This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP3 SP2 PC TOO sluggish for a Sailor on Memorial Day [Closed]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My trusty XP SP3 home computer is jammed to the brim with carp** from kids surfing and dad working. I have used the site before and know the ropes. Can an excellent volunteer lend a hand with this too slow machine. I will follow your instructions to the letter. Promise!
Hello, SkinnyTex . Posted Image

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
  • Please be patient. Logs are lengthy and can take time to analyze.
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • Use only those tools that you have been directed to use.
  • Do not install or uninstall any applications or run any other scans without being directed to do so.
  • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
  • Stay with me until your machine has been deemed to be all clear.
  • Please reply within 3 days of each posting to avoid closing this topic. If you need more time to complete tasks, or if you will be away, please let me know in advance.
Hello, SkinnyTex.

Please run the following scans and submit the reports in your next reply.

1. DDS

Please download DDS from HERE and save it to your desktop.Please copy and paste the scan results of DDS.txt.

Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
2. aswMBR

Please download aswMBR from HERE and save it to your Desktop..
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]

3. TDSSKiller

Please download TDSSKiller from HERE.
  • Extract its content to your desktop. (Right Click > Extract to your Desktop).
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application.
  • When the window opens, click Change Parameters.
  • Under Additional options, put a check mark in the box next to Detect TDLFS File System. Click OK.
  • Click Start Scan.
  • Choose Skip for whatever is found.
  • Click Continue > Reboot now.
Please copy and paste the contents of that file in your next reply.
Hello, SkinnyTex. Thanks for letting me know. I'll wait for your scans, and we can hopefully resolve your problems as quickly as possible.
DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.9.2 Run by [removed] at 4:49:10 on 2013-05-30 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.106 [GMT -5:00] . AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Disabled* . ============== Running Processes ================ . C:\Program Files\ActivIdentity\ActivClient\acevents.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe C:\WINDOWS\System32\SCardSvr.exe C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Java\jre7\bin\jqs.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\msdtc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVAST Software\Avast\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLA.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\AVAST Software\Avast\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\vssvc.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uURLSearchHooks: WinZipBar Toolbar: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - c:\program files\winzipbar\prxtbWin2.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - c:\program files\babylontoolbar\babylontoolbar\1.6.4.6\bh\BabylonToolbar.dll BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll BHO: WinZipBar Toolbar: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - c:\program files\winzipbar\prxtbWin2.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: AVG SafeGuard toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg safeguard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\program files\searchqu toolbar\datamngr\toolbar\searchqudtx.dll BHO: DataMngr: {9D717F81-9148-4f12-8568-69135F087DB0} - c:\program files\searchqu toolbar\datamngr\BrowserConnection.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll TB: WinZipBar Toolbar: {50FAFAF0-70A9-419D-A109-FA4B4FFD4E37} - c:\program files\winzipbar\prxtbWin2.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: : {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll TB: WinZipBar Toolbar: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - c:\program files\winzipbar\prxtbWin2.dll TB: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - c:\program files\babylontoolbar\babylontoolbar\1.6.4.6\BabylonToolbarTlbr.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\program files\searchqu toolbar\datamngr\toolbar\searchqudtx.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: AVG SafeGuard toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg safeguard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: militarycac.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces\{CF2C4811-4F7B-4420-9EF8-1374BACB62B6} : DHCPNameServer = 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\15.2.0\ViProtocol.dll Notify: ackpbsc - c:\program files\actividentity\activclient\ackpbsc.dll Notify: acunlock - c:\program files\actividentity\activclient\acunlock.dll AppInit_DLLs= c:\progra~1\search~1\datamngr\datamngr.dll c:\progra~1\search~1\datamngr\IEBHO.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\27.0.1453.94\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\admin john\application data\mozilla\firefox\profiles\z9680u01.default\ FF - prefs.js: browser.search.selectedEngine - Search Results FF - prefs.js: browser.startup.homepage - hxxp://www.searchnu.com/102 FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=102&sr=0&q= FF - plugin: c:\documents and settings\admin john\local settings\application data\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_287.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll FF - ExtSQL: !HIDDEN! 2012-10-14 08:50; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files\searchqu toolbar\datamngr\FirefoxExtension . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-13 612184] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-7-13 337880] R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-3-31 37664] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-7-13 20696] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-7-13 44768] R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 EZUSB;EZUSB PC/SC Smart Card Reader;c:\windows\system32\drivers\ezusb.sys [2008-6-3 63288] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\common files\actividentity\ac.sharedstore.exe [2009-6-3 207400] S4 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-11-9 160944] S4 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\15.2.0\ToolbarUpdater.exe [2013-5-21 1015984] . =============== Created Last 30 ================ . 2013-05-21 07:48:46 ——– d—–w- c:\windows\system32\cache . ==================== Find3M ==================== . 2013-05-21 07:48:02 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-05-15 13:45:31 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-05-15 13:45:31 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-04-16 22:17:15 920064 —-a-w- c:\windows\system32\wininet.dll 2013-04-16 22:17:14 43520 ——w- c:\windows\system32\licmgr10.dll 2013-04-16 22:17:14 1469440 ——w- c:\windows\system32\inetcpl.cpl 2013-04-12 23:28:55 385024 ——w- c:\windows\system32\html.iec 2013-04-12 08:01:23 1072544 —-a-w- c:\windows\system32\nvdrsdb0.bin 2013-04-12 08:01:23 1 —-a-w- c:\windows\system32\nvdrssel.bin 2013-04-12 08:01:19 1072544 —-a-w- c:\windows\system32\nvdrsdb1.bin 2013-04-10 01:31:19 1876352 —-a-w- c:\windows\system32\win32k.sys 2013-03-08 08:36:22 293376 —-a-w- c:\windows\system32\winsrv.dll 2013-03-07 01:28:24 2193408 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-07 00:50:28 2070016 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-07-13 10:43:22 4402855 —-a-w- c:\program files\setup.exe . ============= FINISH: 4:50:12.92 =============== 📎Attach.zip aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-05-30 04:57:29 —————————– 04:57:29.359 OS Version: Windows 5.1.2600 Service Pack 3 04:57:29.359 Number of processors: 1 586 0x7F02 04:57:29.359 ComputerName: JOHNS-E-MACHINE UserName: Admin John 04:57:30.125 Initialize success 04:57:32.093 AVAST engine defs: 13052901 04:57:38.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path1Target1Lun0 04:57:38.000 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 1 04:57:38.109 Disk 0 MBR read successfully 04:57:38.109 Disk 0 MBR scan 04:57:38.203 Disk 0 Windows XP default MBR code 04:57:38.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 305242 MB offset 63 04:57:38.218 Disk 0 scanning sectors +625137345 04:57:38.296 Disk 0 scanning C:\WINDOWS\system32\drivers 04:57:52.890 Service scanning 04:58:06.703 Modules scanning 04:58:13.703 Disk 0 trace - called modules: 04:58:13.718 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys 04:58:13.718 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x853a0030] 04:58:14.218 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000061[0x854db328] 04:58:14.218 5 ACPI.sys[f735e620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port2Path1Target1Lun0[0x854daa38] 04:58:14.812 AVAST engine scan C:\WINDOWS 04:58:32.468 AVAST engine scan C:\WINDOWS\system32 05:01:23.171 AVAST engine scan C:\WINDOWS\system32\drivers 05:01:45.156 AVAST engine scan C:\Documents and Settings\Admin John 05:03:26.671 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Admin John\Desktop\MBR.dat" 05:03:26.671 The log file has been saved successfully to "C:\Documents and Settings\Admin John\Desktop\aswMBR.txt"
05:09:10.0703 3072 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 05:09:11.0468 3072 ============================================================ 05:09:11.0468 3072 Current date / time: 2013/05/30 05:09:11.0468 05:09:11.0468 3072 SystemInfo: 05:09:11.0468 3072 05:09:11.0468 3072 OS Version: 5.1.2600 ServicePack: 3.0 05:09:11.0468 3072 Product type: Workstation 05:09:11.0468 3072 ComputerName: JOHNS-E-MACHINE 05:09:11.0468 3072 UserName: Admin John 05:09:11.0468 3072 Windows directory: C:\WINDOWS 05:09:11.0468 3072 System windows directory: C:\WINDOWS 05:09:11.0468 3072 Processor architecture: Intel x86 05:09:11.0468 3072 Number of processors: 1 05:09:11.0468 3072 Page size: 0x1000 05:09:11.0468 3072 Boot type: Normal boot 05:09:11.0468 3072 ============================================================ 05:09:12.0984 3072 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058 05:09:12.0984 3072 ============================================================ 05:09:12.0984 3072 \Device\Harddisk0\DR0: 05:09:12.0984 3072 MBR partitions: 05:09:12.0984 3072 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D682 05:09:12.0984 3072 ============================================================ 05:09:13.0000 3072 C: <-> \Device\Harddisk0\DR0\Partition1 05:09:13.0000 3072 ============================================================ 05:09:13.0000 3072 Initialize success 05:09:13.0000 3072 ============================================================ 05:09:42.0265 3628 ============================================================ 05:09:42.0265 3628 Scan started 05:09:42.0265 3628 Mode: Manual; TDLFS; 05:09:42.0265 3628 ============================================================ 05:09:42.0328 3628 ================ Scan system memory ======================== 05:09:42.0328 3628 System memory - ok 05:09:42.0328 3628 ================ Scan services ============================= 05:09:42.0484 3628 [ 473F97EDC5A5312F3665AB2921196C0C ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys 05:09:42.0484 3628 Aavmker4 - ok 05:09:42.0500 3628 Abiosdsk - ok 05:09:42.0500 3628 abp480n5 - ok 05:09:42.0609 3628 [ 00659E56339389469473AEC41587E706 ] ac.sharedstore C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe 05:09:42.0609 3628 ac.sharedstore - ok 05:09:42.0671 3628 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 05:09:42.0687 3628 ACPI - ok 05:09:42.0718 3628 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 05:09:42.0718 3628 ACPIEC - ok 05:09:42.0796 3628 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 05:09:42.0812 3628 AdobeFlashPlayerUpdateSvc - ok 05:09:42.0812 3628 adpu160m - ok 05:09:42.0843 3628 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 05:09:42.0843 3628 aec - ok 05:09:42.0875 3628 [ A7B8A3A79D35215D798A300DF49ED23F ] Afc C:\WINDOWS\system32\drivers\Afc.sys 05:09:42.0875 3628 Afc - ok 05:09:42.0921 3628 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 05:09:42.0921 3628 AFD - ok 05:09:42.0937 3628 [ 8ED60797908FD394EEE0D6949F493224 ] AgereModemAudio C:\WINDOWS\system32\agrsmsvc.exe 05:09:42.0937 3628 AgereModemAudio - ok 05:09:42.0984 3628 [ ACC50F43D9E764D364173B9858D3E940 ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys 05:09:43.0015 3628 AgereSoftModem - ok 05:09:43.0031 3628 Aha154x - ok 05:09:43.0031 3628 aic78u2 - ok 05:09:43.0046 3628 aic78xx - ok 05:09:43.0078 3628 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 05:09:43.0093 3628 Alerter - ok 05:09:43.0109 3628 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 05:09:43.0109 3628 ALG - ok 05:09:43.0125 3628 AliIde - ok 05:09:43.0140 3628 amsint - ok 05:09:43.0218 3628 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 05:09:43.0218 3628 Apple Mobile Device - ok 05:09:43.0281 3628 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 05:09:43.0281 3628 AppMgmt - ok 05:09:43.0281 3628 asc - ok 05:09:43.0406 3628 asc3350p - ok 05:09:43.0421 3628 asc3550 - ok 05:09:43.0484 3628 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 05:09:43.0484 3628 aspnet_state - ok 05:09:43.0515 3628 [ 0AE43C6C411254049279C2EE55630F95 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys 05:09:43.0515 3628 aswFsBlk - ok 05:09:43.0531 3628 [ 8C30B7DDD2F1D8D138EBE40345AF2B11 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys 05:09:43.0531 3628 aswMon2 - ok 05:09:43.0562 3628 [ DA12626FD9A67F4E917E2F2FBE1E1764 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys 05:09:43.0562 3628 aswRdr - ok 05:09:43.0593 3628 [ DCB199B967375753B5019EC15F008F53 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys 05:09:43.0609 3628 aswSnx - ok 05:09:43.0625 3628 [ B32873E5A1443C0A1E322266E203BF10 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys 05:09:43.0625 3628 aswSP - ok 05:09:43.0656 3628 [ 6FF544175A9180C5D88534D3D9C9A9F7 ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys 05:09:43.0656 3628 aswTdi - ok 05:09:43.0687 3628 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 05:09:43.0687 3628 AsyncMac - ok 05:09:43.0687 3628 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 05:09:43.0703 3628 atapi - ok 05:09:43.0703 3628 Atdisk - ok 05:09:43.0734 3628 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 05:09:43.0734 3628 Atmarpc - ok 05:09:43.0765 3628 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 05:09:43.0765 3628 AudioSrv - ok 05:09:43.0812 3628 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 05:09:43.0812 3628 audstub - ok 05:09:43.0859 3628 [ 4041D31508A2A084DFB42C595854090F ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 05:09:43.0875 3628 avast! Antivirus - ok 05:09:43.0890 3628 [ 543E3EA927AD7FCBCFAB9617CED8ED67 ] avgtp C:\WINDOWS\system32\drivers\avgtpx86.sys 05:09:43.0890 3628 avgtp - ok 05:09:43.0921 3628 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 05:09:43.0921 3628 Beep - ok 05:09:43.0984 3628 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 05:09:44.0000 3628 BITS - ok 05:09:44.0078 3628 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 05:09:44.0093 3628 Bonjour Service - ok 05:09:44.0125 3628 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 05:09:44.0125 3628 Browser - ok 05:09:44.0171 3628 [ 248DFA5762DDE38DFDDBBD44149E9D7A ] BVRPMPR5 C:\WINDOWS\system32\drivers\BVRPMPR5.SYS 05:09:44.0171 3628 BVRPMPR5 - ok 05:09:44.0343 3628 [ 442745BF42053A779AB514C5746DF11B ] CarboniteService C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe 05:09:44.0437 3628 CarboniteService - ok 05:09:44.0468 3628 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 05:09:44.0468 3628 cbidf2k - ok 05:09:44.0515 3628 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 05:09:44.0515 3628 CCDECODE - ok 05:09:44.0531 3628 cd20xrnt - ok 05:09:44.0546 3628 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 05:09:44.0546 3628 Cdaudio - ok 05:09:44.0562 3628 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 05:09:44.0562 3628 Cdfs - ok 05:09:44.0593 3628 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 05:09:44.0593 3628 Cdrom - ok 05:09:44.0609 3628 Changer - ok 05:09:44.0640 3628 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 05:09:44.0640 3628 CiSvc - ok 05:09:44.0687 3628 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 05:09:44.0687 3628 ClipSrv - ok 05:09:44.0718 3628 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 05:09:44.0750 3628 clr_optimization_v2.0.50727_32 - ok 05:09:44.0796 3628 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 05:09:44.0812 3628 clr_optimization_v4.0.30319_32 - ok 05:09:44.0812 3628 CmdIde - ok 05:09:44.0828 3628 COMSysApp - ok 05:09:44.0843 3628 Cpqarray - ok 05:09:44.0890 3628 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 05:09:44.0890 3628 CryptSvc - ok 05:09:44.0906 3628 dac2w2k - ok 05:09:44.0906 3628 dac960nt - ok 05:09:44.0953 3628 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 05:09:45.0015 3628 DcomLaunch - ok 05:09:45.0046 3628 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 05:09:45.0046 3628 Dhcp - ok 05:09:45.0078 3628 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 05:09:45.0078 3628 Disk - ok 05:09:45.0078 3628 dmadmin - ok 05:09:45.0125 3628 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 05:09:45.0140 3628 dmboot - ok 05:09:45.0156 3628 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\DRIVERS\dmio.sys 05:09:45.0171 3628 dmio - ok 05:09:45.0187 3628 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 05:09:45.0187 3628 dmload - ok 05:09:45.0234 3628 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 05:09:45.0234 3628 dmserver - ok 05:09:45.0281 3628 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 05:09:45.0281 3628 DMusic - ok 05:09:45.0328 3628 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 05:09:45.0328 3628 Dnscache - ok 05:09:45.0375 3628 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 05:09:45.0375 3628 Dot3svc - ok 05:09:45.0390 3628 dpti2o - ok 05:09:45.0406 3628 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 05:09:45.0421 3628 drmkaud - ok 05:09:45.0453 3628 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 05:09:45.0453 3628 EapHost - ok 05:09:45.0500 3628 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 05:09:45.0500 3628 ERSvc - ok 05:09:45.0531 3628 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 05:09:45.0546 3628 Eventlog - ok 05:09:45.0578 3628 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 05:09:45.0593 3628 EventSystem - ok 05:09:45.0640 3628 [ 5D5D0912EFAE59E54784C605BF0AB52B ] EZUSB C:\WINDOWS\system32\DRIVERS\ezusb.sys 05:09:45.0640 3628 EZUSB - ok 05:09:45.0671 3628 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 05:09:45.0671 3628 Fastfat - ok 05:09:45.0703 3628 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 05:09:45.0734 3628 FastUserSwitchingCompatibility - ok 05:09:45.0750 3628 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 05:09:45.0750 3628 Fdc - ok 05:09:45.0781 3628 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 05:09:45.0781 3628 Fips - ok 05:09:45.0796 3628 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 05:09:45.0796 3628 Flpydisk - ok 05:09:45.0812 3628 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 05:09:45.0812 3628 FltMgr - ok 05:09:45.0875 3628 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 05:09:45.0875 3628 FontCache3.0.0.0 - ok 05:09:45.0890 3628 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 05:09:45.0890 3628 Fs_Rec - ok 05:09:45.0906 3628 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 05:09:45.0906 3628 Ftdisk - ok 05:09:45.0937 3628 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 05:09:45.0937 3628 GEARAspiWDM - ok 05:09:45.0968 3628 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 05:09:45.0968 3628 Gpc - ok 05:09:46.0031 3628 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 05:09:46.0046 3628 gupdate - ok 05:09:46.0046 3628 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 05:09:46.0062 3628 gupdatem - ok 05:09:46.0109 3628 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 05:09:46.0109 3628 gusvc - ok 05:09:46.0156 3628 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 05:09:46.0156 3628 HDAudBus - ok 05:09:46.0218 3628 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 05:09:46.0234 3628 helpsvc - ok 05:09:46.0281 3628 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 05:09:46.0281 3628 HidServ - ok 05:09:46.0312 3628 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 05:09:46.0328 3628 HidUsb - ok 05:09:46.0359 3628 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 05:09:46.0359 3628 hkmsvc - ok 05:09:46.0375 3628 hpn - ok 05:09:46.0406 3628 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 05:09:46.0421 3628 HTTP - ok 05:09:46.0453 3628 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 05:09:46.0468 3628 HTTPFilter - ok 05:09:46.0468 3628 i2omgmt - ok 05:09:46.0484 3628 i2omp - ok 05:09:46.0515 3628 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 05:09:46.0515 3628 i8042prt - ok 05:09:46.0625 3628 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 05:09:46.0640 3628 idsvc - ok 05:09:46.0750 3628 [ AD5DF6F4FBBC798636EDC66BFEC7D0DE ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE 05:09:46.0750 3628 IJPLMSVC - ok 05:09:46.0765 3628 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 05:09:46.0765 3628 Imapi - ok 05:09:46.0796 3628 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 05:09:46.0796 3628 ImapiService - ok 05:09:46.0812 3628 ini910u - ok 05:09:46.0953 3628 [ 19AFBB8427CE65042599555E578170DF ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 05:09:47.0046 3628 IntcAzAudAddService - ok 05:09:47.0062 3628 IntelIde - ok 05:09:47.0109 3628 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 05:09:47.0109 3628 Ip6Fw - ok 05:09:47.0140 3628 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 05:09:47.0140 3628 IpFilterDriver - ok 05:09:47.0171 3628 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 05:09:47.0171 3628 IpInIp - ok 05:09:47.0218 3628 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 05:09:47.0218 3628 IpNat - ok 05:09:47.0265 3628 [ E8A39D41474BE42FD8830CED32932D6C ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 05:09:47.0281 3628 iPod Service - ok 05:09:47.0312 3628 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 05:09:47.0328 3628 IPSec - ok 05:09:47.0359 3628 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 05:09:47.0359 3628 IRENUM - ok 05:09:47.0390 3628 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 05:09:47.0390 3628 isapnp - ok 05:09:47.0484 3628 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 05:09:47.0484 3628 JavaQuickStarterService - ok 05:09:47.0500 3628 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 05:09:47.0500 3628 Kbdclass - ok 05:09:47.0515 3628 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 05:09:47.0531 3628 kmixer - ok 05:09:47.0546 3628 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 05:09:47.0562 3628 KSecDD - ok 05:09:47.0593 3628 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 05:09:47.0593 3628 lanmanserver - ok 05:09:47.0656 3628 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 05:09:47.0671 3628 lanmanworkstation - ok 05:09:47.0687 3628 lbrtfdc - ok 05:09:47.0750 3628 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 05:09:47.0750 3628 LmHosts - ok 05:09:47.0781 3628 [ 7521C0C58EE91BE90B6CC33E792D10C7 ] LVRS C:\WINDOWS\system32\DRIVERS\lvrs.sys 05:09:47.0796 3628 LVRS - ok 05:09:47.0890 3628 [ 37E57C48AF530DF01CDD4E8A2AD77B51 ] LVUVC C:\WINDOWS\system32\DRIVERS\lvuvc.sys 05:09:47.0984 3628 LVUVC - ok 05:09:48.0015 3628 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 05:09:48.0015 3628 Messenger - ok 05:09:48.0062 3628 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 05:09:48.0062 3628 mnmdd - ok 05:09:48.0093 3628 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 05:09:48.0093 3628 mnmsrvc - ok 05:09:48.0125 3628 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 05:09:48.0125 3628 Modem - ok 05:09:48.0140 3628 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 05:09:48.0140 3628 Mouclass - ok 05:09:48.0187 3628 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 05:09:48.0187 3628 mouhid - ok 05:09:48.0218 3628 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 05:09:48.0218 3628 MountMgr - ok 05:09:48.0281 3628 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 05:09:48.0296 3628 MozillaMaintenance - ok 05:09:48.0312 3628 mraid35x - ok 05:09:48.0328 3628 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 05:09:48.0328 3628 MRxDAV - ok 05:09:48.0359 3628 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 05:09:48.0375 3628 MRxSmb - ok 05:09:48.0406 3628 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 05:09:48.0406 3628 MSDTC - ok 05:09:48.0421 3628 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 05:09:48.0437 3628 Msfs - ok 05:09:48.0437 3628 MSIServer - ok 05:09:48.0453 3628 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 05:09:48.0453 3628 MSKSSRV - ok 05:09:48.0468 3628 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 05:09:48.0468 3628 MSPCLOCK - ok 05:09:48.0484 3628 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 05:09:48.0484 3628 MSPQM - ok 05:09:48.0515 3628 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 05:09:48.0531 3628 mssmbios - ok 05:09:48.0531 3628 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 05:09:48.0531 3628 MSTEE - ok 05:09:48.0562 3628 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 05:09:48.0562 3628 Mup - ok 05:09:48.0593 3628 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 05:09:48.0609 3628 NABTSFEC - ok 05:09:48.0656 3628 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 05:09:48.0671 3628 napagent - ok 05:09:48.0687 3628 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 05:09:48.0687 3628 NDIS - ok 05:09:48.0703 3628 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 05:09:48.0703 3628 NdisIP - ok 05:09:48.0734 3628 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 05:09:48.0734 3628 NdisTapi - ok 05:09:48.0750 3628 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 05:09:48.0750 3628 Ndisuio - ok 05:09:48.0765 3628 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 05:09:48.0765 3628 NdisWan - ok 05:09:48.0796 3628 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 05:09:48.0796 3628 NDProxy - ok 05:09:48.0812 3628 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 05:09:48.0812 3628 NetBIOS - ok 05:09:48.0828 3628 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 05:09:48.0828 3628 NetBT - ok 05:09:48.0875 3628 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 05:09:48.0875 3628 NetDDE - ok 05:09:48.0890 3628 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 05:09:48.0890 3628 NetDDEdsdm - ok 05:09:48.0921 3628 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 05:09:48.0937 3628 Netlogon - ok 05:09:48.0968 3628 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 05:09:48.0984 3628 Netman - ok 05:09:49.0046 3628 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 05:09:49.0062 3628 NetTcpPortSharing - ok 05:09:49.0093 3628 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 05:09:49.0109 3628 Nla - ok 05:09:49.0125 3628 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 05:09:49.0125 3628 Npfs - ok 05:09:49.0156 3628 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 05:09:49.0171 3628 Ntfs - ok 05:09:49.0171 3628 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 05:09:49.0187 3628 NtLmSsp - ok 05:09:49.0234 3628 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 05:09:49.0250 3628 NtmsSvc - ok 05:09:49.0265 3628 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 05:09:49.0265 3628 Null - ok 05:09:49.0562 3628 [ 7C56F3FD65B2BDB315CA3605A5392D7B ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 05:09:49.0828 3628 nv - ok 05:09:49.0890 3628 [ 45BA510DB13A0496DB1CD16826519E03 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 05:09:49.0890 3628 NVENETFD - ok 05:09:49.0921 3628 [ A117466B0ACB13288DEEE4F2E936E67F ] nvgts C:\WINDOWS\system32\DRIVERS\nvgts.sys 05:09:49.0921 3628 nvgts - ok 05:09:49.0937 3628 [ 57CBDB934FB1AFB7E03B413D151A6152 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 05:09:49.0937 3628 nvnetbus - ok 05:09:49.0968 3628 [ 7E5B3BE5DCD54BBB44B0C7DB7BD3EC8F ] NVSvc C:\WINDOWS\system32\nvsvc32.exe 05:09:49.0984 3628 NVSvc - ok 05:09:50.0046 3628 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 05:09:50.0046 3628 NwlnkFlt - ok 05:09:50.0046 3628 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 05:09:50.0062 3628 NwlnkFwd - ok 05:09:50.0125 3628 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 05:09:50.0125 3628 ose - ok 05:09:50.0187 3628 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys 05:09:50.0187 3628 Parport - ok 05:09:50.0187 3628 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 05:09:50.0203 3628 PartMgr - ok 05:09:50.0234 3628 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 05:09:50.0234 3628 ParVdm - ok 05:09:50.0250 3628 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 05:09:50.0250 3628 PCI - ok 05:09:50.0250 3628 PCIDump - ok 05:09:50.0265 3628 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 05:09:50.0265 3628 PCIIde - ok 05:09:50.0281 3628 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 05:09:50.0281 3628 Pcmcia - ok 05:09:50.0296 3628 PDCOMP - ok 05:09:50.0312 3628 PDFRAME - ok 05:09:50.0312 3628 PDRELI - ok 05:09:50.0328 3628 PDRFRAME - ok 05:09:50.0343 3628 perc2 - ok 05:09:50.0359 3628 perc2hib - ok 05:09:50.0406 3628 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 05:09:50.0406 3628 PlugPlay - ok 05:09:50.0421 3628 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 05:09:50.0421 3628 PolicyAgent - ok 05:09:50.0453 3628 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 05:09:50.0453 3628 PptpMiniport - ok 05:09:50.0468 3628 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys 05:09:50.0468 3628 Processor - ok 05:09:50.0484 3628 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 05:09:50.0484 3628 ProtectedStorage - ok 05:09:50.0500 3628 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 05:09:50.0500 3628 PSched - ok 05:09:50.0515 3628 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 05:09:50.0515 3628 Ptilink - ok 05:09:50.0531 3628 ql1080 - ok 05:09:50.0546 3628 Ql10wnt - ok 05:09:50.0546 3628 ql12160 - ok 05:09:50.0562 3628 ql1240 - ok 05:09:50.0578 3628 ql1280 - ok 05:09:50.0609 3628 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 05:09:50.0609 3628 RasAcd - ok 05:09:50.0656 3628 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 05:09:50.0671 3628 RasAuto - ok 05:09:50.0671 3628 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 05:09:50.0687 3628 Rasl2tp - ok 05:09:50.0718 3628 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 05:09:50.0734 3628 RasMan - ok 05:09:50.0750 3628 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 05:09:50.0750 3628 RasPppoe - ok 05:09:50.0781 3628 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 05:09:50.0781 3628 Raspti - ok 05:09:50.0796 3628 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 05:09:50.0796 3628 Rdbss - ok 05:09:50.0828 3628 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 05:09:50.0828 3628 RDPCDD - ok 05:09:50.0859 3628 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 05:09:50.0859 3628 rdpdr - ok 05:09:50.0921 3628 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 05:09:50.0921 3628 RDPWD - ok 05:09:50.0968 3628 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 05:09:50.0984 3628 RDSessMgr - ok 05:09:51.0015 3628 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 05:09:51.0015 3628 redbook - ok 05:09:51.0078 3628 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 05:09:51.0078 3628 RemoteAccess - ok 05:09:51.0125 3628 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 05:09:51.0140 3628 RemoteRegistry - ok 05:09:51.0156 3628 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 05:09:51.0156 3628 RpcLocator - ok 05:09:51.0187 3628 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 05:09:51.0203 3628 RpcSs - ok 05:09:51.0234 3628 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 05:09:51.0250 3628 RSVP - ok 05:09:51.0265 3628 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 05:09:51.0265 3628 SamSs - ok 05:09:51.0312 3628 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 05:09:51.0312 3628 SCardSvr - ok 05:09:51.0359 3628 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 05:09:51.0375 3628 Schedule - ok 05:09:51.0421 3628 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 05:09:51.0421 3628 Secdrv - ok 05:09:51.0468 3628 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 05:09:51.0468 3628 seclogon - ok 05:09:51.0484 3628 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 05:09:51.0500 3628 SENS - ok 05:09:51.0531 3628 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\drivers\Serial.sys 05:09:51.0531 3628 Serial - ok 05:09:51.0609 3628 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 05:09:51.0609 3628 Sfloppy - ok 05:09:51.0656 3628 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 05:09:51.0687 3628 SharedAccess - ok 05:09:51.0718 3628 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 05:09:51.0734 3628 ShellHWDetection - ok 05:09:51.0734 3628 Simbad - ok 05:09:51.0781 3628 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 05:09:51.0781 3628 SkypeUpdate - ok 05:09:51.0812 3628 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 05:09:51.0828 3628 SLIP - ok 05:09:51.0859 3628 Sparrow - ok 05:09:51.0890 3628 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 05:09:51.0890 3628 splitter - ok 05:09:51.0921 3628 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 05:09:51.0937 3628 Spooler - ok 05:09:51.0984 3628 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 05:09:51.0984 3628 sr - ok 05:09:52.0046 3628 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 05:09:52.0062 3628 srservice - ok 05:09:52.0109 3628 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 05:09:52.0125 3628 Srv - ok 05:09:52.0156 3628 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 05:09:52.0171 3628 SSDPSRV - ok 05:09:52.0234 3628 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 05:09:52.0281 3628 stisvc - ok 05:09:52.0312 3628 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 05:09:52.0312 3628 streamip - ok 05:09:52.0359 3628 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 05:09:52.0359 3628 swenum - ok 05:09:52.0375 3628 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 05:09:52.0375 3628 swmidi - ok 05:09:52.0390 3628 SwPrv - ok 05:09:52.0406 3628 symc810 - ok 05:09:52.0421 3628 symc8xx - ok 05:09:52.0421 3628 sym_hi - ok 05:09:52.0437 3628 sym_u3 - ok 05:09:52.0468 3628 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 05:09:52.0468 3628 sysaudio - ok 05:09:52.0500 3628 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 05:09:52.0500 3628 SysmonLog - ok 05:09:52.0531 3628 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 05:09:52.0546 3628 TapiSrv - ok 05:09:52.0609 3628 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 05:09:52.0625 3628 Tcpip - ok 05:09:52.0640 3628 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 05:09:52.0640 3628 TDPIPE - ok 05:09:52.0656 3628 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 05:09:52.0656 3628 TDTCP - ok 05:09:52.0687 3628 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 05:09:52.0703 3628 TermDD - ok 05:09:52.0734 3628 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 05:09:52.0750 3628 TermService - ok 05:09:52.0781 3628 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 05:09:52.0781 3628 Themes - ok 05:09:52.0828 3628 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 05:09:52.0843 3628 TlntSvr - ok 05:09:52.0843 3628 TosIde - ok 05:09:52.0875 3628 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 05:09:52.0890 3628 TrkWks - ok 05:09:52.0906 3628 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 05:09:52.0921 3628 Udfs - ok 05:09:52.0921 3628 ultra - ok 05:09:53.0015 3628 [ 927754ABF077AEB5504BE4E0F2C60C1B ] UMVPFSrv C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 05:09:53.0046 3628 UMVPFSrv - ok 05:09:53.0093 3628 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 05:09:53.0109 3628 Update - ok 05:09:53.0140 3628 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 05:09:53.0156 3628 upnphost - ok 05:09:53.0171 3628 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 05:09:53.0187 3628 UPS - ok 05:09:53.0218 3628 [ 8BF5D980CDCE35FB26F05047144BB57E ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys 05:09:53.0218 3628 USBAAPL - ok 05:09:53.0250 3628 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 05:09:53.0250 3628 usbaudio - ok 05:09:53.0312 3628 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 05:09:53.0312 3628 usbccgp - ok 05:09:53.0343 3628 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 05:09:53.0359 3628 usbehci - ok 05:09:53.0375 3628 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 05:09:53.0375 3628 usbhub - ok 05:09:53.0390 3628 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys 05:09:53.0406 3628 usbohci - ok 05:09:53.0421 3628 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 05:09:53.0437 3628 usbprint - ok 05:09:53.0468 3628 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 05:09:53.0531 3628 usbscan - ok 05:09:53.0578 3628 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 05:09:53.0578 3628 usbstor - ok 05:09:53.0625 3628 [ 63BBFCA7F390F4C49ED4B96BFB1633E0 ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys 05:09:53.0625 3628 usbvideo - ok 05:09:53.0656 3628 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 05:09:53.0656 3628 VgaSave - ok 05:09:53.0671 3628 ViaIde - ok 05:09:53.0687 3628 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 05:09:53.0703 3628 VolSnap - ok 05:09:53.0734 3628 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 05:09:53.0750 3628 VSS - ok 05:09:53.0828 3628 [ F1E8C5167F849D1089D8108C50E6FF11 ] vToolbarUpdater15.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe 05:09:53.0843 3628 vToolbarUpdater15.2.0 - ok 05:09:53.0875 3628 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 05:09:53.0890 3628 W32Time - ok 05:09:53.0921 3628 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 05:09:53.0937 3628 Wanarp - ok 05:09:53.0937 3628 WDICA - ok 05:09:53.0968 3628 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 05:09:53.0968 3628 wdmaud - ok 05:09:54.0015 3628 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 05:09:54.0031 3628 WebClient - ok 05:09:54.0125 3628 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 05:09:54.0125 3628 winmgmt - ok 05:09:54.0187 3628 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 05:09:54.0187 3628 WmdmPmSN - ok 05:09:54.0234 3628 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 05:09:54.0250 3628 Wmi - ok 05:09:54.0281 3628 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 05:09:54.0281 3628 WmiAcpi - ok 05:09:54.0328 3628 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 05:09:54.0343 3628 WmiApSrv - ok 05:09:54.0421 3628 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 05:09:54.0484 3628 WMPNetworkSvc - ok 05:09:54.0531 3628 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys 05:09:54.0531 3628 WpdUsb - ok 05:09:54.0718 3628 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 05:09:54.0750 3628 WPFFontCache_v0400 - ok 05:09:54.0781 3628 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 05:09:54.0796 3628 wscsvc - ok 05:09:54.0828 3628 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 05:09:54.0843 3628 WSTCODEC - ok 05:09:54.0875 3628 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 05:09:54.0890 3628 wuauserv - ok 05:09:54.0937 3628 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 05:09:54.0937 3628 WudfPf - ok 05:09:54.0953 3628 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 05:09:54.0953 3628 WudfRd - ok 05:09:55.0000 3628 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 05:09:55.0015 3628 WudfSvc - ok 05:09:55.0062 3628 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 05:09:55.0078 3628 WZCSVC - ok 05:09:55.0109 3628 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 05:09:55.0125 3628 xmlprov - ok 05:09:55.0140 3628 ================ Scan global =============================== 05:09:55.0171 3628 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 05:09:55.0203 3628 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 05:09:55.0218 3628 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 05:09:55.0265 3628 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 05:09:55.0281 3628 [Global] - ok 05:09:55.0281 3628 ================ Scan MBR ================================== 05:09:55.0312 3628 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 05:09:55.0578 3628 \Device\Harddisk0\DR0 - ok 05:09:55.0578 3628 ================ Scan VBR ================================== 05:09:55.0593 3628 [ 85AAE0BBE754E4B6A29CAA47F6D83AB3 ] \Device\Harddisk0\DR0\Partition1 05:09:55.0593 3628 \Device\Harddisk0\DR0\Partition1 - ok 05:09:55.0593 3628 ============================================================ 05:09:55.0593 3628 Scan finished 05:09:55.0593 3628 ============================================================ 05:09:55.0609 4080 Detected object count: 0 05:09:55.0609 4080 Actual detected object count: 0
Hello, SkinnyTex.

Thank you for the DDS, aswMBR, and TDSSKiller logs.

Please run the following scans

1. ComboFix

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings.
  • Please download ComboFix from HERE or HERE.
Very Important! Save ComboFix.exe to to your Desktop.
  • Close all browsers.
  • Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:

  • Right click on the System Tray icon, or
  • Refer to this link HERE for further assistance.

  • Double click on ComboFix.exe and follow the prompts. ComboFix will automatically check to see if the Microsoft Windows Recovery Console is installed.

Note:

  • If Combofix asks you to install the Microsoft Windows Recovery Console, please allow it.
  • If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • When prompted, agree to the End-User License Agreement to begin installation.
  • If ComboFix asks you to update the program, please do so.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Warnings:
  • Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
  • Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
  • Do not attempt to surf the internet while ComboFix is scanning.

Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.

Very Important! Make sure you re-enable your security programs when ComboFix is finished.

2. Security Check

Please download Security Check from HERE or HERE.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt. This may take a few minutes.
Please copy and paste the contents of that document into your next reply.
ComboFix 13-05-30.02 - Admin John 05/30/2013 21:08:50.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.470 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Setup.exe
c:\windows\system32\Cache
c:\windows\system32\Cache\075884af680ff6dc.fb
c:\windows\system32\Cache\227113dfa1ca894d.fb
c:\windows\system32\Cache\49fbbc5a8678d502.fb
c:\windows\system32\Cache\5c54eb1a1655b076.fb
c:\windows\system32\Cache\613e8ce7ab7106af.fb
c:\windows\system32\Cache\633a76311867bd11.fb
c:\windows\system32\Cache\691f14230153a9e1.fb
c:\windows\system32\Cache\6cb409d7ac73d9f1.fb
c:\windows\system32\Cache\7614bd6cfa99e546.fb
c:\windows\system32\Cache\77664b6ccc36be9f.fb
c:\windows\system32\Cache\881b3593316772f0.fb
c:\windows\system32\Cache\98657d0579ae1930.fb
c:\windows\system32\Cache\9eb13e2b2adb974e.fb
c:\windows\system32\Cache\c4e10d1be905349b.fb
c:\windows\system32\Cache\d5c0f4e7bbe35bf3.fb
c:\windows\system32\Cache\d9ca663388d21ec0.fb
c:\windows\system32\Cache\f2cda51fd108941f.fb
c:\windows\system32\Cache\f34d8db84131d925.fb
c:\windows\system32\SET33B.tmp
c:\windows\system32\SET340.tmp
c:\windows\system32\SET5D.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-31 )))))))))))))))))))))))))))))))
.
.
2013-05-21 07:48 . 2013-05-21 07:48 ——– d—–w- c:\documents and settings\John\Application Data\AVG SafeGuard toolbar
2013-05-10 07:57 . 2013-05-10 07:57 187456 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-21 07:48 . 2013-03-31 17:14 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-05-15 13:45 . 2012-04-01 17:40 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-15 13:45 . 2011-07-16 23:21 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-21 16:15 . 2012-01-09 10:22 664 —-a-w- c:\documents and settings\John\Local Settings\Application Data\d3d9caps.tmp
2013-04-16 22:17 . 2004-08-04 12:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-04-16 22:17 . 2004-08-04 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-04-16 22:17 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-04-12 23:28 . 2004-08-04 12:00 385024 ——w- c:\windows\system32\html.iec
2013-04-10 01:31 . 2004-08-04 12:00 1876352 —-a-w- c:\windows\system32\win32k.sys
2013-03-08 08:36 . 2004-08-04 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:28 . 2004-08-04 12:00 2193408 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 2004-08-03 22:59 2070016 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-24 17:50 . 2012-11-03 18:48 261600 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files\WinZipBar\prxtbWin2.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
2013-04-14 12:35 231712 —-a-w- c:\program files\WinZipBar\prxtbWin2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-05-21 07:47 1991344 —-a-w- c:\program files\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files\WinZipBar\prxtbWin2.dll" [2013-04-14 231712]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll" [2013-05-21 1991344]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}"= "c:\program files\WinZipBar\prxtbWin2.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2012-07-26 15:03 1014344 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2012-07-26 15:03 1014344 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2012-07-26 15:03 1014344 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-09-04 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-10-25 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2009-06-03 21:14 113152 —-a-w- c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2009-06-03 21:13 299520 —-a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ActivClient Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ActivClient Agent.lnk
backup=c:\windows\pss\ActivClient Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\accrdsub]
2009-06-03 21:13 400936 —-a-w- c:\program files\ActivIdentity\ActivClient\accrdsub.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acevents]
2009-06-03 21:16 153640 —-a-w- c:\program files\ActivIdentity\ActivClient\acevents.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 22:43 69632 —-a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
2012-10-29 23:22 1573576 —-a-w- c:\program files\Ask.com\Updater\Updater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-10-06 06:52 59240 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-11-28 20:13 59280 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BSDAppUpdater]
2012-09-15 16:39 1660232 —-a-w- c:\program files\Common Files\BSD\AppUpdater\BSDChecker.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2010-03-25 01:50 2516296 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 14:18 1185112 —-a-w- c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Carbonite Backup]
2012-07-26 15:03 1061960 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-04-15 17:35 116648 —-atw- c:\documents and settings\Admin John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-12-12 19:57 152544 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-08-12 17:18 205336 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-02-25 16:29 1626112 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-10-25 09:12 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-05-16 18:39 16862720 —-a-w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-11-09 17:27 17877168 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 14:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2012-09-04 09:20 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
2013-05-21 07:47 1226928 —-a-w- c:\program files\AVG SafeGuard toolbar\vprot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vToolbarUpdater15.2.0"=2 (0x2)
"SkypeUpdate"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"gusvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AgereModemAudio"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
"ac.sharedstore"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\Program Files\\FreeFileViewer\\FFVCheckForUpdates.exe"=
"c:\\Program Files\\File Type Assistant\\tsassist.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Searchqu Toolbar\\Datamngr\\ToolBar\\dtUser.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/13/2011 7:14 PM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/13/2011 7:14 PM 337880]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [3/31/2013 12:14 PM 37664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/13/2011 7:14 PM 20696]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [8/19/2011 4:26 AM 450848]
S3 EZUSB;EZUSB PC/SC Smart Card Reader;c:\windows\system32\drivers\ezusb.sys [6/3/2008 11:22 PM 63288]
S4 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [6/3/2009 4:16 PM 207400]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [11/9/2012 12:21 PM 160944]
S4 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [5/21/2013 2:48 AM 1015984]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-24 21:03 1165776 —-a-w- c:\program files\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 13:45]
.
2013-05-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2013-05-31 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2012-06-17 19:24]
.
2013-05-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-01 17:25]
.
2013-05-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-01 17:25]
.
2013-05-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1004Core.job
- c:\documents and settings\Admin John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 17:35]
.
2013-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1004UA.job
- c:\documents and settings\Admin John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 17:35]
.
2013-05-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1005Core.job
- c:\documents and settings\John_2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-30 17:35]
.
2013-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1005UA.job
- c:\documents and settings\John_2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-30 17:35]
.
2013-05-31 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-06-17 03:19]
.
2013-05-31 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-10-29 23:22]
.
2013-05-31 c:\windows\Tasks\User_Feed_Synchronization-{0F5A8A44-E309-46D9-97E2-91D6E9DBD81C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: army.mil\owa.usar
Trusted Zone: militarycac.com
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll
FF - ProfilePath - c:\documents and settings\Admin John\Application Data\Mozilla\Firefox\Profiles\z9680u01.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://www.searchnu.com/102
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=102&sr=0&q=
FF - ExtSQL: !HIDDEN! 2012-10-14 08:50; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files\Searchqu Toolbar\Datamngr\FirefoxExtension
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-05-30 21:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(728)
c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
c:\program files\ActivIdentity\ActivClient\aclog.dll
c:\program files\ActivIdentity\ActivClient\accrypto.dll
c:\program files\ActivIdentity\ActivClient\ACLIBEAY.dll
c:\program files\ActivIdentity\ActivClient\acevtsub.dll
c:\program files\ActivIdentity\ActivClient\asphat32.dll
c:\program files\ActivIdentity\ActivClient\acerrmes.dll
c:\program files\ActivIdentity\ActivClient\aiwinext.dll
c:\program files\ActivIdentity\ActivClient\aspcom.dll
c:\program files\ActivIdentity\ActivClient\Resources\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\asphatrc.dll
c:\program files\ActivIdentity\ActivClient\acunlock.dll
c:\program files\ActivIdentity\ActivClient\aipingui.dll
c:\program files\ActivIdentity\ActivClient\aicext.dll
c:\program files\ActivIdentity\ActivClient\Resources\aipinguirc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\acunlockrc.dll
.
- - - - - - - > 'explorer.exe'(3520)
c:\windows\system32\WININET.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre7\bin\jqs.exe
.
**************************************************************************
.
Completion time: 2013-05-30 21:34:58 - machine was rebooted
ComboFix-quarantined-files.txt 2013-05-31 02:34
.
Pre-Run: 228,361,916,416 bytes free
Post-Run: 234,838,564,864 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 10A159740DFFCE9C02102A481E42503B


Results of screen317's Security Check version 0.99.64
Windows XP Service Pack 3 x86
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 9
Java SE Development Kit 7 Update 7
Java version out of Date!
Adobe Flash Player 11.7.700.202
Adobe Reader 10.1.7 Adobe Reader out of Date!
Mozilla Firefox 16.0.2 Firefox out of Date!
Google Chrome 26.0.1410.64
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 17% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
Hello, SkinnyTex.

Thank you for the CF and Security Check logs. We have removed some unwanted applications. Let's continue the cleanup.

Show Hidden System Files and Folders

Some of the files and/or folders we need to delete are hidden and need to be shown before they can be removed. Do the following:
  • Click Start > My Computer > Tools > Folder Options > View.
  • In the Advanced Settings section, please do the following:

  • Under Hidden files and folders, select Show hidden files, folders, or drives.
  • Uncheck Hide file extensions for known file types.
  • Uncheck Hide protected operating system files (Recommended) . When the warning message appears, click YES.
  • Click Apply > OK.

Please run the following scans.

1. ComboFix

Very Important!

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix and can cause unpredictable results.

Please open Notepad:
  • Start > Run.
  • Type notepad in the Open field
  • Click OK.
  • Copy and paste the text inside the code box below:
KillAll::
ClearJavaCache::

Firefox::
FF - ProfilePath - c:\documents and settings\Admin John\ApplicationData\Mozilla\Firefox\Profiles\
z9680u01.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.searchnu.com/102
FF - ExtSQL: !HIDDEN! 2012-10-14 08:50; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files\Searchqu Toolbar\Datamngr\FirefoxExtension
  • Save this as CFScript.txt to your desktop and change the "Save as type" to All Files.
  • Drag the CFScript.txt into ComboFix.exe as shown in the screenshot below:

[external image: Posted Image]

  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, ComboFix will produce a log for you. Copy and paste the contents of the log in your next reply.
WARNING
  • Do not mouse-click ComboFix's window while it is running. This may cause it to stall.
  • Do not attempt to surf the internet while ComboFix is scanning.
Very Important! Make sure you re-enable your security programs when ComboFix is finished.

2. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Post the contents of JRT.txt into your next reply.

3. AdwCleaner

Please download AdwCleaner from HERE.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
  • You can also find the logfile at C:\AdwCleaner[S1].txt.
Copy and paste the adwcleaner.txt report into your next reply.

Hide System Files and Folders

We need to rehide the system files and folders to keep them from being accidentally changed or deleted. Do the following:
  • Click Start > My Computer > Tools > Folder Options > View.
  • In the Advanced Settings section, please do the following:

  • Under Hidden files and folders, deselect Show hidden files, folders, or drives.
  • Check Hide file extensions for known file types.
  • Check Hide protected operating system files (Recommended) .
  • Click Apply > OK.

SUMMARY: In your next reply, please post the following:
  • ComboFix log
  • JRT.txt
  • adwcleaner.txt
  • Please let me know how your computer is running at this stage.
ComboFix 13-06-01.01 - Admin John 06/01/2013 12:44:12.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.442 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin John\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Files Created from 2013-05-01 to 2013-06-01 )))))))))))))))))))))))))))))))
.
.
2013-06-01 12:31 . 2013-06-01 12:31 ——– d—–w- c:\documents and settings\John\Application Data\SearchProtect
2013-06-01 08:00 . 2013-06-01 08:00 ——– d—–w- c:\program files\MSXML 4.0
2013-05-31 23:46 . 2013-05-31 23:46 ——– d—–w- c:\documents and settings\Admin John\Application Data\player
2013-05-31 23:46 . 2013-05-31 23:46 ——– d—–w- c:\program files\Tuguu SL
2013-05-31 23:43 . 2013-05-31 23:43 ——– d—–w- c:\documents and settings\Admin John\Application Data\SwvUpdater
2013-05-31 23:42 . 2013-05-31 23:42 ——– d—–w- c:\documents and settings\Admin John\Application Data\Strongvault
2013-05-31 23:41 . 2013-05-31 23:42 ——– d—–w- c:\program files\SearchProtect
2013-05-31 23:41 . 2013-05-31 23:42 ——– d—–w- c:\documents and settings\Admin John\Application Data\SearchProtect
2013-05-31 23:38 . 2013-05-31 23:38 ——– d-sh–w- c:\windows\system32\AI_RecycleBin
2013-05-31 23:38 . 2013-06-01 17:10 ——– d—–w- c:\documents and settings\Admin John\Local Settings\Application Data\Strongvault Online Backup
2013-05-31 23:38 . 2013-06-01 12:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Strongvault Online Backup
2013-05-31 23:38 . 2013-06-01 17:25 ——– d—–w- c:\documents and settings\Admin John\Local Settings\Application Data\Strongvault
2013-05-31 23:38 . 2013-05-31 23:38 ——– d—–w- c:\program files\Strongvault Online Backup
2013-05-31 23:37 . 2013-05-31 23:39 ——– d—–w- C:\AI_RecycleBin
2013-05-31 23:37 . 2013-05-31 23:37 ——– d—–w- c:\program files\SingAlong
2013-05-31 02:44 . 2013-05-31 02:44 ——– d—–w- c:\documents and settings\Admin John\Application Data\1O1L1I1PtF1F1C1N
2013-05-31 02:43 . 2013-05-31 02:43 ——– d—–w- c:\documents and settings\All Users\Application Data\BrowserProtect
2013-05-31 02:43 . 2013-05-31 02:43 ——– d—–w- c:\program files\Delta
2013-05-31 02:43 . 2013-05-31 02:43 ——– d—–w- c:\documents and settings\Admin John\Application Data\BabSolution
2013-05-31 02:43 . 2013-05-31 02:51 ——– d—–w- c:\documents and settings\Admin John\Application Data\Delta
2013-05-31 02:43 . 2013-05-31 02:43 ——– d—–w- c:\program files\LyricsFan
2013-05-31 02:43 . 2013-05-31 02:43 ——– d—–w- c:\program files\FindLyrics
2013-05-21 07:48 . 2013-05-21 07:48 ——– d—–w- c:\documents and settings\John\Application Data\AVG SafeGuard toolbar
2013-05-11 10:37 . 2013-05-11 10:37 209472 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-21 07:48 . 2013-03-31 17:14 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-05-15 13:45 . 2012-04-01 17:40 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-15 13:45 . 2011-07-16 23:21 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-08 06:10 . 2011-02-20 04:03 421200 —-a-w- c:\windows\system32\msvcp100.dll
2013-05-08 06:10 . 2011-02-19 05:40 770384 —-a-w- c:\windows\system32\msvcr100.dll
2013-04-21 16:15 . 2012-01-09 10:22 664 —-a-w- c:\documents and settings\John\Local Settings\Application Data\d3d9caps.tmp
2013-04-16 22:17 . 2004-08-04 12:00 920064 —-a-w- c:\windows\system32\wininet.dll
2013-04-16 22:17 . 2004-08-04 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-04-16 22:17 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-04-12 23:28 . 2004-08-04 12:00 385024 ——w- c:\windows\system32\html.iec
2013-04-10 01:31 . 2004-08-04 12:00 1876352 —-a-w- c:\windows\system32\win32k.sys
2013-03-08 08:36 . 2004-08-04 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2013-03-07 01:28 . 2004-08-04 12:00 2193408 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 00:50 . 2004-08-03 22:59 2070016 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-24 17:50 . 2012-11-03 18:48 261600 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files\WinZipBar\prxtbWin2.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
2013-04-14 12:35 231712 —-a-w- c:\program files\WinZipBar\prxtbWin2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-05-21 07:47 1991344 —-a-w- c:\program files\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{A8720491-9558-4C0D-9E35-30EED15DFB2B}]
2013-05-20 09:10 127488 —-a-w- c:\program files\LyricsFan\lrcfan.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files\WinZipBar\prxtbWin2.dll" [2013-04-14 231712]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll" [2013-05-21 1991344]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}"= "c:\program files\WinZipBar\prxtbWin2.dll" [2013-04-14 231712]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2012-07-26 15:03 1014344 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2012-07-26 15:03 1014344 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2012-07-26 15:03 1014344 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-09-04 39408]
"BackupAgent"="c:\program files\Strongvault Online Backup\BackupAgent.exe" [2013-03-19 197448]
"SearchProtect"="c:\documents and settings\Admin John\Application Data\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-10-25 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"SMessaging"="c:\documents and settings\Admin John\Local Settings\Application Data\Strongvault Online Backup\SMessaging.exe" [2012-04-04 31664]
"SearchProtectAll"="c:\program files\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640]
.
c:\documents and settings\Admin John\Start Menu\Programs\Startup\
StrongVaultApp.lnk - c:\documents and settings\Admin John\Local Settings\Application Data\Strongvault\StrongVaultApp.exe [2013-3-19 400712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2009-06-03 21:14 113152 —-a-w- c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2009-06-03 21:13 299520 —-a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ActivClient Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ActivClient Agent.lnk
backup=c:\windows\pss\ActivClient Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\accrdsub]
2009-06-03 21:13 400936 —-a-w- c:\program files\ActivIdentity\ActivClient\accrdsub.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acevents]
2009-06-03 21:16 153640 —-a-w- c:\program files\ActivIdentity\ActivClient\acevents.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-05-11 10:37 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 22:43 69632 —-a-w- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
2012-10-29 23:22 1573576 —-a-w- c:\program files\Ask.com\Updater\Updater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-10-06 06:52 59240 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-11-28 20:13 59280 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BSDAppUpdater]
2012-09-15 16:39 1660232 —-a-w- c:\program files\Common Files\BSD\AppUpdater\BSDChecker.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2010-03-25 01:50 2516296 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 14:18 1185112 —-a-w- c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Carbonite Backup]
2012-07-26 15:03 1061960 —-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-04-15 17:35 116648 —-atw- c:\documents and settings\Admin John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-12-12 19:57 152544 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-08-12 17:18 205336 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-02-25 16:29 1626112 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-10-25 09:12 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-05-16 18:39 16862720 —-a-w- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-11-09 17:27 17877168 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 14:04 252848 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2012-09-04 09:20 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
2013-05-21 07:47 1226928 —-a-w- c:\program files\AVG SafeGuard toolbar\vprot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vToolbarUpdater15.2.0"=2 (0x2)
"SkypeUpdate"=2 (0x2)
"MozillaMaintenance"=3 (0x3)
"gusvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AgereModemAudio"=2 (0x2)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
"ac.sharedstore"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\Program Files\\FreeFileViewer\\FFVCheckForUpdates.exe"=
"c:\\Program Files\\File Type Assistant\\tsassist.exe"=
"c:\\Program Files\\Opera\\pluginwrapper\\opera_plugin_wrapper.exe"=
"c:\\Program Files\\Searchqu Toolbar\\Datamngr\\ToolBar\\dtUser.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/13/2011 7:14 PM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/13/2011 7:14 PM 337880]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [3/31/2013 12:14 PM 37664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/13/2011 7:14 PM 20696]
R2 BrowserProtect;BrowserProtect;c:\documents and settings\All Users\Application Data\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [5/30/2013 9:43 PM 2787280]
R2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\SearchProtect\bin\CltMngSvc.exe [5/8/2013 1:18 AM 97056]
R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [8/19/2011 4:26 AM 450848]
S3 EZUSB;EZUSB PC/SC Smart Card Reader;c:\windows\system32\drivers\ezusb.sys [6/3/2008 11:22 PM 63288]
S4 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [6/3/2009 4:16 PM 207400]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [11/9/2012 12:21 PM 160944]
S4 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [5/21/2013 2:48 AM 1015984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-24 21:03 1165776 —-a-w- c:\program files\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 13:45]
.
2013-06-01 c:\windows\Tasks\AmiUpdXp.job
- c:\documents and settings\Admin John\Application Data\SwvUpdater\Updater.exe [2013-05-31 23:37]
.
2013-05-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2013-06-01 c:\windows\Tasks\EPUpdater.job
- c:\docume~1\ADMINJ~1\APPLIC~1\BABSOL~1\Shared\BabMaint.exe [2013-05-31 10:34]
.
2013-06-01 c:\windows\Tasks\FreeFileViewerUpdateChecker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2012-06-17 19:24]
.
2013-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-01 17:25]
.
2013-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-01 17:25]
.
2013-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1004Core.job
- c:\documents and settings\Admin John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 17:35]
.
2013-06-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1004UA.job
- c:\documents and settings\Admin John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 17:35]
.
2013-06-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1005Core.job
- c:\documents and settings\John_2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-30 17:35]
.
2013-06-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-573735546-839522115-1005UA.job
- c:\documents and settings\John_2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-30 17:35]
.
2013-06-01 c:\windows\Tasks\Lyrics Fan Update.job
- c:\program files\LyricsFan\LyricsFanUpdater.exe [2013-05-20 09:10]
.
2013-06-01 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2012-06-17 03:19]
.
2013-06-01 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-10-29 23:22]
.
2013-06-01 c:\windows\Tasks\User_Feed_Synchronization-{0F5A8A44-E309-46D9-97E2-91D6E9DBD81C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: army.mil\owa.usar
Trusted Zone: militarycac.com
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll
FF - ProfilePath - c:\documents and settings\Admin John\Application Data\Mozilla\Firefox\Profiles\z9680u01.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN29983022311797271&UM=2&SearchSource=3&q={searchTerms}&sspv=TB_TFS
FF - prefs.js: browser.search.selectedEngine - Delta Search
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=119351&tt=300513_ctrl&babsrc=HP_ss_gin2g&mntrId=ACA3001D72B2F71C
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN29983022311797271&UM=2&sspv=TB_TFS&q=
FF - ExtSQL: !HIDDEN! 2012-10-14 08:50; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files\Searchqu Toolbar\Datamngr\FirefoxExtension
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-01 14:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(728)
c:\program files\ActivIdentity\ActivClient\ackpbsc.dll
c:\program files\ActivIdentity\ActivClient\aclog.dll
c:\program files\ActivIdentity\ActivClient\accrypto.dll
c:\program files\ActivIdentity\ActivClient\ACLIBEAY.dll
c:\program files\ActivIdentity\ActivClient\acevtsub.dll
c:\program files\ActivIdentity\ActivClient\asphat32.dll
c:\program files\ActivIdentity\ActivClient\acerrmes.dll
c:\program files\ActivIdentity\ActivClient\aiwinext.dll
c:\program files\ActivIdentity\ActivClient\aspcom.dll
c:\program files\ActivIdentity\ActivClient\Resources\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\asphatrc.dll
c:\program files\ActivIdentity\ActivClient\acunlock.dll
c:\program files\ActivIdentity\ActivClient\aipingui.dll
c:\program files\ActivIdentity\ActivClient\aicext.dll
c:\program files\ActivIdentity\ActivClient\Resources\aipinguirc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\acunlockrc.dll
.
- - - - - - - > 'explorer.exe'(3080)
c:\windows\system32\WININET.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2013-06-01 14:22:00 - machine was rebooted
ComboFix-quarantined-files.txt 2013-06-01 19:21
ComboFix2.txt 2013-06-01 17:13
ComboFix3.txt 2013-05-31 02:35
.
Pre-Run: 233,809,641,472 bytes free
Post-Run: 233,822,400,512 bytes free
.
- - End Of File - - 345DDABECF621764A17CE586CBFCF872







~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Microsoft Windows XP x86
Ran by [removed] on Sat 06/01/2013 at 14:33:25.87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] browserprotect
Successfully deleted: [Service] browserprotect
Successfully stopped: [Service] cltmngsvc
Successfully deleted: [Service] cltmngsvc



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotect
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotectall
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\smessaging
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babylontoolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylontoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\datamngr_toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\freeze.com
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\searchqutoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\stronghold online backup
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Babylon
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\windows\currentversion\ext\bprotectsettings
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\browserconnection.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\dnsbho.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escort.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escortapp.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escorteng.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\escortlbr.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\esrv.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\genericasktoolbar.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\scripthelper.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\appid\viprotocol.dll
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\b
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\babylon.dskbnd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\babylon.dskbnd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\delta.deltaappcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\delta.deltaappcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.deltaesrvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.deltaesrvc.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\a28b4d68debaa244eb686953b7074fef
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\3192aa38321c641458dbdaf83979d193
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\a28b4d68debaa244eb686953b7074fef
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\searchquiehelper.dnsguard
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\searchquiehelper.dnsguard.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT3106777
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn"
Successfully deleted: [Registry Key] "hkey_current_user\software\asktoolbar"
Successfully deleted: [Registry Key] "hkey_local_machine\software\apn"
Successfully deleted: [Registry Key] "hkey_local_machine\software\asktoolbar"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\0cfe535c35f99574e8340bfa75bf92c2"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\0e12f736682067fde4d1158d5940a82e"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\120dfadeb50841f408f04d2a278f9509"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\1a24b5bb8521b03e0c8d908f5abc0ae6"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\261f213d1f55267499b1f87d0cc3bcf7"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\2b0d56c4f4c46d844a57ffed6f0d2852"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\49d4375fe41653242aea4c969e4e65e0"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\6aa0923513360135b272e8289c5f13fa"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\6f7467af8f29c134cbbab394eccfde96"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\741b4adf27276464790022c965ab6da8"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\7de196b10195f5647a2b21b761f3de01"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\922525dcc5199162f8935747ca3d8e59"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\9d4f5849367142e4685ed8c25e44c5ed"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\a5875b04372c19545beb90d4d606c472"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\a876d9e80b896ec44a8620248cc79296"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\b66ffab725b92594c986de826a867888"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\bcda179d619b91648538e3394cac94cc"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\d677b1a9671d4d4004f6f2a4469e86ea"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\dd1402a9dd4215a43abde169a41afa0e"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\e36e114a0ead2ad46b381d23ad69cddf"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\components\ef8e618db3aedfbb384561b5c548f65e"
Successfully deleted: [Registry Key] "hkey_local_machine\software\microsoft\windows\currentversion\installer\userdata\s-1-5-18\products\a28b4d68debaa244eb686953b7074fef"



~~~ Files

Successfully deleted: [File] "C:\end"
Successfully deleted: [File] C:\WINDOWS\prefetch\BABYLONTOOLBARSRV.EXE-08CD5ADB.pf
Successfully deleted: [File] "C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job"



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\babylon"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\boost_interprocess"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\browserprotect"
Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\strongvault online backup"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\babsolution"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\babylon"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\babylontoolbar"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\delta"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\searchprotect"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\searchquband"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\searchqutoolbar"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\strongvault"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Application Data\swvupdater"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\appdata\locallow\datamngr"
Failed to delete: [Folder] "C:\Documents and Settings\Admin John\Local Settings\Application Data\conduit"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Local Settings\Application Data\strongvault"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Local Settings\Application Data\strongvault online backup"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\Local Settings\Application Data\winzipbar"
Successfully deleted: [Folder] "C:\Program Files\babylontoolbar"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\delta"
Successfully deleted: [Folder] "C:\Program Files\free offers from freeze.com"
Successfully deleted: [Folder] "C:\Program Files\searchprotect"
Failed to delete: [Folder] "C:\Program Files\searchqu toolbar"
Successfully deleted: [Folder] "C:\Program Files\strongvault online backup"
Successfully deleted: [Folder] "C:\Program Files\winzipbar"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\start menu\programs\BrowserProtect"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\start menu\programs\strongvault online backup"
Successfully deleted: [Folder] "C:\WINDOWS\system32\ai_recyclebin"
Successfully deleted: [Folder] "C:\ai_recyclebin"
Successfully deleted: [Folder] "C:\Program Files\ask.com"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin John\local settings\application data\asktoolbar"
Successfully deleted: [Folder] "C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}"



~~~ FireFox

Successfully deleted: [File] C:\user.js
Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\search_results.xml"
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\user.js
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\bprotector_extensions.sqlite
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\bprotector_prefs.js
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\searchplugins\babylon.xml
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\searchplugins\browserprotect.xml
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\searchplugins\conduit.xml
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\searchplugins\delta.xml
Successfully deleted: [File] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\searchplugins\search_results.xml
Failed to delete: [Folder] "C:\Program Files\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}"
Successfully deleted: [Folder] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\searchqutoolbar
Successfully deleted: [Folder] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\extensions\[removed]
Successfully deleted: [Folder] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\extensions\[removed]
Failed to delete: [Folder] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
Failed to delete: [Folder] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\extensions\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
Successfully deleted: [Folder] C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\extensions\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Successfully deleted the following from C:\Documents and Settings\Admin John\Application Data\mozilla\firefox\profiles\z9680u01.default\prefs.js

user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?affID=119351&tt=300513_ctrl&babsrc=NT_ss&mntrId=ACA3001D72B2F71C");
user_pref("browser.search.defaultenginename", "Search Results");
user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New Customized Web Search");
user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&CUI=UN29983022311797271&UM=2&SearchSource=3&q={searchTerms}&sspv=TB_TFS");
user_pref("browser.search.order.1", "Delta Search");
user_pref("browser.search.selectedEngine", "Delta Search");
user_pref("browser.startup.homepage", "hxxp://search.babylon.com/?affID=119351&tt=300513_ctrl&babsrc=HP_ss_gin2g&mntrId=ACA3001D72B2F71C");
user_pref("CT3289847.originalSearchAddressUrl", "hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=102&sr=0&q=");
user_pref("CT3289847.originalSearchEngine", "Delta Search");
user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN29983022311797271&UM=2&sspv=TB_TFS&q=");
user_pref("smartbar.addressBarOwnerCTID", "CT3289847");
user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289847&octid=CT3289847&SearchSource=61&CUI=UN29983022311797271&UM=2&UP=SP2E7C3E74-4200-4D66-9CE2-
user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289847&SearchSource=2&CUI=UN29983022311797271&UM=2&sspv=TB_TFS&q=");
user_pref("smartbar.defaultSearchOwnerCTID", "CT3289847");
user_pref("smartbar.originalHomepage", "hxxp://www.delta-search.com/?affID=119351&tt=300513_ctrl&babsrc=HP_ss&mntrId=ACA3001D72B2F71C");
user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=102&sr=0&q=");



~~~ Chrome

Successfully deleted: [Folder] C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 06/01/2013 at 14:39:15.92
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





# AdwCleaner v2.301 - Logfile created 06/01/2013 at 14:50:38
# Updated 16/05/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Admin John - JOHNS-E-MACHINE
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Admin John\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Documents and Settings\Admin John\Application Data\Mozilla\Firefox\Profiles\z9680u01.default\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}
Deleted on reboot : C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb
Deleted on reboot : C:\Documents and Settings\Jaguer\Local Settings\Application Data\WinZipBar
Deleted on reboot : C:\Program Files\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
File Deleted : C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\bProtector Web Data
File Deleted : C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\bprotectorpreferences
File Deleted : C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage
File Deleted : C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_apps.conduit.com_0.localstorage-journal
File Deleted : C:\Documents and Settings\Jaguer\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Deleted : C:\Documents and Settings\Jaguer\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
File Deleted : C:\WINDOWS\Tasks\AmiUpdXp.job
File Deleted : C:\WINDOWS\Tasks\EPUpdater.job
Folder Deleted : C:\Documents and Settings\Admin John\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\Jaguer\Application Data\BabylonToolbar
Folder Deleted : C:\Documents and Settings\Jaguer\Application Data\Mozilla\Firefox\Profiles\4qzj026y.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
Folder Deleted : C:\Documents and Settings\Jaguer\Application Data\Mozilla\Firefox\Profiles\4qzj026y.default\extensions\[removed]
Folder Deleted : C:\Documents and Settings\Jaguer\Application Data\Mozilla\Firefox\Profiles\4qzj026y.default\Searchqutoolbar
Folder Deleted : C:\Documents and Settings\Jaguer\Application Data\Searchqutoolbar
Folder Deleted : C:\Documents and Settings\Jaguer\Local Settings\Application Data\AskToolbar
Folder Deleted : C:\Documents and Settings\Jaguer\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\John\Application Data\SearchProtect
Folder Deleted : C:\Documents and Settings\John\Application Data\Searchqutoolbar
Folder Deleted : C:\Documents and Settings\John\Local Settings\Application Data\AskToolbar
Folder Deleted : C:\Documents and Settings\John_2\Application Data\BabylonToolbar
Folder Deleted : C:\Documents and Settings\John_2\Application Data\Searchqutoolbar
Folder Deleted : C:\Documents and Settings\John_2\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\John_2\Local Settings\Application Data\WinZipBar
Folder Deleted : C:\Documents and Settings\NetworkService\Local Settings\Application Data\WinZipBar
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files\Searchqu Toolbar
Folder Deleted : C:\Program Files\SingAlong
Folder Deleted : C:\WINDOWS\Installer\{EBE677C0-CBCB-4EBF-8098-E27E1B5271CF}

***** [Registry] *****

Key Deleted : HKCU\Software\a558fdab03dbe17
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6492E171-2427-4932-B414-33574A089F5E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6492E171-2427-4932-B414-33574A089F5E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\WinZipBar
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\a558fdab03dbe17
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6492E171-2427-4932-B414-33574A089F5E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Key Deleted : HKLM\Software\Classes\Installer\Features\3192AA38321C641458DBDAF83979D193
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FD8F79A0-D2E2-4FA2-AEAF-393EAC8064F7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\DomaIQ
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\cgpnojibjokpoghebklhkdeijehkohhb
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6234D26E-2501-4808-9FA5-D17C62CC9533}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E22B150-E4CC-4E01-B54B-37B69E399FE2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater
Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DATAMNGR
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinZipBar Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6492E171-2427-4932-B414-33574A089F5E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9280CAA3-237E-468E-A41C-43EADB5FF61A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DA5BD2D3CA2D6943A1A233CD3F88CE7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BDF3E992C0908741B7C11F4B4E0F775
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC9EFC5C3366B4DB850DAB49330C52
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B3BC4CF5ECE1F54BBA174C13A1AB907
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E98451C7CA808F47AFE467BDABD02FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BAE2ED018083A4C8DA86D6E3F4B024
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEABAA33A5E68374DBF197F2A00CD011
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFD11FD45FC7B9E46A8F4B69F3A66E35
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB61AF52AD64B6B45930BE969F316720
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5979AD63CA2D6943A1A233CD3F88CE7
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF9BD2952384A9C49B4A5D3D95329890
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FABA2A33488410A4AA40489BD2224282
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83AA2913-C123-4146-85BD-AD8F93971D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EBE677C0-CBCB-4EBF-8098-E27E1B5271CF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZipBar Toolbar
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\WinZipBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [[removed]]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - bProtectTabs] = hxxp://www.delta-search.com/?affID=119351&tt=300513_ctrl&babsrc=NT_ss&mntrId=ACA3001D72B2F71C –> hxxp://www.google.com

-\\ Mozilla Firefox v16.0.2 (en-US)

File : C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\1exmm956.default\prefs.js

[OK] File is clean.

File : C:\Documents and Settings\Admin John\Application Data\Mozilla\Firefox\Profiles\z9680u01.default\prefs.js

[OK] File is clean.

File : C:\Documents and Settings\Jaguer\Application Data\Mozilla\Firefox\Profiles\4qzj026y.default\prefs.js

Deleted : user_pref("browser.startup.homepage", "hxxp://www.searchnu.com/102");
Deleted : user_pref("keyword.URL", "hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=102&sr=0&q=");

-\\ Google Chrome v27.0.1453.94

File : C:\Documents and Settings\Admin John\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

Deleted [l.1] : icon_url ={"apps_promo_counter":11,"browser":{"check_default_browser":false,"clear_lso_data_enabled":true,"las[…]

File : C:\Documents and Settings\John_2\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

File : C:\Documents and Settings\Jaguer\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v12.0.1467.0

File : C:\Documents and Settings\John\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

File : C:\Documents and Settings\Admin John\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

File : C:\Documents and Settings\John_2\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

File : C:\Documents and Settings\Jaguer\Application Data\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [20578 octets] - [01/06/2013 14:50:38]

########## EOF - C:\AdwCleaner[S1].txt - [20639 octets] ##########


fbfbfb,

The computer is running faster than before. redirects to fake computer malware "fix" sites are no longiner nagging me. Sor far, so good!
Hello, SkinnyTex.

Glad to hear that your computer has shown improvement. Please stay with me until I have determined that your system is completely clean and safe.

Please run the following scans

1. Malwarebytes Anti-Malware

Please download Malwarebytes from Here or Here.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan
.[external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Post the report please.

2. ESET Online Scanner

Note:

  • Disable any antivirus program and antispyware programs to avoid conflicts.
  • Run ESET in Internet Explorer, or, if using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted, then double click on it to install.
  • Please do not surf the internet while your security programs are disabled.
  • Let the scan run uninterrupted to avoid a stall.
  • Remember to enable your security programs when the scan has finished.
Run ESET Online Scanner from HERE.
  • Click the green ESET Online Scanner button.
  • Read the End User License Agreement and check the box YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • If prompted, allow the Add-On/Active X to install.
Under Computer scan settings:
  • Do not check Remove found threats
  • Check Scan Archives.
  • Click Advanced settings and select the following:

  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology

  • Click Start. ESET will download updates, install itself, and begin scanning your computer. Please be patient as this scan could take up to a few hours to complete.
  • Wait for the scan to finish. When the scan completes, click List of found threats.
  • Click Export and save the file to your desktop using a unique name, such as ESETScan.
  • Copy and paste the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
fb, I have the MBAM log - here you go: Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.06.05.01 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Administrator :: JOHNS-E-MACHINE [administrator] Protection: Enabled 6/4/2013 8:38:10 PM mbam-log-2013-06-04 (20-38-10).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 302186 Time elapsed: 11 minute(s), 52 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) The EET ran all night - it took over 4 hours. When I got home to send you the log, it was not there. I am running the scan again and will stay up for it this time (work is hectic). I will attach that log tonight or tomorrow when I complete it. I ran the EET from the Internet via IE8. I saw the screen where I had 38 files infected. Starting again next… SkinnyTex

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI