rsglick
-
Posts
31 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by rsglick
-
-
That website was in red. I did try going to it and it worked fine. I know the people who are also associated with the site. It also is showing legit websites like microsoft as red.
-
I'm not really sure what I'm supposed to do or copy when I run that program. Do I just run it all the time and look for all the red ones and post them here? Is there a log for it? I'm not really sure what you want me to show you.
-
[Fiddler] The socket connection to www.crazycampground.com failed. A Firewall may be blocking Fiddler's traffic.
ErrorCode: 10013.
An attempt was made to access a socket in a way forbidden by its access permissions 74.208.30.205:80
-
Ok I've installed it. What do I do now?
-
nope it didn't work.
2012/06/25 16:03:30 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53610, Process: chrome.exe)
2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53651, Process: chrome.exe)
2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53652, Process: chrome.exe)
2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53653, Process: chrome.exe)
2012/06/25 16:08:12 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53694, Process: chrome.exe)
2012/06/25 16:08:12 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53695, Process: chrome.exe)
2012/06/25 16:35:27 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 54127, Process: chrome.exe)
-
On a side note, I had the freemake video converter plugin for chrome installled. I just uninstalled it so I can see if that was what was doing it. I have no other extensions installed on chrome. I will keep you advised.
-
I'm still getting the IP block message from the same IP.
2012/06/25 11:41:42 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 50805, Process: chrome.exe)
2012/06/25 11:41:42 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 50817, Process: chrome.exe)
2012/06/25 13:28:58 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 51419, Process: chrome.exe)
2012/06/25 13:29:38 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 51424, Process: chrome.exe)
-
I haven't got the IP block message as of yet. It was sporadic at best. I will watch it closely and if I get more I will post back. Either way I will wait a week or so, if I don't get anymore IP blocks from that same IP I will have to consider it fixed.
-
I fully uninstalled firefox and chrome. I have run CCleaner to make sure it was out of my registry. I have just installed chrome only.
-
Can I keep my book marks? I have alot I dont want to lose
-
yes and each time it shows chrome.exe at the bottom of the malware message
2012/06/24 07:30:31 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49846, Process: chrome.exe)
2012/06/24 07:31:20 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49869, Process: chrome.exe)
2012/06/24 07:32:08 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49882, Process: chrome.exe)
2012/06/24 07:32:24 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49888, Process: chrome.exe)
2012/06/24 07:34:49 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49968, Process: chrome.exe)
It does it for firefox also.
Also just fyi, I had backed up my C drive onto my E drive as requested by my machine utilities. So I just deleted that off my E drive so now there is no copy of the C drive on my E drive. I'm wondering if all the scans we were doing for the C drive was also scanning the E drive.
-
ok i was able to compress the quarantine subfolder
-
I rebooted and its telling me the same thing.
-
It won't allow me to compress it. I've included a screen shot of the message I'm getting. http://img341.imageshack.us/img341/8600/69687001.jpg
-
Scan of both C drive and E drive completed. I have uploaded an image of it.
-
ComboFix 12-06-21.03 - Ronald Glickman 06/22/2012 21:06:37.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8102.4619 [GMT -4:00]
Running from: e:\rsg downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ronald Glickman\AppData\Local\Temp\0fc113bebd3c.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\19d20a6fbc7a.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\445fec56af0e.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\5a07244160fb.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\6e050972a7cc.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\71c12d7a8180.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\71ca0fe59f0c.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\791722b78375.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\ad0f0f8f62a5.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\bceff7d56bff.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\bed204085de1.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\cb08234cf0e7.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\f111f32f3afb.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\f4f018b21319.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\NGC1E9.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\NGC939.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\NGCABE.tmp
c:\users\RONALD~1\AppData\Local\Temp\0fc113bebd3c.tmp
c:\users\RONALD~1\AppData\Local\Temp\19d20a6fbc7a.tmp
c:\users\RONALD~1\AppData\Local\Temp\445fec56af0e.tmp
c:\users\RONALD~1\AppData\Local\Temp\5a07244160fb.tmp
c:\users\RONALD~1\AppData\Local\Temp\6e050972a7cc.tmp
c:\users\RONALD~1\AppData\Local\Temp\71c12d7a8180.tmp
c:\users\RONALD~1\AppData\Local\Temp\71ca0fe59f0c.tmp
c:\users\RONALD~1\AppData\Local\Temp\791722b78375.tmp
c:\users\RONALD~1\AppData\Local\Temp\ad0f0f8f62a5.tmp
c:\users\RONALD~1\AppData\Local\Temp\bceff7d56bff.tmp
c:\users\RONALD~1\AppData\Local\Temp\bed204085de1.tmp
c:\users\RONALD~1\AppData\Local\Temp\cb08234cf0e7.tmp
c:\users\RONALD~1\AppData\Local\Temp\f111f32f3afb.tmp
c:\users\RONALD~1\AppData\Local\Temp\f4f018b21319.tmp
c:\users\RONALD~1\AppData\Local\Temp\NGC1E9.tmp
c:\users\RONALD~1\AppData\Local\Temp\NGC939.tmp
c:\users\RONALD~1\AppData\Local\Temp\NGCABE.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-05-23 to 2012-06-23 )))))))))))))))))))))))))))))))
.
.
2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-23 00:05 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54DB061F-FB9C-4663-9424-F36FA76DE9DA}\mpengine.dll
2012-06-22 23:05 . 2012-06-22 23:05 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-22 23:05 . 2012-06-22 23:05 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-22 23:05 . 2012-06-22 23:05 -------- d-----w- c:\program files\Java
2012-06-22 15:37 . 2012-06-22 15:53 -------- d-----w- c:\users\Ronald Glickman\DoctorWeb
2012-06-22 13:32 . 2012-06-22 13:32 -------- d-----w- c:\programdata\Kaspersky Lab
2012-06-22 12:25 . 2012-06-22 12:25 -------- d-----w- c:\program files (x86)\ESET
2012-06-22 01:34 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-21 19:07 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-21 19:07 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-21 19:07 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-21 19:07 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-21 19:07 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-21 19:07 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-21 19:07 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-21 19:07 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-21 19:07 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-19 16:31 . 2012-06-19 22:24 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-06-19 16:31 . 2012-06-22 19:56 -------- d-----w- c:\program files (x86)\Steam
2012-06-16 22:16 . 2012-06-16 22:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\MAGIX
2012-06-16 16:24 . 2012-06-16 16:24 -------- d-----w- c:\windows\SysWow64\RTCOM
2012-06-16 12:06 . 2012-06-16 12:06 -------- d-----w- c:\programdata\Nexon
2012-06-16 12:02 . 2012-06-16 12:02 -------- d-----w- C:\Nexon
2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\program files\Microsoft IntelliPoint
2012-06-13 18:46 . 2012-06-13 18:56 -------- d-----w- c:\program files (x86)\Razer
2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Razer
2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\programdata\Razer
2012-06-13 10:17 . 2011-12-12 21:42 1256192 ----a-w- c:\windows\system32\drivers\bcmwlhigh664.sys
2012-06-13 10:17 . 2011-04-19 21:52 95544 ----a-w- c:\windows\system32\bcmwlcoi.dll
2012-06-13 10:17 . 2011-04-19 21:31 3900928 ----a-w- c:\windows\system32\bcmihvsrv64.dll
2012-06-13 10:17 . 2011-04-19 21:31 3566592 ----a-w- c:\windows\system32\bcmihvui64.dll
2012-06-13 10:17 . 2010-06-09 17:11 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2012-06-13 10:17 . 2010-02-03 15:20 47632 ----a-w- c:\windows\system32\drivers\npf.sys
2012-06-13 10:17 . 2011-07-22 14:33 25056 ----a-w- c:\windows\system32\drivers\SCMNdisP.sys
2012-06-13 10:17 . 2012-06-13 10:17 -------- d-----w- c:\program files (x86)\NETGEAR
2012-06-12 18:42 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-06-12 17:12 . 2012-06-12 17:12 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2012-06-12 17:03 . 2012-06-12 17:03 -------- d-----w- c:\programdata\EA Core
2012-06-12 17:03 . 2012-06-13 17:40 -------- d-----w- c:\programdata\EA Logs
2012-06-12 16:35 . 2007-10-12 19:14 2006552 ----a-w- c:\windows\system32\D3DCompiler_36.dll
2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5DD60F6-F67B-4B8C-AF21-C5E783A93374}\gapaengine.dll
2012-06-12 14:59 . 2012-06-12 15:00 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Origin
2012-06-12 14:59 . 2012-06-12 14:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Origin
2012-06-12 14:58 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Electronic Arts
2012-06-12 14:58 . 2012-06-12 16:11 -------- d-----w- c:\program files (x86)\Origin Games
2012-06-12 14:58 . 2012-06-12 15:00 -------- d-----w- c:\program files (x86)\Origin
2012-06-12 14:44 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Origin
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-06-11 21:50 . 2012-06-11 21:51 -------- d-----w- c:\program files (x86)\QuickTime
2012-06-11 13:34 . 2012-06-11 13:34 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\OpenOffice.org
2012-06-11 13:22 . 2012-06-11 13:22 -------- d-----w- c:\program files\CCleaner
2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\programdata\IObit
2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\program files (x86)\IObit
2012-06-10 15:52 . 2012-06-10 15:52 -------- d-----w- c:\programdata\McAfee
2012-06-10 15:52 . 2012-06-16 22:26 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-10 15:52 . 2012-06-16 22:26 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-10 15:21 . 2012-06-10 15:21 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Tipard Studio
2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\programdata\Tipard MKV Video Converter
2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\program files (x86)\Tipard Studio
2012-06-10 12:55 . 2012-06-10 12:55 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Macromedia
2012-06-08 14:16 . 2012-06-08 14:16 -------- d-----w- c:\program files (x86)\Virtual Magnifying Glass
2012-06-07 21:19 . 2012-06-18 03:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\JPEGsnoop
2012-06-06 13:08 . 2012-06-06 13:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\TouchStoneSoftware
2012-06-04 23:37 . 2011-05-28 04:29 67176 ----a-w- c:\windows\system32\OpenCL.dll
2012-06-04 23:37 . 2011-05-28 04:29 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-06-04 21:59 . 2012-03-11 06:17 121344 ----a-w- c:\windows\system32\IntelOpenCL64.dll
2012-06-04 21:59 . 2012-03-11 06:09 86528 ----a-w- c:\windows\SysWow64\IntelOpenCL32.dll
2012-06-04 19:14 . 2012-06-21 00:03 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-06-04 19:13 . 2012-06-12 17:13 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\PunkBuster
2012-06-04 18:59 . 2012-06-04 18:59 -------- d-----w- c:\program files (x86)\EA Games
2012-06-04 13:25 . 2012-06-04 13:25 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-06-04 13:24 . 2012-06-04 13:24 -------- d-----w- c:\program files (x86)\Oracle
2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\SystemRequirementsLab
2012-06-03 23:27 . 2012-06-03 23:27 -------- d-----w- c:\program files (x86)\ImageShack Uploader
2012-06-03 18:54 . 2011-11-08 14:18 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-06-03 18:54 . 2011-11-08 14:18 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-06-03 18:54 . 2009-12-05 23:42 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-06-03 18:54 . 2012-06-03 18:54 -------- d-----w- c:\program files (x86)\ffdshow
2012-06-03 18:45 . 2012-06-22 20:42 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\vlc
2012-06-03 18:44 . 2012-06-03 18:44 -------- d-----w- c:\program files (x86)\VideoLAN
2012-06-03 15:21 . 2011-09-16 15:28 210432 ----a-w- c:\program files\Windows Sidebar\Shared Gadgets\InstantOn.gadget\InstantOnCOM.dll
2012-06-03 15:21 . 2012-06-03 15:21 -------- d-----w- c:\program files (x86)\Common Files\InstantOn
2012-06-03 04:31 . 2012-05-15 10:48 249152 ----a-w- c:\windows\system32\drivers\nvkflt.sys
2012-06-03 04:31 . 2012-05-15 10:48 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
2012-06-03 04:31 . 2012-05-15 10:48 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
2012-06-03 04:30 . 2012-06-03 04:30 -------- d-----w- C:\NVIDIA
2012-06-02 06:40 . 2012-06-08 21:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\X-Chat 2
2012-06-02 06:40 . 2012-06-02 06:40 -------- d-----w- c:\program files (x86)\xchat
2012-06-01 23:32 . 2012-06-01 23:32 -------- d-----w- c:\program files (x86)\Moffsoft FreeCalc
2012-06-01 15:44 . 2010-10-01 04:16 13312 ----a-w- c:\windows\system32\drivers\VKbms.sys
2012-06-01 15:44 . 2010-09-30 00:45 6656 ----a-w- c:\windows\system32\drivers\hidkmdf.sys
2012-06-01 13:00 . 2012-06-01 13:00 -------- d-----w- c:\program files (x86)\CleanUp!
2012-05-31 23:34 . 2012-06-22 18:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Akamai
2012-05-31 23:01 . 2012-05-31 23:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Diagnostics
2012-05-31 22:13 . 2012-05-31 22:13 -------- d-----w- c:\programdata\WEBREG
2012-05-31 22:10 . 2012-06-07 23:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\HP
2012-05-31 22:10 . 2012-05-31 22:10 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\HP
2012-05-31 22:09 . 2009-06-09 05:48 249856 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpfpp092.dll
2012-05-31 22:08 . 2012-05-31 22:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Yahoo!
2012-05-31 22:08 . 2012-06-10 12:35 -------- d-----w- c:\program files (x86)\Yahoo!
2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\programdata\HP Product Assistant
2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\windows\SysWow64\spool
2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\HP
2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\Hewlett-Packard
2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\windows\hpoj4500g510n-z
2012-05-31 22:03 . 2009-05-26 17:32 902656 ----a-w- c:\windows\system32\hpwwiax9.dll
2012-05-31 22:03 . 2009-05-26 17:32 742912 ----a-w- c:\windows\system32\hpwtscl5.dll
2012-05-31 22:03 . 2009-05-26 17:32 503296 ----a-w- c:\windows\system32\hpwvst01.dll
2012-05-31 22:03 . 2009-05-18 21:51 551424 ----a-w- c:\windows\system32\hppldcoi.dll
2012-05-31 22:03 . 2009-05-21 13:14 642360 ----a-w- c:\windows\system32\hpzids40.dll
2012-05-31 22:03 . 2009-06-09 05:48 136704 ----a-w- c:\windows\system32\hpf3l092.dll
2012-05-31 22:02 . 2012-05-31 22:07 -------- d-----w- c:\program files (x86)\HP
2012-05-31 22:00 . 2012-05-31 22:11 -------- d-----w- c:\programdata\HP
2012-05-31 21:54 . 2012-05-31 21:54 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\FLEXnet
2012-05-31 20:38 . 2012-01-31 12:44 279656 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-23 00:08 . 2011-09-11 17:24 45056 ----a-w- c:\windows\SysWow64\acovcnt.exe
2012-05-15 21:59 . 2010-06-24 18:33 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-15 10:48 . 2011-09-11 17:06 949056 ----a-w- c:\windows\system32\nvumdshimx.dll
2012-05-15 10:48 . 2011-09-11 17:06 818496 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2012-05-15 10:48 . 2011-09-11 17:06 246592 ----a-w- c:\windows\system32\nvinitx.dll
2012-05-15 10:48 . 2011-09-11 17:06 202048 ----a-w- c:\windows\SysWow64\nvinit.dll
2012-05-15 10:48 . 2011-09-11 17:06 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-05-15 10:48 . 2011-09-11 17:06 2741568 ----a-w- c:\windows\system32\nvapi64.dll
2012-05-15 10:48 . 2011-09-11 17:06 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-05-15 09:29 . 2011-05-27 13:38 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-05-15 09:29 . 2011-05-27 13:38 858944 ----a-w- c:\windows\system32\nv3dappshext.dll
2012-05-15 09:29 . 2011-05-27 16:38 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-05-15 09:29 . 2011-05-27 13:38 55616 ----a-w- c:\windows\system32\nv3dappshextr.dll
2012-05-15 09:29 . 2011-05-27 13:38 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-05-15 09:29 . 2011-05-27 13:38 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-15 09:29 . 2011-05-27 16:38 2621723 ----a-w- c:\windows\system32\nvcoproc.bin
2012-05-15 09:29 . 2011-05-27 13:38 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-05-15 09:28 . 2011-05-27 13:38 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-15 06:21 . 2012-05-15 06:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-05-15 02:50 . 2012-05-15 02:50 20992 ----a-w- c:\windows\system32\drivers\rzvkeyboard.sys
2012-05-15 02:50 . 2012-05-15 02:50 94208 ----a-w- c:\windows\system32\drivers\rzudd.sys
2012-05-15 02:36 . 2012-05-15 02:36 142848 ----a-w- c:\windows\SysWow64\rztouchdll.dll
2012-05-15 02:36 . 2012-05-15 02:36 354816 ----a-w- c:\windows\SysWow64\rzdevicedll.dll
2012-05-15 02:36 . 2012-05-15 02:36 165888 ----a-w- c:\windows\SysWow64\rzaudiodll.dll
2012-05-08 02:46 . 2012-05-08 02:46 7168 ----a-w- c:\windows\system32\drivers\rzkbdhid.sys
2012-05-08 02:46 . 2012-05-08 02:46 26112 ----a-w- c:\windows\system32\drivers\rzdaendpt.sys
2012-04-19 00:56 . 2012-04-19 00:56 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-04-19 00:56 . 2012-04-19 00:56 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2012-04-04 22:47 . 2012-05-15 22:15 772504 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-04-04 22:47 . 2012-05-15 22:15 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-04 19:56 . 2012-05-15 22:19 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-30 11:35 . 2012-05-16 22:10 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-22_00.58.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-18 20:13 . 2012-06-23 00:09 57462 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-06-23 00:09 42110 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-05-15 22:00 . 2012-06-23 00:09 12236 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-953877884-1205063476-829431027-1001_UserData.bin
+ 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-22 23:05 . 2012-06-22 23:05 268720 c:\windows\system32\javaws.exe
+ 2012-06-22 23:05 . 2012-06-22 23:05 189360 c:\windows\system32\javaw.exe
+ 2012-06-22 23:05 . 2012-06-22 23:05 188840 c:\windows\system32\java.exe
+ 2009-07-14 05:01 . 2012-06-23 00:06 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-06-22 00:48 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-06-22 23:04 . 2012-06-22 23:04 891392 c:\windows\Installer\104132a.msi
- 2012-05-15 22:03 . 2012-06-22 00:48 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat
+ 2012-05-15 22:03 . 2012-06-23 00:06 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat
- 2012-05-15 23:49 . 2012-06-21 23:15 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat
+ 2012-05-15 23:49 . 2012-06-23 00:07 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-02 2018032]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472]
"SonicMasterTray"="c:\program files (x86)\ASUS\SonicMaster\SonicMasterTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"RemoteControl10"="c:\program files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-11-12 75048]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-11-24 222504]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2012-05-29 313768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-4-2 549040]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe [2012-5-31 12862]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
NETGEAR WNDA3100v2 Genie.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-6-13 8453376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/09/11 10:30;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-11-12 241648]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]
R2 WSWNDA3100v2;WSWNDA3100v2;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2011-12-14 303360]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-16 257224]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]
R3 cphs;Intel® Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-03-20 276248]
R3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\Drivers\CYUSB.sys [x]
R3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files (x86)\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024]
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-09-08 92800]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-13 138400]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-01-14 1839616]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S2 Splashtop MDES;Splashtop Meta Data Export Service;c:\asus.sys\SIONExportService.exe [2011-05-10 338208]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]
S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]
S3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 rzdaendpt;%rzdaendpt.SvcDesc%;c:\windows\system32\DRIVERS\rzdaendpt.sys [x]
S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys [x]
S3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - CLKMDRV10_38F51D56
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-10 22:26]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2011-03-21 361984]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552]
"SynAsusAcpi"="c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe" [bU]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Ronald Glickman\AppData\Roaming\Mozilla\Firefox\Profiles\k2hn4jp8.default\
FF - prefs.js: browser.startup.homepage - hxxp://combatarms.nexon.net/|http://battlelog.battlefield.com/bf3/gate/|http://forums.thecbl.net/ucp.php?mode=login|http://yellowsnowarmy.com/
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-06-22 21:12:56
ComboFix-quarantined-files.txt 2012-06-23 01:12
ComboFix2.txt 2012-06-22 01:00
.
Pre-Run: 382,098,587,648 bytes free
Post-Run: 381,901,774,848 bytes free
.
- - End Of File - - 26733B94D1EF8A46D71C0A005273615D
-
ComboFix 12-06-21.03 - Ronald Glickman 06/22/2012 21:06:37.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8102.4619 [GMT -4:00]
Running from: e:\rsg downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ronald Glickman\AppData\Local\Temp\0fc113bebd3c.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\19d20a6fbc7a.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\445fec56af0e.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\5a07244160fb.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\6e050972a7cc.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\71c12d7a8180.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\71ca0fe59f0c.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\791722b78375.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\ad0f0f8f62a5.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\bceff7d56bff.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\bed204085de1.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\cb08234cf0e7.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\f111f32f3afb.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\f4f018b21319.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\NGC1E9.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\NGC939.tmp
c:\users\Ronald Glickman\AppData\Local\Temp\NGCABE.tmp
c:\users\RONALD~1\AppData\Local\Temp\0fc113bebd3c.tmp
c:\users\RONALD~1\AppData\Local\Temp\19d20a6fbc7a.tmp
c:\users\RONALD~1\AppData\Local\Temp\445fec56af0e.tmp
c:\users\RONALD~1\AppData\Local\Temp\5a07244160fb.tmp
c:\users\RONALD~1\AppData\Local\Temp\6e050972a7cc.tmp
c:\users\RONALD~1\AppData\Local\Temp\71c12d7a8180.tmp
c:\users\RONALD~1\AppData\Local\Temp\71ca0fe59f0c.tmp
c:\users\RONALD~1\AppData\Local\Temp\791722b78375.tmp
c:\users\RONALD~1\AppData\Local\Temp\ad0f0f8f62a5.tmp
c:\users\RONALD~1\AppData\Local\Temp\bceff7d56bff.tmp
c:\users\RONALD~1\AppData\Local\Temp\bed204085de1.tmp
c:\users\RONALD~1\AppData\Local\Temp\cb08234cf0e7.tmp
c:\users\RONALD~1\AppData\Local\Temp\f111f32f3afb.tmp
c:\users\RONALD~1\AppData\Local\Temp\f4f018b21319.tmp
c:\users\RONALD~1\AppData\Local\Temp\NGC1E9.tmp
c:\users\RONALD~1\AppData\Local\Temp\NGC939.tmp
c:\users\RONALD~1\AppData\Local\Temp\NGCABE.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-05-23 to 2012-06-23 )))))))))))))))))))))))))))))))
.
.
2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-23 00:05 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54DB061F-FB9C-4663-9424-F36FA76DE9DA}\mpengine.dll
2012-06-22 23:05 . 2012-06-22 23:05 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-22 23:05 . 2012-06-22 23:05 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-22 23:05 . 2012-06-22 23:05 -------- d-----w- c:\program files\Java
2012-06-22 15:37 . 2012-06-22 15:53 -------- d-----w- c:\users\Ronald Glickman\DoctorWeb
2012-06-22 13:32 . 2012-06-22 13:32 -------- d-----w- c:\programdata\Kaspersky Lab
2012-06-22 12:25 . 2012-06-22 12:25 -------- d-----w- c:\program files (x86)\ESET
2012-06-22 01:34 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-21 19:07 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-21 19:07 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-21 19:07 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-21 19:07 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-21 19:07 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-21 19:07 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-21 19:07 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-21 19:07 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-21 19:07 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-19 16:31 . 2012-06-19 22:24 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-06-19 16:31 . 2012-06-22 19:56 -------- d-----w- c:\program files (x86)\Steam
2012-06-16 22:16 . 2012-06-16 22:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\MAGIX
2012-06-16 16:24 . 2012-06-16 16:24 -------- d-----w- c:\windows\SysWow64\RTCOM
2012-06-16 12:06 . 2012-06-16 12:06 -------- d-----w- c:\programdata\Nexon
2012-06-16 12:02 . 2012-06-16 12:02 -------- d-----w- C:\Nexon
2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\program files\Microsoft IntelliPoint
2012-06-13 18:46 . 2012-06-13 18:56 -------- d-----w- c:\program files (x86)\Razer
2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Razer
2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\programdata\Razer
2012-06-13 10:17 . 2011-12-12 21:42 1256192 ----a-w- c:\windows\system32\drivers\bcmwlhigh664.sys
2012-06-13 10:17 . 2011-04-19 21:52 95544 ----a-w- c:\windows\system32\bcmwlcoi.dll
2012-06-13 10:17 . 2011-04-19 21:31 3900928 ----a-w- c:\windows\system32\bcmihvsrv64.dll
2012-06-13 10:17 . 2011-04-19 21:31 3566592 ----a-w- c:\windows\system32\bcmihvui64.dll
2012-06-13 10:17 . 2010-06-09 17:11 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2012-06-13 10:17 . 2010-02-03 15:20 47632 ----a-w- c:\windows\system32\drivers\npf.sys
2012-06-13 10:17 . 2011-07-22 14:33 25056 ----a-w- c:\windows\system32\drivers\SCMNdisP.sys
2012-06-13 10:17 . 2012-06-13 10:17 -------- d-----w- c:\program files (x86)\NETGEAR
2012-06-12 18:42 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-06-12 17:12 . 2012-06-12 17:12 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2012-06-12 17:03 . 2012-06-12 17:03 -------- d-----w- c:\programdata\EA Core
2012-06-12 17:03 . 2012-06-13 17:40 -------- d-----w- c:\programdata\EA Logs
2012-06-12 16:35 . 2007-10-12 19:14 2006552 ----a-w- c:\windows\system32\D3DCompiler_36.dll
2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5DD60F6-F67B-4B8C-AF21-C5E783A93374}\gapaengine.dll
2012-06-12 14:59 . 2012-06-12 15:00 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Origin
2012-06-12 14:59 . 2012-06-12 14:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Origin
2012-06-12 14:58 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Electronic Arts
2012-06-12 14:58 . 2012-06-12 16:11 -------- d-----w- c:\program files (x86)\Origin Games
2012-06-12 14:58 . 2012-06-12 15:00 -------- d-----w- c:\program files (x86)\Origin
2012-06-12 14:44 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Origin
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
2012-06-11 21:50 . 2012-06-11 21:51 -------- d-----w- c:\program files (x86)\QuickTime
2012-06-11 13:34 . 2012-06-11 13:34 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\OpenOffice.org
2012-06-11 13:22 . 2012-06-11 13:22 -------- d-----w- c:\program files\CCleaner
2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\programdata\IObit
2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\program files (x86)\IObit
2012-06-10 15:52 . 2012-06-10 15:52 -------- d-----w- c:\programdata\McAfee
2012-06-10 15:52 . 2012-06-16 22:26 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-10 15:52 . 2012-06-16 22:26 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-06-10 15:21 . 2012-06-10 15:21 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Tipard Studio
2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\programdata\Tipard MKV Video Converter
2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\program files (x86)\Tipard Studio
2012-06-10 12:55 . 2012-06-10 12:55 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Macromedia
2012-06-08 14:16 . 2012-06-08 14:16 -------- d-----w- c:\program files (x86)\Virtual Magnifying Glass
2012-06-07 21:19 . 2012-06-18 03:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\JPEGsnoop
2012-06-06 13:08 . 2012-06-06 13:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\TouchStoneSoftware
2012-06-04 23:37 . 2011-05-28 04:29 67176 ----a-w- c:\windows\system32\OpenCL.dll
2012-06-04 23:37 . 2011-05-28 04:29 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-06-04 21:59 . 2012-03-11 06:17 121344 ----a-w- c:\windows\system32\IntelOpenCL64.dll
2012-06-04 21:59 . 2012-03-11 06:09 86528 ----a-w- c:\windows\SysWow64\IntelOpenCL32.dll
2012-06-04 19:14 . 2012-06-21 00:03 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-06-04 19:13 . 2012-06-12 17:13 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\PunkBuster
2012-06-04 18:59 . 2012-06-04 18:59 -------- d-----w- c:\program files (x86)\EA Games
2012-06-04 13:25 . 2012-06-04 13:25 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-06-04 13:24 . 2012-06-04 13:24 -------- d-----w- c:\program files (x86)\Oracle
2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\program files (x86)\SystemRequirementsLab
2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\SystemRequirementsLab
2012-06-03 23:27 . 2012-06-03 23:27 -------- d-----w- c:\program files (x86)\ImageShack Uploader
2012-06-03 18:54 . 2011-11-08 14:18 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-06-03 18:54 . 2011-11-08 14:18 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-06-03 18:54 . 2009-12-05 23:42 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2012-06-03 18:54 . 2012-06-03 18:54 -------- d-----w- c:\program files (x86)\ffdshow
2012-06-03 18:45 . 2012-06-22 20:42 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\vlc
2012-06-03 18:44 . 2012-06-03 18:44 -------- d-----w- c:\program files (x86)\VideoLAN
2012-06-03 15:21 . 2011-09-16 15:28 210432 ----a-w- c:\program files\Windows Sidebar\Shared Gadgets\InstantOn.gadget\InstantOnCOM.dll
2012-06-03 15:21 . 2012-06-03 15:21 -------- d-----w- c:\program files (x86)\Common Files\InstantOn
2012-06-03 04:31 . 2012-05-15 10:48 249152 ----a-w- c:\windows\system32\drivers\nvkflt.sys
2012-06-03 04:31 . 2012-05-15 10:48 1738048 ----a-w- c:\windows\system32\nvdispco64.dll
2012-06-03 04:31 . 2012-05-15 10:48 1468224 ----a-w- c:\windows\system32\nvgenco64.dll
2012-06-03 04:30 . 2012-06-03 04:30 -------- d-----w- C:\NVIDIA
2012-06-02 06:40 . 2012-06-08 21:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\X-Chat 2
2012-06-02 06:40 . 2012-06-02 06:40 -------- d-----w- c:\program files (x86)\xchat
2012-06-01 23:32 . 2012-06-01 23:32 -------- d-----w- c:\program files (x86)\Moffsoft FreeCalc
2012-06-01 15:44 . 2010-10-01 04:16 13312 ----a-w- c:\windows\system32\drivers\VKbms.sys
2012-06-01 15:44 . 2010-09-30 00:45 6656 ----a-w- c:\windows\system32\drivers\hidkmdf.sys
2012-06-01 13:00 . 2012-06-01 13:00 -------- d-----w- c:\program files (x86)\CleanUp!
2012-05-31 23:34 . 2012-06-22 18:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Akamai
2012-05-31 23:01 . 2012-05-31 23:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Diagnostics
2012-05-31 22:13 . 2012-05-31 22:13 -------- d-----w- c:\programdata\WEBREG
2012-05-31 22:10 . 2012-06-07 23:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\HP
2012-05-31 22:10 . 2012-05-31 22:10 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\HP
2012-05-31 22:09 . 2009-06-09 05:48 249856 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpfpp092.dll
2012-05-31 22:08 . 2012-05-31 22:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Yahoo!
2012-05-31 22:08 . 2012-06-10 12:35 -------- d-----w- c:\program files (x86)\Yahoo!
2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\programdata\HP Product Assistant
2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\windows\SysWow64\spool
2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\HP
2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\Hewlett-Packard
2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\windows\hpoj4500g510n-z
2012-05-31 22:03 . 2009-05-26 17:32 902656 ----a-w- c:\windows\system32\hpwwiax9.dll
2012-05-31 22:03 . 2009-05-26 17:32 742912 ----a-w- c:\windows\system32\hpwtscl5.dll
2012-05-31 22:03 . 2009-05-26 17:32 503296 ----a-w- c:\windows\system32\hpwvst01.dll
2012-05-31 22:03 . 2009-05-18 21:51 551424 ----a-w- c:\windows\system32\hppldcoi.dll
2012-05-31 22:03 . 2009-05-21 13:14 642360 ----a-w- c:\windows\system32\hpzids40.dll
2012-05-31 22:03 . 2009-06-09 05:48 136704 ----a-w- c:\windows\system32\hpf3l092.dll
2012-05-31 22:02 . 2012-05-31 22:07 -------- d-----w- c:\program files (x86)\HP
2012-05-31 22:00 . 2012-05-31 22:11 -------- d-----w- c:\programdata\HP
2012-05-31 21:54 . 2012-05-31 21:54 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\FLEXnet
2012-05-31 20:38 . 2012-01-31 12:44 279656 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-23 00:08 . 2011-09-11 17:24 45056 ----a-w- c:\windows\SysWow64\acovcnt.exe
2012-05-15 21:59 . 2010-06-24 18:33 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-15 10:48 . 2011-09-11 17:06 949056 ----a-w- c:\windows\system32\nvumdshimx.dll
2012-05-15 10:48 . 2011-09-11 17:06 818496 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2012-05-15 10:48 . 2011-09-11 17:06 246592 ----a-w- c:\windows\system32\nvinitx.dll
2012-05-15 10:48 . 2011-09-11 17:06 202048 ----a-w- c:\windows\SysWow64\nvinit.dll
2012-05-15 10:48 . 2011-09-11 17:06 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll
2012-05-15 10:48 . 2011-09-11 17:06 2741568 ----a-w- c:\windows\system32\nvapi64.dll
2012-05-15 10:48 . 2011-09-11 17:06 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll
2012-05-15 09:29 . 2011-05-27 13:38 889664 ----a-w- c:\windows\system32\nvvsvc.exe
2012-05-15 09:29 . 2011-05-27 13:38 858944 ----a-w- c:\windows\system32\nv3dappshext.dll
2012-05-15 09:29 . 2011-05-27 16:38 63296 ----a-w- c:\windows\system32\nvshext.dll
2012-05-15 09:29 . 2011-05-27 13:38 55616 ----a-w- c:\windows\system32\nv3dappshextr.dll
2012-05-15 09:29 . 2011-05-27 13:38 2561856 ----a-w- c:\windows\system32\nvsvcr.dll
2012-05-15 09:29 . 2011-05-27 13:38 118080 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-15 09:29 . 2011-05-27 16:38 2621723 ----a-w- c:\windows\system32\nvcoproc.bin
2012-05-15 09:29 . 2011-05-27 13:38 3149632 ----a-w- c:\windows\system32\nvsvc64.dll
2012-05-15 09:28 . 2011-05-27 13:38 6151488 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-15 06:21 . 2012-05-15 06:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-05-15 02:50 . 2012-05-15 02:50 20992 ----a-w- c:\windows\system32\drivers\rzvkeyboard.sys
2012-05-15 02:50 . 2012-05-15 02:50 94208 ----a-w- c:\windows\system32\drivers\rzudd.sys
2012-05-15 02:36 . 2012-05-15 02:36 142848 ----a-w- c:\windows\SysWow64\rztouchdll.dll
2012-05-15 02:36 . 2012-05-15 02:36 354816 ----a-w- c:\windows\SysWow64\rzdevicedll.dll
2012-05-15 02:36 . 2012-05-15 02:36 165888 ----a-w- c:\windows\SysWow64\rzaudiodll.dll
2012-05-08 02:46 . 2012-05-08 02:46 7168 ----a-w- c:\windows\system32\drivers\rzkbdhid.sys
2012-05-08 02:46 . 2012-05-08 02:46 26112 ----a-w- c:\windows\system32\drivers\rzdaendpt.sys
2012-04-19 00:56 . 2012-04-19 00:56 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-04-19 00:56 . 2012-04-19 00:56 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2012-04-04 22:47 . 2012-05-15 22:15 772504 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2012-04-04 22:47 . 2012-05-15 22:15 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-04-04 19:56 . 2012-05-15 22:19 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-30 11:35 . 2012-05-16 22:10 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-22_00.58.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-18 20:13 . 2012-06-23 00:09 57462 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-06-23 00:09 42110 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-05-15 22:00 . 2012-06-23 00:09 12236 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-953877884-1205063476-829431027-1001_UserData.bin
+ 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-06-22 23:05 . 2012-06-22 23:05 268720 c:\windows\system32\javaws.exe
+ 2012-06-22 23:05 . 2012-06-22 23:05 189360 c:\windows\system32\javaw.exe
+ 2012-06-22 23:05 . 2012-06-22 23:05 188840 c:\windows\system32\java.exe
+ 2009-07-14 05:01 . 2012-06-23 00:06 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-06-22 00:48 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2012-06-22 23:04 . 2012-06-22 23:04 891392 c:\windows\Installer\104132a.msi
- 2012-05-15 22:03 . 2012-06-22 00:48 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat
+ 2012-05-15 22:03 . 2012-06-23 00:06 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat
- 2012-05-15 23:49 . 2012-06-21 23:15 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat
+ 2012-05-15 23:49 . 2012-06-23 00:07 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-02 2018032]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472]
"SonicMasterTray"="c:\program files (x86)\ASUS\SonicMaster\SonicMasterTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"RemoteControl10"="c:\program files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-11-12 75048]
"UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-11-24 222504]
"UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2012-05-29 313768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-4-2 549040]
FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe [2012-5-31 12862]
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
NETGEAR WNDA3100v2 Genie.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-6-13 8453376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/09/11 10:30;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-11-12 241648]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]
R2 WSWNDA3100v2;WSWNDA3100v2;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2011-12-14 303360]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-16 257224]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]
R3 cphs;Intel® Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-03-20 276248]
R3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\Drivers\CYUSB.sys [x]
R3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]
R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files (x86)\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024]
S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-09-08 92800]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-13 138400]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-01-14 1839616]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
S2 Splashtop MDES;Splashtop Meta Data Export Service;c:\asus.sys\SIONExportService.exe [2011-05-10 338208]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]
S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]
S3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 rzdaendpt;%rzdaendpt.SvcDesc%;c:\windows\system32\DRIVERS\rzdaendpt.sys [x]
S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys [x]
S3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - CLKMDRV10_38F51D56
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-10 22:26]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]
.
2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2011-03-21 361984]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552]
"SynAsusAcpi"="c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe" [bU]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Ronald Glickman\AppData\Roaming\Mozilla\Firefox\Profiles\k2hn4jp8.default\
FF - prefs.js: browser.startup.homepage - hxxp://combatarms.nexon.net/|http://battlelog.battlefield.com/bf3/gate/|http://forums.thecbl.net/ucp.php?mode=login|http://yellowsnowarmy.com/
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-06-22 21:12:56
ComboFix-quarantined-files.txt 2012-06-23 01:12
ComboFix2.txt 2012-06-22 01:00
.
Pre-Run: 382,098,587,648 bytes free
Post-Run: 381,901,774,848 bytes free
.
- - End Of File - - 26733B94D1EF8A46D71C0A005273615D
-
I just received the IP block message again from the same IP address.
2012/06/22 19:36:03 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 56530, Process: chrome.exe)
2012/06/22 19:36:03 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 56532, Process: chrome.exe)
-
Ok I have removed the old java and installed Java SE 7u5 JRE edition for windows x64. http://www.oracle.com/technetwork/java/javase/downloads/jre7-downloads-1637588.html
-
netsession_win.exe;c:\users\ronald glickman\appdata\local\akamai;Probably DLOADER.Trojan;Incurable.Moved.; netsession_win.exe;c:\users\ronald glickman\appdata\local\akamai;Probably DLOADER.Trojan;Invalid path to file ; netsession_win.exe;C:\Documents and Settings\Ronald Glickman\AppData\Local\Akamai;Probably DLOADER.Trojan;Invalid path to file ; netsession_win.exe;C:\Documents and Settings\Ronald Glickman\AppData\Local\Application Data\Akamai;Probably DLOADER.Trojan;Invalid path to file ; netsession_win.exe;C:\Documents and Settings\Ronald Glickman\DoctorWeb\Quarantine;Probably DLOADER.Trojan;Incurable.Moved.; netsession_win.exe;C:\Users\Ronald Glickman\AppData\Local\Akamai;Probably DLOADER.Trojan;Invalid path to file ; OTL.exe;E:\RSG Downloads;Trojan.Siggen4.6108;Incurable.Moved.;
-
MiniToolBox by Farbar Version: 09-06-2012
Ran by Ronald Glickman (administrator) on 22-06-2012 at 11:30:02
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= FF Proxy Settings: ==============================
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20) = Local Area Connection (Connected)
Atheros AR9002WB-1NG Wireless Network Adapter = Wireless Network Connection (Media disconnected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection 2 (Media disconnected)
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
reset
set global
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : Jags-Awesome-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Bluetooth Network Connection 2:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network) #2
Physical Address. . . . . . . . . : 74-2F-68-B8-8C-CC
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
Physical Address. . . . . . . . . : 14-DA-E9-66-23-F1
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::6511:f4b0:8d4c:6b6f%14(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.2.9(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Friday, June 22, 2012 8:14:14 AM
Lease Expires . . . . . . . . . . : Saturday, June 23, 2012 8:14:14 AM
Default Gateway . . . . . . . . . : 192.168.2.1
DHCP Server . . . . . . . . . . . : 192.168.2.1
DHCPv6 IAID . . . . . . . . . . . : 387242729
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-FE-A1-03-74-2F-68-B9-58-7D
DNS Servers . . . . . . . . . . . : 192.168.2.1
NetBIOS over Tcpip. . . . . . . . : Enabled
Wireless LAN adapter Wireless Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Atheros AR9002WB-1NG Wireless Network Adapter
Physical Address. . . . . . . . . : 74-2F-68-B9-58-7D
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter isatap.{1BC833C7-962F-4E56-A43D-9DE390C45F72}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:245e:3c28:b4ba:2f4d(Preferred)
Link-local IPv6 Address . . . . . : fe80::245e:3c28:b4ba:2f4d%18(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: UnKnown
Address: 192.168.2.1
Name: google.com
Addresses: 2607:f8b0:4006:801::1000
74.125.226.206
74.125.226.201
74.125.226.197
74.125.226.198
74.125.226.194
74.125.226.196
74.125.226.199
74.125.226.193
74.125.226.200
74.125.226.192
74.125.226.195
Pinging google.com [173.194.43.8] with 32 bytes of data:
Reply from 173.194.43.8: bytes=32 time=38ms TTL=54
Reply from 173.194.43.8: bytes=32 time=40ms TTL=54
Ping statistics for 173.194.43.8:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 38ms, Maximum = 40ms, Average = 39ms
Server: UnKnown
Address: 192.168.2.1
Name: yahoo.com
Addresses: 98.139.183.24
209.191.122.70
72.30.38.140
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=301ms TTL=50
Reply from 98.139.183.24: bytes=32 time=287ms TTL=50
Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 287ms, Maximum = 301ms, Average = 294ms
Server: UnKnown
Address: 192.168.2.1
Name: bleepingcomputer.com
Address: 208.43.87.2
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time=2ms TTL=128
Reply from 127.0.0.1: bytes=32 time=1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms
===========================================================================
Interface List
17...74 2f 68 b8 8c cc ......Bluetooth Device (Personal Area Network) #2
14...14 da e9 66 23 f1 ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
11...74 2f 68 b9 58 7d ......Atheros AR9002WB-1NG Wireless Network Adapter
1...........................Software Loopback Interface 1
20...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
18...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.9 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.2.0 255.255.255.0 On-link 192.168.2.9 276
192.168.2.9 255.255.255.255 On-link 192.168.2.9 276
192.168.2.255 255.255.255.255 On-link 192.168.2.9 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.2.9 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.2.9 276
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
18 58 ::/0 On-link
1 306 ::1/128 On-link
18 58 2001::/32 On-link
18 306 2001:0:4137:9e76:245e:3c28:b4ba:2f4d/128
On-link
14 276 fe80::/64 On-link
18 306 fe80::/64 On-link
18 306 fe80::245e:3c28:b4ba:2f4d/128
On-link
14 276 fe80::6511:f4b0:8d4c:6b6f/128
On-link
1 306 ff00::/8 On-link
18 306 ff00::/8 On-link
14 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 10 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 09 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
x64-Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (06/22/2012 09:31:54 AM) (Source: Application Error) (User: )
Description: Faulting application name: sidebar.exe, version: 6.1.7601.17514, time stamp: 0x4ce7a1c7
Faulting module name: InstantOnCOM.dll, version: 1.0.0.1, time stamp: 0x4e72c267
Exception code: 0xc0000417
Fault offset: 0x0000000000013c68
Faulting process id: 0x1240
Faulting application start time: 0xsidebar.exe0
Faulting application path: sidebar.exe1
Faulting module path: sidebar.exe2
Report Id: sidebar.exe3
Error: (06/22/2012 09:06:49 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (06/22/2012 00:13:01 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8003
Error: (06/22/2012 00:13:01 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8003
Error: (06/22/2012 00:13:01 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/22/2012 00:13:00 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7005
Error: (06/22/2012 00:13:00 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7005
Error: (06/22/2012 00:13:00 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (06/22/2012 00:12:59 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6006
Error: (06/22/2012 00:12:59 AM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6006
System errors:
=============
Error: (06/21/2012 08:49:31 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender service terminated with the following error:
%%126
Error: (06/21/2012 08:48:31 PM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Error: (06/21/2012 08:48:26 PM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Error: (06/21/2012 08:48:01 PM) (Source: Application Popup) (User: )
Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
Error: (06/21/2012 08:46:11 PM) (Source: Service Control Manager) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Error: (06/21/2012 08:41:52 PM) (Source: Service Control Manager) (User: )
Description: The HP CUE DeviceDiscovery Service service terminated unexpectedly. It has done this 1 time(s).
Error: (06/21/2012 08:41:52 PM) (Source: Service Control Manager) (User: )
Description: The hpqcxs08 service terminated unexpectedly. It has done this 1 time(s).
Error: (06/21/2012 08:22:17 PM) (Source: Service Control Manager) (User: )
Description: The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
Error: (06/20/2012 04:12:31 PM) (Source: Tcpip) (User: )
Description: The system detected an address conflict for IP address 192.168.2.5 with the system
having network hardware address 68-B5-99-54-2F-04. Network operations on this system may
be disrupted as a result.
Error: (06/19/2012 00:32:07 PM) (Source: Service Control Manager) (User: )
Description: The Steam Client Service service failed to start due to the following error:
%%1053
Microsoft Office Sessions:
=========================
=========================== Installed Programs ============================
Update for Microsoft Office 2007 (KB2508958)
??????? Windows Live Mesh ActiveX ??(????) (Version: 15.4.5722.2)
??????? Windows Live Mesh ActiveX ??? (Version: 15.4.5722.2)
4500_G510nz_Help (Version: 000.0.439.000)
4500G510nz (Version: 000.0.439.000)
4500G510nz_Software_Min (Version: 000.0.423.000)
64 Bit HP CIO Components Installer (Version: 6.2.1)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.257)
Adobe Flash Player 11 Plugin (Version: 11.3.300.257)
Adobe Reader X (10.1.3) (Version: 10.1.3)
Adobe Shockwave Player 11.6 (Version: 11.6.5.635)
Akamai NetSession Interface
Alcor Micro USB Card Reader (Version: 1.2.0117.08443)
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
AsMakeLink
Asmedia ASM104x USB 3.0 Host Controller Driver (Version: 1.6.3.0)
ASUS AI Recovery (Version: 1.0.13)
ASUS FancyStart (Version: 1.1.0)
ASUS LifeFrame3 (Version: 3.0.22)
ASUS Music Maker (Version: 17.0.2.22)
ASUS Power4Gear Hybrid (Version: 1.1.45)
ASUS Splendid Video Enhancement Technology (Version: 1.02.0033)
ASUS USB Charger Plus (Version: 2.0.2)
ASUS Video Magic (Version: 6.0.4710)
ASUS Virtual Camera (Version: 1.0.21)
ASUS WebStorage (Version: 3.0.84.161)
AsusScr_N5_En (Version: 1.0.0001)
AsusVibe2.0 (Version: 2.0.10.168)
Atheros Client Installation Program (Version: 7.0)
ATK Package (Version: 1.0.0008)
Battlefield 3™ (Version: 1.0.0.0)
Battlelog Web Plugins (Version: 1.122.0)
Bing Bar (Version: 7.0.610.0)
Bluetooth Win7 Suite (64) (Version: 7.2.0.65)
Bonjour (Version: 3.0.0.10)
BufferChm (Version: 130.0.331.000)
CCleaner (Version: 3.19)
CleanUp!
Combat Arms
Counter-Strike: Source
CyberLink LabelPrint (Version: 2.5.1908)
CyberLink MediaEspresso (Version: 6.0.1123_32710)
CyberLink Power2Go (Version: 6.1.3602c)
CyberLink PowerDirector (Version: 8.0.3327)
CyberLink PowerDVD 10 (Version: 10.0.2312.52)
D3DX10 (Version: 15.4.2368.0902)
Destinations (Version: 130.0.0.0)
DeviceDiscovery (Version: 130.0.372.000)
DocMgr (Version: 130.0.000.000)
DocProc (Version: 13.0.0.0)
Dropbox (Version: 1.4.7)
ESET Online Scanner v3
ESN Sonar (Version: 0.70.4)
Fast Boot (Version: 1.0.9)
Fax (Version: 130.0.418.000)
ffdshow [rev 3154] [2009-12-09] (Version: 1.0)
Firebird SQL Server - MAGIX Edition (Version: 2.1.29.0)
Freemake Video Converter version 3.0.2 (Version: 3.0.2)
Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922)
Galerie de photos Windows Live (Version: 15.4.3502.0922)
Galería fotográfica de Windows Live (Version: 15.4.3502.0922)
Game Booster 3 (Version: 3.4)
Google Chrome (Version: 19.0.1084.56)
Google Update Helper (Version: 1.3.21.111)
GPBaseService2 (Version: 130.0.371.000)
HP Customer Participation Program 13.0 (Version: 13.0)
HP Document Manager 2.0 (Version: 2.0)
HP Imaging Device Functions 13.0 (Version: 13.0)
HP Officejet 4500 G510n-z (Version: 13.0)
HP Smart Web Printing 4.5 (Version: 4.5)
HP Solution Center 13.0 (Version: 13.0)
HP Update (Version: 4.000.011.006)
HPProductAssistant (Version: 130.0.371.000)
HPSSupply (Version: 130.0.371.000)
ImageShack Uploader 2.2.0 (Version: 2.2.0)
InstantOn for NB (Version: 2.1.5)
Intel® Control Center (Version: 1.2.1.1007)
Intel® Management Engine Components (Version: 7.0.0.1118)
Intel® OpenCL CPU Runtime
Intel® Processor Graphics (Version: 8.15.10.2696)
Intel® Turbo Boost Technology Monitor 2.0 (Version: 2.1.23.0)
iTunes (Version: 10.6.1.7)
Java Auto Updater (Version: 2.1.6.0)
Java 7 Update 4 (Version: 7.0.40)
JavaFX 2.1.0 (Version: 2.1.0)
Junk Mail filter update (Version: 15.4.3502.0922)
KeePass Password Safe 2.19
Malwarebytes Anti-Malware version 1.61.0.1400 (Version: 1.61.0.1400)
MarketResearch (Version: 130.0.374.000)
Mesh Runtime (Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.0.1526.0)
Microsoft Security Essentials (Version: 4.0.1526.0)
Microsoft Silverlight (Version: 4.1.10329.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Moffsoft FreeCalc (Version: 1.1)
Mozilla Firefox 12.0 (x86 en-US) (Version: 12.0)
Mozilla Maintenance Service (Version: 12.0)
Mozilla Thunderbird 12.0.1 (x86 en-US) (Version: 12.0.1)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Music Now! (Version: 1.0.5.0)
NETGEAR WNDA3100v2 wireless USB 2.0 adapter (Version: 1.03.000)
Network64 (Version: 130.0.374.000)
Network64 (Version: 140.0.221.000)
Nexon Game Manager
Nuance PDF Reader (Version: 6.00.0041)
NVIDIA 3D Vision Driver 301.42 (Version: 301.42)
NVIDIA Control Panel 301.42 (Version: 301.42)
NVIDIA Graphics Driver 301.42 (Version: 301.42)
NVIDIA HD Audio Driver 1.3.16.0 (Version: 1.3.16.0)
NVIDIA Install Application (Version: 2.1002.75.420)
NVIDIA Optimus 1.8.15 (Version: 1.8.15)
NVIDIA PhysX (Version: 9.12.0213)
NVIDIA PhysX System Software 9.12.0213 (Version: 9.12.0213)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.0142)
NVIDIA Update 1.8.15 (Version: 1.8.15)
NVIDIA Update Components (Version: 1.8.15)
OCR Software by I.R.I.S. 13.0 (Version: 13.0)
OpenOffice.org 3.4 (Version: 3.4.9590)
Origin (Version: 8.6.0.357)
PunkBuster Services (Version: 0.991)
QuickTime (Version: 7.72.80.56)
Razer Synapse 2.0 (Version: 1.2.16)
Realtek High Definition Audio Driver (Version: 6.0.1.6438)
Scan (Version: 13.0.0.0)
Shop for HP Supplies (Version: 13.0)
SmartWebPrinting (Version: 130.0.373.000)
SolutionCenter (Version: 130.0.373.000)
SolveigMM AVI Trimmer (Version: 2.0.1204.27)
SonicMaster (Version: 1.0.0.4)
Status (Version: 130.0.373.000)
Steam (Version: 1.0.0.0)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.3.6.0)
syncables desktop SE (Version: 5.5.746.11492)
System Requirements Lab (Version: 4.5.1.0)
System Requirements Lab CYRI (Version: 4.5.1.0)
System Requirements Lab for Intel (Version: 4.5.5.0)
TeamSpeak 3 Client (Version: 3.0.7)
TeamViewer 7 (Version: 7.0.12979)
Tipard MKV Video Converter 6.1.12
Toolbox (Version: 130.0.648.000)
TrayApp (Version: 130.0.376.000)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687267) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Virtual Magnifying Glass v3.5
Visual Studio 2008 x64 Redistributables (Version: 10.0.0.2)
VLC media player 2.0.1 (Version: 2.0.1)
WebReg (Version: 130.0.132.017)
Windows Live ??? (Version: 15.4.3502.0922)
Windows Live ???? (Version: 15.4.3502.0922)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3508.1109)
Windows Live Family Safety (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
WinFlash (Version: 2.31.1)
WinRAR 4.11 (64-bit) (Version: 4.11.0)
WinSCP 4.3.7 (Version: 4.3.7)
XChat 2 (remove only)
Xilisoft Video Converter Ultimate 6 (Version: 6.0.3.0416)
========================= Devices: ================================
Name: Officejet 4500 G510n-z
Description: Officejet 4500 G510n-z
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
========================= Memory info: ===================================
Percentage of memory in use: 36%
Total physical RAM: 8102.06 MB
Available physical RAM: 5143.06 MB
Total Pagefile: 16202.31 MB
Available Pagefile: 13043.04 MB
Total Virtual: 4095.88 MB
Available Virtual: 3975.09 MB
========================= Partitions: =====================================
1 Drive c: (OS) (Fixed) (Total:440.76 GB) (Free:356.82 GB) NTFS
2 Drive e: (DATA) (Fixed) (Total:465.75 GB) (Free:405.29 GB) NTFS
========================= Users: ========================================
User accounts for \\JAGS-AWESOME-PC
Administrator Guest Ronald Glickman
UpdatusUser
========================= Minidump Files ==================================
No minidump file found
**** End of log ****
Farbar Service Scanner Version: 22-06-2012
Ran by Ronald Glickman (administrator) on 22-06-2012 at 11:31:16
Running from "E:\RSG Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
-
Kaspersky AVP log was nothing there. I clicked on the Detected Threats buttons as you instructed and the Save button was greyed out, not allowing me to save anything because it didn't detect anything.
aswMBR.log is as follows.....
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-06-22 11:20:55
-----------------------------
11:20:55.560 OS Version: Windows x64 6.1.7601 Service Pack 1
11:20:55.560 Number of processors: 8 586 0x2A07
11:20:55.560 ComputerName: JAGS-AWESOME-PC UserName: Ronald Glickman
11:20:59.726 Initialize success
11:21:35.631 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:21:35.631 Disk 0 Vendor: ST950042 0002 Size: 476940MB BusType: 3
11:21:35.631 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
11:21:35.631 Disk 1 Vendor: ST950042 0002 Size: 476940MB BusType: 3
11:21:35.647 Disk 0 MBR read successfully
11:21:35.662 Disk 0 MBR scan
11:21:35.662 Disk 0 Windows 7 default MBR code
11:21:35.662 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048
11:21:35.678 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 451337 MB offset 52430848
11:21:35.693 Disk 0 scanning C:\Windows\system32\drivers
11:21:41.731 Service scanning
11:21:54.179 Modules scanning
11:21:54.179 Disk 0 trace - called modules:
11:21:54.273 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
11:21:54.273 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008126790]
11:21:54.601 3 CLASSPNP.SYS[fffff88001dbb43f] -> nt!IofCallDriver -> [0xfffffa8007bc9550]
11:21:54.601 5 ACPI.sys[fffff88000f427a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007bd0050]
11:21:54.601 Scan finished successfully
11:22:07.845 Disk 0 MBR has been saved successfully to "C:\Users\Ronald Glickman\Desktop\MBR.dat"
11:22:07.892 The log file has been saved successfully to "C:\Users\Ronald Glickman\Desktop\aswMBR.txt"
-
It didn't find anything and the log file is quite small.
ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
That's all there was on the text document
-
I ran the otl fix and the combofix last night and they were posted already. I just got that same ip block message for the same ip this morning
2012/06/22 06:39:31 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE Starting protection
2012/06/22 06:39:33 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE Protection started successfully
2012/06/22 06:39:36 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE Starting IP protection
2012/06/22 06:39:37 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE IP Protection started successfully
2012/06/22 06:40:24 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49332, Process: chrome.exe)
2012/06/22 06:41:13 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49339, Process: chrome.exe)
2012/06/22 06:47:41 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49447, Process: chrome.exe)
2012/06/22 06:48:29 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49458, Process: chrome.exe)
IP Block message help
in Resolved Malware Removal Logs
Posted
yes that was the entire message, nothing omitted, that I got inside fiddler