpectedly. It has done this 1 time(s).
1/24/2013 11:27:45 PM, Error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
1/24/2013 11:27:45 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/24/2013 11:27:45 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/22/2013 3:48:16 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
1/20/2013 8:33:06 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
.
==== End Of File ===========================



.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 19:18:30.07 on Sat 01/26/2013
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2512 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\AsHookDevice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\home\Desktop\OTL.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\home\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
mStart Page = hxxp://asus.msn.com
uInternet Settings,ProxyOverride = *.local
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
TB-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
EB-X64: {21347690-EC41-4F9A-8887-1F4AEE672439} - No File
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\r7alwd3i.Default User\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-10-30 370288]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-21 202752]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-10-30 71600]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-11-4 44808]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 Device Handle Service;Device Handle Service;C:\Windows\SysWOW64\AsHookDevice.exe [2011-4-21 203392]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-19 399432]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atipmdag.sys [2011-4-21 6368256]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2011-4-21 188416]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-19 25928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-4-21 406632]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2011-4-21 38456]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2011-4-21 1349232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-19 676936]
S3 ahcix64s;ahcix64s;C:\Windows\System32\drivers\ahcix64s.sys [2011-4-21 234040]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-9-25 57280]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2011-4-21 702976]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-24 1255736]
.
=============== Created Last 30 ================
.
2013-01-25 19:16:31 9161176 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{BD0407CC-94B2-4DCE-881E-722A5FBC9AD4}\mpengine.dll
2013-01-25 16:49:22 ——– d-sh–w- C:\$RECYCLE.BIN
2013-01-25 04:30:37 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-01-22 17:52:22 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-01-20 18:13:03 ——– d–h–w- C:\PROGRA~3\CanonIJEPPEX2
2013-01-20 18:13:03 ——– d–h–w- C:\PROGRA~3\CanonEPP
2013-01-20 18:11:11 361472 —-a-w- C:\Windows\System32\CNMXLMAA.DLL
2013-01-20 18:10:43 ——– d—–w- C:\PROGRA~3\CanonIJMSetup
2013-01-20 18:05:50 ——– d—–w- C:\PROGRA~3\CanonIJWSpt
2013-01-20 18:04:27 ——– d—–w- C:\Program Files\Canon
2013-01-20 18:02:11 ——– d—–w- C:\Program Files (x86)\Canon
2013-01-09 18:58:54 307200 —-a-w- C:\Windows\System32\ncrypt.dll
2013-01-09 18:58:54 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll
2013-01-09 18:58:52 2002432 —-a-w- C:\Windows\System32\msxml6.dll
2013-01-09 18:58:51 1882624 —-a-w- C:\Windows\System32\msxml3.dll
2013-01-09 18:58:51 1389568 —-a-w- C:\Windows\SysWow64\msxml6.dll
2013-01-09 18:58:51 1236992 —-a-w- C:\Windows\SysWow64\msxml3.dll
2013-01-09 18:58:48 68608 —-a-w- C:\Windows\System32\taskhost.exe
2013-01-09 18:58:47 750592 —-a-w- C:\Windows\System32\win32spl.dll
2013-01-09 18:58:47 492032 —-a-w- C:\Windows\SysWow64\win32spl.dll
2013-01-09 18:57:27 3149824 —-a-w- C:\Windows\System32\win32k.sys
2013-01-09 18:55:54 74248 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 18:55:54 697864 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-12-31 17:49:18 ——– d—–w- C:\Program Files (x86)\stinger
2012-12-28 04:28:58 ——– d—–w- C:\Users\home\AppData\Roaming\JGsoft
2012-12-28 04:28:48 ——– d—–w- C:\Program Files\Just Great Software
.
==================== Find3M ====================
.
2012-12-16 17:11:22 46080 —-a-w- C:\Windows\System32\atmlib.dll
2012-12-16 14:45:03 367616 —-a-w- C:\Windows\System32\atmfd.dll
2012-12-16 14:13:28 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-16 14:13:20 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll
2012-11-23 17:59:37 916456 —-a-w- C:\Windows\System32\deployJava1.dll
2012-11-23 17:59:37 1034216 —-a-w- C:\Windows\System32\npDeployJava1.dll
2012-11-16 07:34:48 821736 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-11-16 07:34:48 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2012-11-14 06:11:44 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 —-a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:52:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 02:09:22 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:44:42 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-09 05:45:09 2048 —-a-w- C:\Windows\System32\tzres.dll
2012-11-09 04:42:49 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2012-11-08 16:29:12 1402312 —-a-w- C:\Windows\SysWow64\msxml4.dll
2012-11-02 05:59:11 478208 —-a-w- C:\Windows\System32\dpnet.dll
2012-11-02 05:11:31 376832 —-a-w- C:\Windows\SysWow64\dpnet.dll
2012-10-30 23:51:55 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-10-30 23:51:55 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-10-30 23:51:07 41224 —-a-w- C:\Windows\avastSS.scr
.
============= FINISH: 19:19:15.44 ===============


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:23:02 PM, on 1/26/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\home\Desktop\OTL.exe
C:\Windows\SysWOW64\notepad.exe
C:\Windows\SysWOW64\notepad.exe
C:\Users\home\Desktop\HijackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Device Handle Service - ASUSTeK Computer Inc. - C:\Windows\SysWOW64\AsHookDevice.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 5851 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———
[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
# AdwCleaner v2.109 - Logfile created 01/27/2013 at 09:36:50 # Updated 26/01/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : home - HOME-PC # Boot Mode : Normal # Running from : C:\Users\home\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Mozilla Firefox v18.0.1 (en-US) File : C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\r7alwd3i.Default User\prefs.js [OK] File is clean. ************************* AdwCleaner[R4].txt - [797 octets] - [26/01/2013 19:56:34] AdwCleaner[R5].txt - [856 octets] - [27/01/2013 09:34:03] AdwCleaner[S3].txt - [788 octets] - [27/01/2013 09:36:50] ########## EOF - C:\AdwCleaner[S3].txt - [847 octets] ########## aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2013-01-27 09:40:33 —————————– 09:40:33.056 OS Version: Windows x64 6.1.7601 Service Pack 1 09:40:33.056 Number of processors: 2 586 0x603 09:40:33.056 ComputerName: HOME-PC UserName: home 09:40:36.956 Initialize success 09:40:37.049 AVAST engine defs: 13012700 09:40:47.470 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 09:40:47.470 Disk 0 Vendor: WDC_WD10EALX-229BA0 15.01H15 Size: 953869MB BusType: 3 09:40:47.486 Disk 0 MBR read successfully 09:40:47.501 Disk 0 MBR scan 09:40:47.501 Disk 0 unknown MBR code 09:40:47.517 Disk 0 Partition 1 00 1B Hidd FAT32 NTFS 10024 MB offset 2048 09:40:47.533 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 943842 MB offset 20531200 09:40:47.548 Disk 0 scanning C:\Windows\system32\drivers 09:40:54.397 Service scanning 09:41:09.919 Modules scanning 09:41:09.934 Disk 0 trace - called modules: 09:41:09.950 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys 09:41:09.950 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004590790] 09:41:10.496 3 CLASSPNP.SYS[fffff880018e243f] -> nt!IofCallDriver -> [0xfffffa80045902d0] 09:41:10.496 5 ACPI.sys[fffff88000f0f7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004588060] 09:41:14.380 AVAST engine scan C:\Windows 09:41:19.060 AVAST engine scan C:\Windows\system32 09:43:51.293 AVAST engine scan C:\Windows\system32\drivers 09:44:02.995 AVAST engine scan C:\Users\home 09:47:53.026 AVAST engine scan C:\ProgramData 09:48:47.250 Scan finished successfully 09:49:10.961 Disk 0 MBR has been saved successfully to "C:\Users\home\Desktop\MBR.dat" 09:49:10.971 The log file has been saved successfully to "C:\Users\home\Desktop\aswMBR.txt"
ComboFix

Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Sorry for the delay, Jeffce.. Here is the combofix log ComboFix 13-01-27.03 - home 01/27/2013 17:18:19.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2487 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-12-27 to 2013-01-27 ))))))))))))))))))))))))))))))) . . 2013-01-27 22:22 . 2013-01-27 22:22 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-25 19:16 . 2013-01-08 05:32 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BD0407CC-94B2-4DCE-881E-722A5FBC9AD4}\mpengine.dll 2013-01-25 04:30 . 2013-01-25 04:30 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2013-01-22 17:52 . 2013-01-22 17:53 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2013-01-20 18:13 . 2013-01-20 18:13 ——– d–h–w- c:\programdata\CanonIJEPPEX2 2013-01-20 18:13 . 2013-01-20 18:13 ——– d–h–w- c:\programdata\CanonEPP 2013-01-20 18:11 . 2010-08-25 10:00 361472 —-a-w- c:\windows\system32\CNMXLMAA.DLL 2013-01-20 18:10 . 2013-01-20 18:10 ——– d—–w- c:\programdata\CanonIJMSetup 2013-01-20 18:05 . 2013-01-20 18:05 ——– d—–w- c:\programdata\CanonIJWSpt 2013-01-20 18:04 . 2013-01-20 18:04 ——– d—–w- c:\program files\Canon 2013-01-20 18:02 . 2013-01-20 18:10 ——– d—–w- c:\program files (x86)\Canon 2013-01-09 18:58 . 2012-11-20 05:48 307200 —-a-w- c:\windows\system32\ncrypt.dll 2013-01-09 18:58 . 2012-11-20 04:51 220160 —-a-w- c:\windows\SysWow64\ncrypt.dll 2013-01-09 18:58 . 2012-11-01 05:43 2002432 —-a-w- c:\windows\system32\msxml6.dll 2013-01-09 18:58 . 2012-11-01 05:43 1882624 —-a-w- c:\windows\system32\msxml3.dll 2013-01-09 18:58 . 2012-11-01 04:47 1389568 —-a-w- c:\windows\SysWow64\msxml6.dll 2013-01-09 18:58 . 2012-11-01 04:47 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2013-01-09 18:58 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe 2013-01-09 18:58 . 2012-11-09 05:45 750592 —-a-w- c:\windows\system32\win32spl.dll 2013-01-09 18:58 . 2012-11-09 04:43 492032 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-01-09 18:57 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 18:55 . 2013-01-09 18:55 74248 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-01-09 18:55 . 2013-01-09 18:55 697864 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-31 17:49 . 2013-01-01 15:22 ——– d—–w- c:\program files (x86)\stinger . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-09 19:05 . 2012-09-24 11:12 67599240 —-a-w- c:\windows\system32\MRT.exe 2012-12-16 17:11 . 2012-12-21 12:03 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 12:03 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 12:03 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 12:03 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-11-23 17:59 . 2012-11-23 18:00 916456 —-a-w- c:\windows\system32\deployJava1.dll 2012-11-23 17:59 . 2012-11-23 18:00 1034216 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-11-16 07:34 . 2012-09-27 16:29 821736 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-11-16 07:34 . 2012-09-27 16:29 746984 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-11-14 07:06 . 2012-12-12 12:57 17811968 —-a-w- c:\windows\system32\mshtml.dll 2012-11-14 06:32 . 2012-12-12 12:57 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-11-14 06:11 . 2012-12-12 12:58 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 06:04 . 2012-12-12 12:58 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-11-14 06:04 . 2012-12-12 12:58 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 06:02 . 2012-12-12 12:58 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 06:02 . 2012-12-12 12:58 237056 —-a-w- c:\windows\system32\url.dll 2012-11-14 05:59 . 2012-12-12 12:58 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-11-14 05:58 . 2012-12-12 12:58 816640 —-a-w- c:\windows\system32\jscript.dll 2012-11-14 05:57 . 2012-12-12 12:58 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 05:57 . 2012-12-12 12:58 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 05:55 . 2012-12-12 12:58 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-11-14 05:55 . 2012-12-12 12:58 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-11-14 05:53 . 2012-12-12 12:58 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-11-14 05:52 . 2012-12-12 12:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-14 05:46 . 2012-12-12 12:58 248320 —-a-w- c:\windows\system32\ieui.dll 2012-11-14 02:09 . 2012-12-12 12:58 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-11-14 01:58 . 2012-12-12 12:58 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57 . 2012-12-12 12:58 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-11-14 01:49 . 2012-12-12 12:58 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48 . 2012-12-12 12:58 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-11-14 01:44 . 2012-12-12 12:58 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 12:56 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 12:56 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-11-08 16:29 . 2012-11-08 16:29 1402312 —-a-w- c:\windows\SysWow64\msxml4.dll 2012-11-02 05:59 . 2012-12-12 12:56 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-11-02 05:11 . 2012-12-12 12:56 376832 —-a-w- c:\windows\SysWow64\dpnet.dll 2012-10-30 23:51 . 2012-10-30 20:08 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-30 23:51 . 2012-10-30 20:08 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-30 23:51 . 2012-10-30 20:08 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-30 23:51 . 2012-10-30 20:08 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-30 23:51 . 2012-10-30 20:08 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-30 23:51 . 2012-10-30 20:08 41224 —-a-w- c:\windows\avastSS.scr 2012-10-30 23:50 . 2012-10-30 20:08 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-10-30 23:50 . 2012-10-30 20:08 285328 —-a-w- c:\windows\system32\aswBoot.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-10-22 13:31 220632 —-a-w- c:\users\home\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-10-22 13:31 220632 —-a-w- c:\users\home\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-10-22 13:31 220632 —-a-w- c:\users\home\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936] R3 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2009-11-10 234040] R3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2009-05-20 702976] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-24 1255736] S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-02-10 202752] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 Device Handle Service;Device Handle Service;c:\windows\SysWOW64\AsHookDevice.exe [2009-12-23 203392] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-10-26 406632] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-10-01 1349232] . . — Other Services/Drivers In Memory — . *Deregistered* - aswMBR . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] Hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2012-10-22 13:31 244696 —-a-w- c:\users\home\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2012-10-22 13:31 244696 —-a-w- c:\users\home\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2012-10-22 13:31 244696 —-a-w- c:\users\home\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 23:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://google.com/ mStart Page = hxxp://asus.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\home\AppData\Roaming\Mozilla\Firefox\Profiles\r7alwd3i.Default User\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://google.com/ FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2012-12-27 20:47; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\home\AppData\Roaming\Mozilla\Firefox\Profiles\r7alwd3i.Default User\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) SafeBoot-78180547.sys . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3787175316-1067705176-549167976-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3787175316-1067705176-549167976-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-01-27 17:24:13 ComboFix-quarantined-files.txt 2013-01-27 22:24 . Pre-Run: 930,461,872,128 bytes free Post-Run: 930,386,653,184 bytes free . - - End Of File - - 1C87E59B60F328E05BA296460B013AF8
[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Do you see anything at all in my system? 16:30:50.0501 3356 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 16:30:50.0844 3356 ============================================================ 16:30:50.0844 3356 Current date / time: 2013/01/26 16:30:50.0844 16:30:50.0844 3356 SystemInfo: 16:30:50.0844 3356 16:30:50.0844 3356 OS Version: 6.1.7601 ServicePack: 1.0 16:30:50.0844 3356 Product type: Workstation 16:30:50.0844 3356 ComputerName: HOME-PC 16:30:50.0844 3356 UserName: home 16:30:50.0844 3356 Windows directory: C:\Windows 16:30:50.0844 3356 System windows directory: C:\Windows 16:30:50.0844 3356 Running under WOW64 16:30:50.0844 3356 Processor architecture: Intel x64 16:30:50.0844 3356 Number of processors: 2 16:30:50.0844 3356 Page size: 0x1000 16:30:50.0844 3356 Boot type: Normal boot 16:30:50.0844 3356 ============================================================ 16:30:51.0781 3356 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 16:30:51.0813 3356 ============================================================ 16:30:51.0813 3356 \Device\Harddisk0\DR0: 16:30:51.0813 3356 MBR partitions: 16:30:51.0813 3356 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1394800, BlocksNum 0x73371000 16:30:51.0813 3356 ============================================================ 16:30:51.0844 3356 C: <-> \Device\Harddisk0\DR0\Partition1 16:30:51.0844 3356 ============================================================ 16:30:51.0844 3356 Initialize success 16:30:51.0844 3356 ============================================================ 16:31:58.0971 3592 Deinitialize success
Ok great! :thumbup:
———–

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
malwarebytes is clean and eset didnt find anything Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2013.01.28.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 home :: HOME-PC [administrator] 1/28/2013 10:59:53 AM mbam-log-2013-01-28 (10-59-53).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 206463 Time elapsed: 1 minute(s), 42 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI