Jump to content

rsglick

Honorary Members
  • Posts

    31
  • Joined

  • Last visited

Posts posted by rsglick

  1. nope it didn't work.

    2012/06/25 16:03:30 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53610, Process: chrome.exe)

    2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53651, Process: chrome.exe)

    2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53652, Process: chrome.exe)

    2012/06/25 16:04:11 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53653, Process: chrome.exe)

    2012/06/25 16:08:12 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53694, Process: chrome.exe)

    2012/06/25 16:08:12 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 53695, Process: chrome.exe)

    2012/06/25 16:35:27 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 54127, Process: chrome.exe)

  2. I'm still getting the IP block message from the same IP.

    2012/06/25 11:41:42 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 50805, Process: chrome.exe)

    2012/06/25 11:41:42 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 50817, Process: chrome.exe)

    2012/06/25 13:28:58 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 51419, Process: chrome.exe)

    2012/06/25 13:29:38 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 51424, Process: chrome.exe)

  3. yes and each time it shows chrome.exe at the bottom of the malware message

    2012/06/24 07:30:31 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49846, Process: chrome.exe)

    2012/06/24 07:31:20 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49869, Process: chrome.exe)

    2012/06/24 07:32:08 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49882, Process: chrome.exe)

    2012/06/24 07:32:24 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49888, Process: chrome.exe)

    2012/06/24 07:34:49 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49968, Process: chrome.exe)

    It does it for firefox also.

    Also just fyi, I had backed up my C drive onto my E drive as requested by my machine utilities. So I just deleted that off my E drive so now there is no copy of the C drive on my E drive. I'm wondering if all the scans we were doing for the C drive was also scanning the E drive.

  4. ComboFix 12-06-21.03 - Ronald Glickman 06/22/2012 21:06:37.2.8 - x64

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8102.4619 [GMT -4:00]

    Running from: e:\rsg downloads\ComboFix.exe

    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}

    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\users\Ronald Glickman\AppData\Local\Temp\0fc113bebd3c.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\19d20a6fbc7a.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\445fec56af0e.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\5a07244160fb.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\6e050972a7cc.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\71c12d7a8180.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\71ca0fe59f0c.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\791722b78375.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\ad0f0f8f62a5.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\bceff7d56bff.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\bed204085de1.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\cb08234cf0e7.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\f111f32f3afb.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\f4f018b21319.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\NGC1E9.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\NGC939.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\NGCABE.tmp

    c:\users\RONALD~1\AppData\Local\Temp\0fc113bebd3c.tmp

    c:\users\RONALD~1\AppData\Local\Temp\19d20a6fbc7a.tmp

    c:\users\RONALD~1\AppData\Local\Temp\445fec56af0e.tmp

    c:\users\RONALD~1\AppData\Local\Temp\5a07244160fb.tmp

    c:\users\RONALD~1\AppData\Local\Temp\6e050972a7cc.tmp

    c:\users\RONALD~1\AppData\Local\Temp\71c12d7a8180.tmp

    c:\users\RONALD~1\AppData\Local\Temp\71ca0fe59f0c.tmp

    c:\users\RONALD~1\AppData\Local\Temp\791722b78375.tmp

    c:\users\RONALD~1\AppData\Local\Temp\ad0f0f8f62a5.tmp

    c:\users\RONALD~1\AppData\Local\Temp\bceff7d56bff.tmp

    c:\users\RONALD~1\AppData\Local\Temp\bed204085de1.tmp

    c:\users\RONALD~1\AppData\Local\Temp\cb08234cf0e7.tmp

    c:\users\RONALD~1\AppData\Local\Temp\f111f32f3afb.tmp

    c:\users\RONALD~1\AppData\Local\Temp\f4f018b21319.tmp

    c:\users\RONALD~1\AppData\Local\Temp\NGC1E9.tmp

    c:\users\RONALD~1\AppData\Local\Temp\NGC939.tmp

    c:\users\RONALD~1\AppData\Local\Temp\NGCABE.tmp

    .

    .

    ((((((((((((((((((((((((( Files Created from 2012-05-23 to 2012-06-23 )))))))))))))))))))))))))))))))

    .

    .

    2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

    2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-06-23 00:05 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54DB061F-FB9C-4663-9424-F36FA76DE9DA}\mpengine.dll

    2012-06-22 23:05 . 2012-06-22 23:05 955840 ----a-w- c:\windows\system32\npDeployJava1.dll

    2012-06-22 23:05 . 2012-06-22 23:05 839096 ----a-w- c:\windows\system32\deployJava1.dll

    2012-06-22 23:05 . 2012-06-22 23:05 -------- d-----w- c:\program files\Java

    2012-06-22 15:37 . 2012-06-22 15:53 -------- d-----w- c:\users\Ronald Glickman\DoctorWeb

    2012-06-22 13:32 . 2012-06-22 13:32 -------- d-----w- c:\programdata\Kaspersky Lab

    2012-06-22 12:25 . 2012-06-22 12:25 -------- d-----w- c:\program files (x86)\ESET

    2012-06-22 01:34 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

    2012-06-21 19:07 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-21 19:07 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-21 19:07 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll

    2012-06-21 19:07 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll

    2012-06-21 19:07 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll

    2012-06-21 19:07 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-21 19:07 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll

    2012-06-21 19:07 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll

    2012-06-21 19:07 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe

    2012-06-19 16:31 . 2012-06-19 22:24 -------- d-----w- c:\program files (x86)\Common Files\Steam

    2012-06-19 16:31 . 2012-06-22 19:56 -------- d-----w- c:\program files (x86)\Steam

    2012-06-16 22:16 . 2012-06-16 22:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\MAGIX

    2012-06-16 16:24 . 2012-06-16 16:24 -------- d-----w- c:\windows\SysWow64\RTCOM

    2012-06-16 12:06 . 2012-06-16 12:06 -------- d-----w- c:\programdata\Nexon

    2012-06-16 12:02 . 2012-06-16 12:02 -------- d-----w- C:\Nexon

    2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\program files\Microsoft IntelliPoint

    2012-06-13 18:46 . 2012-06-13 18:56 -------- d-----w- c:\program files (x86)\Razer

    2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Razer

    2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\programdata\Razer

    2012-06-13 10:17 . 2011-12-12 21:42 1256192 ----a-w- c:\windows\system32\drivers\bcmwlhigh664.sys

    2012-06-13 10:17 . 2011-04-19 21:52 95544 ----a-w- c:\windows\system32\bcmwlcoi.dll

    2012-06-13 10:17 . 2011-04-19 21:31 3900928 ----a-w- c:\windows\system32\bcmihvsrv64.dll

    2012-06-13 10:17 . 2011-04-19 21:31 3566592 ----a-w- c:\windows\system32\bcmihvui64.dll

    2012-06-13 10:17 . 2010-06-09 17:11 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll

    2012-06-13 10:17 . 2010-02-03 15:20 47632 ----a-w- c:\windows\system32\drivers\npf.sys

    2012-06-13 10:17 . 2011-07-22 14:33 25056 ----a-w- c:\windows\system32\drivers\SCMNdisP.sys

    2012-06-13 10:17 . 2012-06-13 10:17 -------- d-----w- c:\program files (x86)\NETGEAR

    2012-06-12 18:42 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll

    2012-06-12 17:12 . 2012-06-12 17:12 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins

    2012-06-12 17:03 . 2012-06-12 17:03 -------- d-----w- c:\programdata\EA Core

    2012-06-12 17:03 . 2012-06-13 17:40 -------- d-----w- c:\programdata\EA Logs

    2012-06-12 16:35 . 2007-10-12 19:14 2006552 ----a-w- c:\windows\system32\D3DCompiler_36.dll

    2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

    2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5DD60F6-F67B-4B8C-AF21-C5E783A93374}\gapaengine.dll

    2012-06-12 14:59 . 2012-06-12 15:00 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Origin

    2012-06-12 14:59 . 2012-06-12 14:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Origin

    2012-06-12 14:58 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Electronic Arts

    2012-06-12 14:58 . 2012-06-12 16:11 -------- d-----w- c:\program files (x86)\Origin Games

    2012-06-12 14:58 . 2012-06-12 15:00 -------- d-----w- c:\program files (x86)\Origin

    2012-06-12 14:44 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Origin

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll

    2012-06-11 21:50 . 2012-06-11 21:51 -------- d-----w- c:\program files (x86)\QuickTime

    2012-06-11 13:34 . 2012-06-11 13:34 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\OpenOffice.org

    2012-06-11 13:22 . 2012-06-11 13:22 -------- d-----w- c:\program files\CCleaner

    2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\programdata\IObit

    2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\program files (x86)\IObit

    2012-06-10 15:52 . 2012-06-10 15:52 -------- d-----w- c:\programdata\McAfee

    2012-06-10 15:52 . 2012-06-16 22:26 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-06-10 15:52 . 2012-06-16 22:26 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

    2012-06-10 15:21 . 2012-06-10 15:21 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Tipard Studio

    2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\programdata\Tipard MKV Video Converter

    2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\program files (x86)\Tipard Studio

    2012-06-10 12:55 . 2012-06-10 12:55 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Macromedia

    2012-06-08 14:16 . 2012-06-08 14:16 -------- d-----w- c:\program files (x86)\Virtual Magnifying Glass

    2012-06-07 21:19 . 2012-06-18 03:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\JPEGsnoop

    2012-06-06 13:08 . 2012-06-06 13:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\TouchStoneSoftware

    2012-06-04 23:37 . 2011-05-28 04:29 67176 ----a-w- c:\windows\system32\OpenCL.dll

    2012-06-04 23:37 . 2011-05-28 04:29 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll

    2012-06-04 21:59 . 2012-03-11 06:17 121344 ----a-w- c:\windows\system32\IntelOpenCL64.dll

    2012-06-04 21:59 . 2012-03-11 06:09 86528 ----a-w- c:\windows\SysWow64\IntelOpenCL32.dll

    2012-06-04 19:14 . 2012-06-21 00:03 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr

    2012-06-04 19:13 . 2012-06-12 17:13 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\PunkBuster

    2012-06-04 18:59 . 2012-06-04 18:59 -------- d-----w- c:\program files (x86)\EA Games

    2012-06-04 13:25 . 2012-06-04 13:25 -------- d-----w- c:\program files (x86)\Common Files\Java

    2012-06-04 13:24 . 2012-06-04 13:24 -------- d-----w- c:\program files (x86)\Oracle

    2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\program files (x86)\SystemRequirementsLab

    2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\SystemRequirementsLab

    2012-06-03 23:27 . 2012-06-03 23:27 -------- d-----w- c:\program files (x86)\ImageShack Uploader

    2012-06-03 18:54 . 2011-11-08 14:18 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll

    2012-06-03 18:54 . 2011-11-08 14:18 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll

    2012-06-03 18:54 . 2009-12-05 23:42 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll

    2012-06-03 18:54 . 2012-06-03 18:54 -------- d-----w- c:\program files (x86)\ffdshow

    2012-06-03 18:45 . 2012-06-22 20:42 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\vlc

    2012-06-03 18:44 . 2012-06-03 18:44 -------- d-----w- c:\program files (x86)\VideoLAN

    2012-06-03 15:21 . 2011-09-16 15:28 210432 ----a-w- c:\program files\Windows Sidebar\Shared Gadgets\InstantOn.gadget\InstantOnCOM.dll

    2012-06-03 15:21 . 2012-06-03 15:21 -------- d-----w- c:\program files (x86)\Common Files\InstantOn

    2012-06-03 04:31 . 2012-05-15 10:48 249152 ----a-w- c:\windows\system32\drivers\nvkflt.sys

    2012-06-03 04:31 . 2012-05-15 10:48 1738048 ----a-w- c:\windows\system32\nvdispco64.dll

    2012-06-03 04:31 . 2012-05-15 10:48 1468224 ----a-w- c:\windows\system32\nvgenco64.dll

    2012-06-03 04:30 . 2012-06-03 04:30 -------- d-----w- C:\NVIDIA

    2012-06-02 06:40 . 2012-06-08 21:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\X-Chat 2

    2012-06-02 06:40 . 2012-06-02 06:40 -------- d-----w- c:\program files (x86)\xchat

    2012-06-01 23:32 . 2012-06-01 23:32 -------- d-----w- c:\program files (x86)\Moffsoft FreeCalc

    2012-06-01 15:44 . 2010-10-01 04:16 13312 ----a-w- c:\windows\system32\drivers\VKbms.sys

    2012-06-01 15:44 . 2010-09-30 00:45 6656 ----a-w- c:\windows\system32\drivers\hidkmdf.sys

    2012-06-01 13:00 . 2012-06-01 13:00 -------- d-----w- c:\program files (x86)\CleanUp!

    2012-05-31 23:34 . 2012-06-22 18:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Akamai

    2012-05-31 23:01 . 2012-05-31 23:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Diagnostics

    2012-05-31 22:13 . 2012-05-31 22:13 -------- d-----w- c:\programdata\WEBREG

    2012-05-31 22:10 . 2012-06-07 23:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\HP

    2012-05-31 22:10 . 2012-05-31 22:10 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\HP

    2012-05-31 22:09 . 2009-06-09 05:48 249856 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpfpp092.dll

    2012-05-31 22:08 . 2012-05-31 22:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Yahoo!

    2012-05-31 22:08 . 2012-06-10 12:35 -------- d-----w- c:\program files (x86)\Yahoo!

    2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\programdata\HP Product Assistant

    2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\windows\SysWow64\spool

    2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\HP

    2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\Hewlett-Packard

    2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\windows\hpoj4500g510n-z

    2012-05-31 22:03 . 2009-05-26 17:32 902656 ----a-w- c:\windows\system32\hpwwiax9.dll

    2012-05-31 22:03 . 2009-05-26 17:32 742912 ----a-w- c:\windows\system32\hpwtscl5.dll

    2012-05-31 22:03 . 2009-05-26 17:32 503296 ----a-w- c:\windows\system32\hpwvst01.dll

    2012-05-31 22:03 . 2009-05-18 21:51 551424 ----a-w- c:\windows\system32\hppldcoi.dll

    2012-05-31 22:03 . 2009-05-21 13:14 642360 ----a-w- c:\windows\system32\hpzids40.dll

    2012-05-31 22:03 . 2009-06-09 05:48 136704 ----a-w- c:\windows\system32\hpf3l092.dll

    2012-05-31 22:02 . 2012-05-31 22:07 -------- d-----w- c:\program files (x86)\HP

    2012-05-31 22:00 . 2012-05-31 22:11 -------- d-----w- c:\programdata\HP

    2012-05-31 21:54 . 2012-05-31 21:54 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\FLEXnet

    2012-05-31 20:38 . 2012-01-31 12:44 279656 ------w- c:\windows\system32\MpSigStub.exe

    .

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-06-23 00:08 . 2011-09-11 17:24 45056 ----a-w- c:\windows\SysWow64\acovcnt.exe

    2012-05-15 21:59 . 2010-06-24 18:33 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

    2012-05-15 10:48 . 2011-09-11 17:06 949056 ----a-w- c:\windows\system32\nvumdshimx.dll

    2012-05-15 10:48 . 2011-09-11 17:06 818496 ----a-w- c:\windows\SysWow64\nvumdshim.dll

    2012-05-15 10:48 . 2011-09-11 17:06 246592 ----a-w- c:\windows\system32\nvinitx.dll

    2012-05-15 10:48 . 2011-09-11 17:06 202048 ----a-w- c:\windows\SysWow64\nvinit.dll

    2012-05-15 10:48 . 2011-09-11 17:06 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll

    2012-05-15 10:48 . 2011-09-11 17:06 2741568 ----a-w- c:\windows\system32\nvapi64.dll

    2012-05-15 10:48 . 2011-09-11 17:06 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll

    2012-05-15 09:29 . 2011-05-27 13:38 889664 ----a-w- c:\windows\system32\nvvsvc.exe

    2012-05-15 09:29 . 2011-05-27 13:38 858944 ----a-w- c:\windows\system32\nv3dappshext.dll

    2012-05-15 09:29 . 2011-05-27 16:38 63296 ----a-w- c:\windows\system32\nvshext.dll

    2012-05-15 09:29 . 2011-05-27 13:38 55616 ----a-w- c:\windows\system32\nv3dappshextr.dll

    2012-05-15 09:29 . 2011-05-27 13:38 2561856 ----a-w- c:\windows\system32\nvsvcr.dll

    2012-05-15 09:29 . 2011-05-27 13:38 118080 ----a-w- c:\windows\system32\nvmctray.dll

    2012-05-15 09:29 . 2011-05-27 16:38 2621723 ----a-w- c:\windows\system32\nvcoproc.bin

    2012-05-15 09:29 . 2011-05-27 13:38 3149632 ----a-w- c:\windows\system32\nvsvc64.dll

    2012-05-15 09:28 . 2011-05-27 13:38 6151488 ----a-w- c:\windows\system32\nvcpl.dll

    2012-05-15 06:21 . 2012-05-15 06:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe

    2012-05-15 02:50 . 2012-05-15 02:50 20992 ----a-w- c:\windows\system32\drivers\rzvkeyboard.sys

    2012-05-15 02:50 . 2012-05-15 02:50 94208 ----a-w- c:\windows\system32\drivers\rzudd.sys

    2012-05-15 02:36 . 2012-05-15 02:36 142848 ----a-w- c:\windows\SysWow64\rztouchdll.dll

    2012-05-15 02:36 . 2012-05-15 02:36 354816 ----a-w- c:\windows\SysWow64\rzdevicedll.dll

    2012-05-15 02:36 . 2012-05-15 02:36 165888 ----a-w- c:\windows\SysWow64\rzaudiodll.dll

    2012-05-08 02:46 . 2012-05-08 02:46 7168 ----a-w- c:\windows\system32\drivers\rzkbdhid.sys

    2012-05-08 02:46 . 2012-05-08 02:46 26112 ----a-w- c:\windows\system32\drivers\rzdaendpt.sys

    2012-04-19 00:56 . 2012-04-19 00:56 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx

    2012-04-19 00:56 . 2012-04-19 00:56 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts

    2012-04-04 22:47 . 2012-05-15 22:15 772504 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

    2012-04-04 22:47 . 2012-05-15 22:15 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll

    2012-04-04 19:56 . 2012-05-15 22:19 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-03-30 11:35 . 2012-05-16 22:10 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys

    .

    .

    ((((((((((((((((((((((((((((( SnapShot@2012-06-22_00.58.32 )))))))))))))))))))))))))))))))))))))))))

    .

    + 2011-02-18 20:13 . 2012-06-23 00:09 57462 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

    + 2009-07-14 05:10 . 2012-06-23 00:09 42110 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

    + 2012-05-15 22:00 . 2012-06-23 00:09 12236 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-953877884-1205063476-829431027-1001_UserData.bin

    + 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2012-06-22 23:05 . 2012-06-22 23:05 268720 c:\windows\system32\javaws.exe

    + 2012-06-22 23:05 . 2012-06-22 23:05 189360 c:\windows\system32\javaw.exe

    + 2012-06-22 23:05 . 2012-06-22 23:05 188840 c:\windows\system32\java.exe

    + 2009-07-14 05:01 . 2012-06-23 00:06 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

    - 2009-07-14 05:01 . 2012-06-22 00:48 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

    + 2012-06-22 23:04 . 2012-06-22 23:04 891392 c:\windows\Installer\104132a.msi

    - 2012-05-15 22:03 . 2012-06-22 00:48 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat

    + 2012-05-15 22:03 . 2012-06-23 00:06 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat

    - 2012-05-15 23:49 . 2012-06-21 23:15 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat

    + 2012-05-15 23:49 . 2012-06-23 00:07 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]

    "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

    "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]

    "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-02 2018032]

    "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472]

    "SonicMasterTray"="c:\program files (x86)\ASUS\SonicMaster\SonicMasterTray.exe" [2010-07-10 984400]

    "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]

    "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]

    "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]

    "RemoteControl10"="c:\program files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]

    "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-11-12 75048]

    "UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-11-24 222504]

    "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]

    "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]

    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]

    "KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]

    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]

    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]

    "Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2012-05-29 313768]

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-4-2 549040]

    FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe [2012-5-31 12862]

    HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

    NETGEAR WNDA3100v2 Genie.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-6-13 8453376]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

    "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

    @="Service"

    .

    R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/09/11 10:30;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-11-12 241648]

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]

    R2 WSWNDA3100v2;WSWNDA3100v2;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2011-12-14 303360]

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-16 257224]

    R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]

    R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]

    R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]

    R3 cphs;Intel® Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-03-20 276248]

    R3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\Drivers\CYUSB.sys [x]

    R3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]

    R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]

    R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]

    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]

    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]

    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]

    R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]

    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

    R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]

    R3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]

    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

    R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]

    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files (x86)\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]

    S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]

    S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024]

    S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [x]

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]

    S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]

    S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]

    S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-09-08 92800]

    S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-13 138400]

    S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912]

    S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-01-14 1839616]

    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]

    S2 Splashtop MDES;Splashtop Meta Data Export Service;c:\asus.sys\SIONExportService.exe [2011-05-10 338208]

    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]

    S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]

    S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]

    S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]

    S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys [x]

    S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x]

    S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x]

    S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]

    S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]

    S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]

    S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]

    S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]

    S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]

    S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]

    S3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]

    S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]

    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

    S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]

    S3 rzdaendpt;%rzdaendpt.SvcDesc%;c:\windows\system32\DRIVERS\rzdaendpt.sys [x]

    S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys [x]

    S3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys [x]

    .

    .

    --- Other Services/Drivers In Memory ---

    .

    *Deregistered* - CLKMDRV10_38F51D56

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .

    Contents of the 'Scheduled Tasks' folder

    .

    2012-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-10 22:26]

    .

    2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]

    .

    2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]

    .

    .

    --------- X64 Entries -----------

    .

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]

    @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"

    [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]

    2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]

    @="{64174815-8D98-4CE6-8646-4C039977D808}"

    [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]

    2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2011-03-21 361984]

    "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

    "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120]

    "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552]

    "SynAsusAcpi"="c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe" [bU]

    "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]

    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064]

    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]

    "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    "AppInit_DLLs"=c:\windows\System32\nvinitx.dll

    .

    ------- Supplementary Scan -------

    .

    uLocal Page = c:\windows\system32\blank.htm

    mStart Page = hxxp://asus.msn.com

    mLocal Page = c:\windows\SysWOW64\blank.htm

    uInternet Settings,ProxyOverride = *.local;<local>

    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.2.1

    FF - ProfilePath - c:\users\Ronald Glickman\AppData\Roaming\Mozilla\Firefox\Profiles\k2hn4jp8.default\

    FF - prefs.js: browser.startup.homepage - hxxp://combatarms.nexon.net/|http://battlelog.battlefield.com/bf3/gate/|http://forums.thecbl.net/ucp.php?mode=login|http://yellowsnowarmy.com/

    FF - user.js: extensions.autoDisableScopes - 14

    .

    - - - - ORPHANS REMOVED - - - -

    .

    Toolbar-Locked - (no file)

    .

    .

    .

    --------------------- LOCKED REGISTRY KEYS ---------------------

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Shockwave Flash Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

    @="0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

    @="ShockwaveFlash.ShockwaveFlash.11"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="ShockwaveFlash.ShockwaveFlash"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Macromedia Flash Factory Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

    @="FlashFactory.FlashFactory.1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="FlashFactory.FlashFactory"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker4"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    Completion time: 2012-06-22 21:12:56

    ComboFix-quarantined-files.txt 2012-06-23 01:12

    ComboFix2.txt 2012-06-22 01:00

    .

    Pre-Run: 382,098,587,648 bytes free

    Post-Run: 381,901,774,848 bytes free

    .

    - - End Of File - - 26733B94D1EF8A46D71C0A005273615D

  5. ComboFix 12-06-21.03 - Ronald Glickman 06/22/2012 21:06:37.2.8 - x64

    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8102.4619 [GMT -4:00]

    Running from: e:\rsg downloads\ComboFix.exe

    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}

    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}

    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    c:\users\Ronald Glickman\AppData\Local\Temp\0fc113bebd3c.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\19d20a6fbc7a.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\445fec56af0e.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\5a07244160fb.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\6e050972a7cc.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\71c12d7a8180.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\71ca0fe59f0c.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\791722b78375.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\ad0f0f8f62a5.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\bceff7d56bff.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\bed204085de1.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\cb08234cf0e7.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\f111f32f3afb.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\f4f018b21319.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\NGC1E9.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\NGC939.tmp

    c:\users\Ronald Glickman\AppData\Local\Temp\NGCABE.tmp

    c:\users\RONALD~1\AppData\Local\Temp\0fc113bebd3c.tmp

    c:\users\RONALD~1\AppData\Local\Temp\19d20a6fbc7a.tmp

    c:\users\RONALD~1\AppData\Local\Temp\445fec56af0e.tmp

    c:\users\RONALD~1\AppData\Local\Temp\5a07244160fb.tmp

    c:\users\RONALD~1\AppData\Local\Temp\6e050972a7cc.tmp

    c:\users\RONALD~1\AppData\Local\Temp\71c12d7a8180.tmp

    c:\users\RONALD~1\AppData\Local\Temp\71ca0fe59f0c.tmp

    c:\users\RONALD~1\AppData\Local\Temp\791722b78375.tmp

    c:\users\RONALD~1\AppData\Local\Temp\ad0f0f8f62a5.tmp

    c:\users\RONALD~1\AppData\Local\Temp\bceff7d56bff.tmp

    c:\users\RONALD~1\AppData\Local\Temp\bed204085de1.tmp

    c:\users\RONALD~1\AppData\Local\Temp\cb08234cf0e7.tmp

    c:\users\RONALD~1\AppData\Local\Temp\f111f32f3afb.tmp

    c:\users\RONALD~1\AppData\Local\Temp\f4f018b21319.tmp

    c:\users\RONALD~1\AppData\Local\Temp\NGC1E9.tmp

    c:\users\RONALD~1\AppData\Local\Temp\NGC939.tmp

    c:\users\RONALD~1\AppData\Local\Temp\NGCABE.tmp

    .

    .

    ((((((((((((((((((((((((( Files Created from 2012-05-23 to 2012-06-23 )))))))))))))))))))))))))))))))

    .

    .

    2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp

    2012-06-23 01:11 . 2012-06-23 01:11 -------- d-----w- c:\users\Default\AppData\Local\temp

    2012-06-23 00:05 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{54DB061F-FB9C-4663-9424-F36FA76DE9DA}\mpengine.dll

    2012-06-22 23:05 . 2012-06-22 23:05 955840 ----a-w- c:\windows\system32\npDeployJava1.dll

    2012-06-22 23:05 . 2012-06-22 23:05 839096 ----a-w- c:\windows\system32\deployJava1.dll

    2012-06-22 23:05 . 2012-06-22 23:05 -------- d-----w- c:\program files\Java

    2012-06-22 15:37 . 2012-06-22 15:53 -------- d-----w- c:\users\Ronald Glickman\DoctorWeb

    2012-06-22 13:32 . 2012-06-22 13:32 -------- d-----w- c:\programdata\Kaspersky Lab

    2012-06-22 12:25 . 2012-06-22 12:25 -------- d-----w- c:\program files (x86)\ESET

    2012-06-22 01:34 . 2012-05-31 04:04 9013136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

    2012-06-21 19:07 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll

    2012-06-21 19:07 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe

    2012-06-21 19:07 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll

    2012-06-21 19:07 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll

    2012-06-21 19:07 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll

    2012-06-21 19:07 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll

    2012-06-21 19:07 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll

    2012-06-21 19:07 . 2012-06-02 19:19 186752 ----a-w- c:\windows\system32\wuwebv.dll

    2012-06-21 19:07 . 2012-06-02 19:15 36864 ----a-w- c:\windows\system32\wuapp.exe

    2012-06-19 16:31 . 2012-06-19 22:24 -------- d-----w- c:\program files (x86)\Common Files\Steam

    2012-06-19 16:31 . 2012-06-22 19:56 -------- d-----w- c:\program files (x86)\Steam

    2012-06-16 22:16 . 2012-06-16 22:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\MAGIX

    2012-06-16 16:24 . 2012-06-16 16:24 -------- d-----w- c:\windows\SysWow64\RTCOM

    2012-06-16 12:06 . 2012-06-16 12:06 -------- d-----w- c:\programdata\Nexon

    2012-06-16 12:02 . 2012-06-16 12:02 -------- d-----w- C:\Nexon

    2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\program files\Microsoft IntelliPoint

    2012-06-13 18:46 . 2012-06-13 18:56 -------- d-----w- c:\program files (x86)\Razer

    2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Razer

    2012-06-13 18:46 . 2012-06-13 18:46 -------- d-----w- c:\programdata\Razer

    2012-06-13 10:17 . 2011-12-12 21:42 1256192 ----a-w- c:\windows\system32\drivers\bcmwlhigh664.sys

    2012-06-13 10:17 . 2011-04-19 21:52 95544 ----a-w- c:\windows\system32\bcmwlcoi.dll

    2012-06-13 10:17 . 2011-04-19 21:31 3900928 ----a-w- c:\windows\system32\bcmihvsrv64.dll

    2012-06-13 10:17 . 2011-04-19 21:31 3566592 ----a-w- c:\windows\system32\bcmihvui64.dll

    2012-06-13 10:17 . 2010-06-09 17:11 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll

    2012-06-13 10:17 . 2010-02-03 15:20 47632 ----a-w- c:\windows\system32\drivers\npf.sys

    2012-06-13 10:17 . 2011-07-22 14:33 25056 ----a-w- c:\windows\system32\drivers\SCMNdisP.sys

    2012-06-13 10:17 . 2012-06-13 10:17 -------- d-----w- c:\program files (x86)\NETGEAR

    2012-06-12 18:42 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll

    2012-06-12 17:12 . 2012-06-12 17:12 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins

    2012-06-12 17:03 . 2012-06-12 17:03 -------- d-----w- c:\programdata\EA Core

    2012-06-12 17:03 . 2012-06-13 17:40 -------- d-----w- c:\programdata\EA Logs

    2012-06-12 16:35 . 2007-10-12 19:14 2006552 ----a-w- c:\windows\system32\D3DCompiler_36.dll

    2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll

    2012-06-12 16:17 . 2012-05-31 20:38 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5DD60F6-F67B-4B8C-AF21-C5E783A93374}\gapaengine.dll

    2012-06-12 14:59 . 2012-06-12 15:00 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Origin

    2012-06-12 14:59 . 2012-06-12 14:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Origin

    2012-06-12 14:58 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Electronic Arts

    2012-06-12 14:58 . 2012-06-12 16:11 -------- d-----w- c:\program files (x86)\Origin Games

    2012-06-12 14:58 . 2012-06-12 15:00 -------- d-----w- c:\program files (x86)\Origin

    2012-06-12 14:44 . 2012-06-12 17:03 -------- d-----w- c:\programdata\Origin

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll

    2012-06-11 21:51 . 2012-06-11 21:51 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll

    2012-06-11 21:50 . 2012-06-11 21:51 -------- d-----w- c:\program files (x86)\QuickTime

    2012-06-11 13:34 . 2012-06-11 13:34 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\OpenOffice.org

    2012-06-11 13:22 . 2012-06-11 13:22 -------- d-----w- c:\program files\CCleaner

    2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\programdata\IObit

    2012-06-11 11:15 . 2012-06-11 11:15 -------- d-----w- c:\program files (x86)\IObit

    2012-06-10 15:52 . 2012-06-10 15:52 -------- d-----w- c:\programdata\McAfee

    2012-06-10 15:52 . 2012-06-16 22:26 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

    2012-06-10 15:52 . 2012-06-16 22:26 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

    2012-06-10 15:21 . 2012-06-10 15:21 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Tipard Studio

    2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\programdata\Tipard MKV Video Converter

    2012-06-10 15:19 . 2012-06-10 15:19 -------- d-----w- c:\program files (x86)\Tipard Studio

    2012-06-10 12:55 . 2012-06-10 12:55 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Macromedia

    2012-06-08 14:16 . 2012-06-08 14:16 -------- d-----w- c:\program files (x86)\Virtual Magnifying Glass

    2012-06-07 21:19 . 2012-06-18 03:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\JPEGsnoop

    2012-06-06 13:08 . 2012-06-06 13:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\TouchStoneSoftware

    2012-06-04 23:37 . 2011-05-28 04:29 67176 ----a-w- c:\windows\system32\OpenCL.dll

    2012-06-04 23:37 . 2011-05-28 04:29 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll

    2012-06-04 21:59 . 2012-03-11 06:17 121344 ----a-w- c:\windows\system32\IntelOpenCL64.dll

    2012-06-04 21:59 . 2012-03-11 06:09 86528 ----a-w- c:\windows\SysWow64\IntelOpenCL32.dll

    2012-06-04 19:14 . 2012-06-21 00:03 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr

    2012-06-04 19:13 . 2012-06-12 17:13 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\PunkBuster

    2012-06-04 18:59 . 2012-06-04 18:59 -------- d-----w- c:\program files (x86)\EA Games

    2012-06-04 13:25 . 2012-06-04 13:25 -------- d-----w- c:\program files (x86)\Common Files\Java

    2012-06-04 13:24 . 2012-06-04 13:24 -------- d-----w- c:\program files (x86)\Oracle

    2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\program files (x86)\SystemRequirementsLab

    2012-06-04 12:55 . 2012-06-08 11:26 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\SystemRequirementsLab

    2012-06-03 23:27 . 2012-06-03 23:27 -------- d-----w- c:\program files (x86)\ImageShack Uploader

    2012-06-03 18:54 . 2011-11-08 14:18 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll

    2012-06-03 18:54 . 2011-11-08 14:18 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll

    2012-06-03 18:54 . 2009-12-05 23:42 85504 ----a-w- c:\windows\SysWow64\ff_vfw.dll

    2012-06-03 18:54 . 2012-06-03 18:54 -------- d-----w- c:\program files (x86)\ffdshow

    2012-06-03 18:45 . 2012-06-22 20:42 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\vlc

    2012-06-03 18:44 . 2012-06-03 18:44 -------- d-----w- c:\program files (x86)\VideoLAN

    2012-06-03 15:21 . 2011-09-16 15:28 210432 ----a-w- c:\program files\Windows Sidebar\Shared Gadgets\InstantOn.gadget\InstantOnCOM.dll

    2012-06-03 15:21 . 2012-06-03 15:21 -------- d-----w- c:\program files (x86)\Common Files\InstantOn

    2012-06-03 04:31 . 2012-05-15 10:48 249152 ----a-w- c:\windows\system32\drivers\nvkflt.sys

    2012-06-03 04:31 . 2012-05-15 10:48 1738048 ----a-w- c:\windows\system32\nvdispco64.dll

    2012-06-03 04:31 . 2012-05-15 10:48 1468224 ----a-w- c:\windows\system32\nvgenco64.dll

    2012-06-03 04:30 . 2012-06-03 04:30 -------- d-----w- C:\NVIDIA

    2012-06-02 06:40 . 2012-06-08 21:59 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\X-Chat 2

    2012-06-02 06:40 . 2012-06-02 06:40 -------- d-----w- c:\program files (x86)\xchat

    2012-06-01 23:32 . 2012-06-01 23:32 -------- d-----w- c:\program files (x86)\Moffsoft FreeCalc

    2012-06-01 15:44 . 2010-10-01 04:16 13312 ----a-w- c:\windows\system32\drivers\VKbms.sys

    2012-06-01 15:44 . 2010-09-30 00:45 6656 ----a-w- c:\windows\system32\drivers\hidkmdf.sys

    2012-06-01 13:00 . 2012-06-01 13:00 -------- d-----w- c:\program files (x86)\CleanUp!

    2012-05-31 23:34 . 2012-06-22 18:16 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Akamai

    2012-05-31 23:01 . 2012-05-31 23:01 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\Diagnostics

    2012-05-31 22:13 . 2012-05-31 22:13 -------- d-----w- c:\programdata\WEBREG

    2012-05-31 22:10 . 2012-06-07 23:46 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\HP

    2012-05-31 22:10 . 2012-05-31 22:10 -------- d-----w- c:\users\Ronald Glickman\AppData\Local\HP

    2012-05-31 22:09 . 2009-06-09 05:48 249856 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpfpp092.dll

    2012-05-31 22:08 . 2012-05-31 22:08 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\Yahoo!

    2012-05-31 22:08 . 2012-06-10 12:35 -------- d-----w- c:\program files (x86)\Yahoo!

    2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\programdata\HP Product Assistant

    2012-05-31 22:06 . 2012-05-31 22:06 -------- d-----w- c:\windows\SysWow64\spool

    2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\HP

    2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\program files (x86)\Common Files\Hewlett-Packard

    2012-05-31 22:04 . 2012-05-31 22:04 -------- d-----w- c:\windows\hpoj4500g510n-z

    2012-05-31 22:03 . 2009-05-26 17:32 902656 ----a-w- c:\windows\system32\hpwwiax9.dll

    2012-05-31 22:03 . 2009-05-26 17:32 742912 ----a-w- c:\windows\system32\hpwtscl5.dll

    2012-05-31 22:03 . 2009-05-26 17:32 503296 ----a-w- c:\windows\system32\hpwvst01.dll

    2012-05-31 22:03 . 2009-05-18 21:51 551424 ----a-w- c:\windows\system32\hppldcoi.dll

    2012-05-31 22:03 . 2009-05-21 13:14 642360 ----a-w- c:\windows\system32\hpzids40.dll

    2012-05-31 22:03 . 2009-06-09 05:48 136704 ----a-w- c:\windows\system32\hpf3l092.dll

    2012-05-31 22:02 . 2012-05-31 22:07 -------- d-----w- c:\program files (x86)\HP

    2012-05-31 22:00 . 2012-05-31 22:11 -------- d-----w- c:\programdata\HP

    2012-05-31 21:54 . 2012-05-31 21:54 -------- d-----w- c:\users\Ronald Glickman\AppData\Roaming\FLEXnet

    2012-05-31 20:38 . 2012-01-31 12:44 279656 ------w- c:\windows\system32\MpSigStub.exe

    .

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-06-23 00:08 . 2011-09-11 17:24 45056 ----a-w- c:\windows\SysWow64\acovcnt.exe

    2012-05-15 21:59 . 2010-06-24 18:33 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

    2012-05-15 10:48 . 2011-09-11 17:06 949056 ----a-w- c:\windows\system32\nvumdshimx.dll

    2012-05-15 10:48 . 2011-09-11 17:06 818496 ----a-w- c:\windows\SysWow64\nvumdshim.dll

    2012-05-15 10:48 . 2011-09-11 17:06 246592 ----a-w- c:\windows\system32\nvinitx.dll

    2012-05-15 10:48 . 2011-09-11 17:06 202048 ----a-w- c:\windows\SysWow64\nvinit.dll

    2012-05-15 10:48 . 2011-09-11 17:06 18044224 ----a-w- c:\windows\system32\nvd3dumx.dll

    2012-05-15 10:48 . 2011-09-11 17:06 2741568 ----a-w- c:\windows\system32\nvapi64.dll

    2012-05-15 10:48 . 2011-09-11 17:06 2368832 ----a-w- c:\windows\SysWow64\nvapi.dll

    2012-05-15 09:29 . 2011-05-27 13:38 889664 ----a-w- c:\windows\system32\nvvsvc.exe

    2012-05-15 09:29 . 2011-05-27 13:38 858944 ----a-w- c:\windows\system32\nv3dappshext.dll

    2012-05-15 09:29 . 2011-05-27 16:38 63296 ----a-w- c:\windows\system32\nvshext.dll

    2012-05-15 09:29 . 2011-05-27 13:38 55616 ----a-w- c:\windows\system32\nv3dappshextr.dll

    2012-05-15 09:29 . 2011-05-27 13:38 2561856 ----a-w- c:\windows\system32\nvsvcr.dll

    2012-05-15 09:29 . 2011-05-27 13:38 118080 ----a-w- c:\windows\system32\nvmctray.dll

    2012-05-15 09:29 . 2011-05-27 16:38 2621723 ----a-w- c:\windows\system32\nvcoproc.bin

    2012-05-15 09:29 . 2011-05-27 13:38 3149632 ----a-w- c:\windows\system32\nvsvc64.dll

    2012-05-15 09:28 . 2011-05-27 13:38 6151488 ----a-w- c:\windows\system32\nvcpl.dll

    2012-05-15 06:21 . 2012-05-15 06:21 423744 ----a-w- c:\windows\SysWow64\nvStreaming.exe

    2012-05-15 02:50 . 2012-05-15 02:50 20992 ----a-w- c:\windows\system32\drivers\rzvkeyboard.sys

    2012-05-15 02:50 . 2012-05-15 02:50 94208 ----a-w- c:\windows\system32\drivers\rzudd.sys

    2012-05-15 02:36 . 2012-05-15 02:36 142848 ----a-w- c:\windows\SysWow64\rztouchdll.dll

    2012-05-15 02:36 . 2012-05-15 02:36 354816 ----a-w- c:\windows\SysWow64\rzdevicedll.dll

    2012-05-15 02:36 . 2012-05-15 02:36 165888 ----a-w- c:\windows\SysWow64\rzaudiodll.dll

    2012-05-08 02:46 . 2012-05-08 02:46 7168 ----a-w- c:\windows\system32\drivers\rzkbdhid.sys

    2012-05-08 02:46 . 2012-05-08 02:46 26112 ----a-w- c:\windows\system32\drivers\rzdaendpt.sys

    2012-04-19 00:56 . 2012-04-19 00:56 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx

    2012-04-19 00:56 . 2012-04-19 00:56 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts

    2012-04-04 22:47 . 2012-05-15 22:15 772504 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

    2012-04-04 22:47 . 2012-05-15 22:15 687504 ----a-w- c:\windows\SysWow64\deployJava1.dll

    2012-04-04 19:56 . 2012-05-15 22:19 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-03-30 11:35 . 2012-05-16 22:10 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys

    .

    .

    ((((((((((((((((((((((((((((( SnapShot@2012-06-22_00.58.32 )))))))))))))))))))))))))))))))))))))))))

    .

    + 2011-02-18 20:13 . 2012-06-23 00:09 57462 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

    + 2009-07-14 05:10 . 2012-06-23 00:09 42110 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

    + 2012-05-15 22:00 . 2012-06-23 00:09 12236 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-953877884-1205063476-829431027-1001_UserData.bin

    + 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

    - 2012-06-22 00:49 . 2012-06-22 00:49 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2012-06-23 00:07 . 2012-06-23 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

    + 2012-06-22 23:05 . 2012-06-22 23:05 268720 c:\windows\system32\javaws.exe

    + 2012-06-22 23:05 . 2012-06-22 23:05 189360 c:\windows\system32\javaw.exe

    + 2012-06-22 23:05 . 2012-06-22 23:05 188840 c:\windows\system32\java.exe

    + 2009-07-14 05:01 . 2012-06-23 00:06 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

    - 2009-07-14 05:01 . 2012-06-22 00:48 502696 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

    + 2012-06-22 23:04 . 2012-06-22 23:04 891392 c:\windows\Installer\104132a.msi

    - 2012-05-15 22:03 . 2012-06-22 00:48 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat

    + 2012-05-15 22:03 . 2012-06-23 00:06 9729984 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-8192.dat

    - 2012-05-15 23:49 . 2012-06-21 23:15 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat

    + 2012-05-15 23:49 . 2012-06-23 00:07 5492268 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-953877884-1205063476-829431027-1001-12288.dat

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 94208 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

    .

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]

    "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

    "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992]

    "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-02 2018032]

    "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472]

    "SonicMasterTray"="c:\program files (x86)\ASUS\SonicMaster\SonicMasterTray.exe" [2010-07-10 984400]

    "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]

    "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]

    "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]

    "RemoteControl10"="c:\program files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]

    "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2010-11-12 75048]

    "UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-11-24 222504]

    "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]

    "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]

    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]

    "KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]

    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]

    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]

    "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]

    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]

    "Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2012-05-29 313768]

    .

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

    AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe [2011-4-2 549040]

    FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe [2012-5-31 12862]

    HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

    NETGEAR WNDA3100v2 Genie.lnk - c:\program files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2012-6-13 8453376]

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

    "ConsentPromptBehaviorAdmin"= 5 (0x5)

    "ConsentPromptBehaviorUser"= 3 (0x3)

    "EnableUIADesktopToggle"= 0 (0x0)

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

    "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll

    .

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

    @="Service"

    .

    R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/09/11 10:30;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-11-12 241648]

    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]

    R2 WSWNDA3100v2;WSWNDA3100v2;c:\program files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [2011-12-14 303360]

    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-16 257224]

    R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]

    R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]

    R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [x]

    R3 cphs;Intel® Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-03-20 276248]

    R3 CYUSB;Cypress Generic USB Driver;c:\windows\system32\Drivers\CYUSB.sys [x]

    R3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]

    R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x]

    R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]

    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 135664]

    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]

    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]

    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]

    R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]

    R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]

    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]

    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]

    R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]

    R3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x]

    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

    R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [2010-11-01 14544]

    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files (x86)\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]

    S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [x]

    S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2010-07-26 17024]

    S1 nvkflt;nvkflt;c:\windows\system32\DRIVERS\nvkflt.sys [x]

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]

    S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe [x]

    S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]

    S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-09-08 92800]

    S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-03-13 138400]

    S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912]

    S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2011-01-14 1839616]

    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]

    S2 Splashtop MDES;Splashtop Meta Data Export Service;c:\asus.sys\SIONExportService.exe [2011-05-10 338208]

    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]

    S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-03-19 2666880]

    S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]

    S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]

    S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys [x]

    S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [x]

    S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [x]

    S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x]

    S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x]

    S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x]

    S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x]

    S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x]

    S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x]

    S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x]

    S3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]

    S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]

    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]

    S3 MEIx64;Intel® Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [x]

    S3 rzdaendpt;%rzdaendpt.SvcDesc%;c:\windows\system32\DRIVERS\rzdaendpt.sys [x]

    S3 rzudd;Razer Keyboard Driver;c:\windows\system32\DRIVERS\rzudd.sys [x]

    S3 rzvkeyboard;Razer Virtual Keyboard Driver;c:\windows\system32\DRIVERS\rzvkeyboard.sys [x]

    .

    .

    --- Other Services/Drivers In Memory ---

    .

    *Deregistered* - CLKMDRV10_38F51D56

    .

    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .

    Contents of the 'Scheduled Tasks' folder

    .

    2012-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-10 22:26]

    .

    2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]

    .

    2012-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-02 04:36]

    .

    .

    --------- X64 Entries -----------

    .

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]

    @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"

    [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]

    2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]

    @="{64174815-8D98-4CE6-8646-4C039977D808}"

    [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]

    2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

    2012-02-15 00:32 97792 ----a-w- c:\users\Ronald Glickman\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2011-03-21 361984]

    "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [bU]

    "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120]

    "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552]

    "SynAsusAcpi"="c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe" [bU]

    "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]

    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-19 170264]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-19 398616]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-19 439064]

    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]

    "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 2277480]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    "AppInit_DLLs"=c:\windows\System32\nvinitx.dll

    .

    ------- Supplementary Scan -------

    .

    uLocal Page = c:\windows\system32\blank.htm

    mStart Page = hxxp://asus.msn.com

    mLocal Page = c:\windows\SysWOW64\blank.htm

    uInternet Settings,ProxyOverride = *.local;<local>

    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

    TCP: DhcpNameServer = 192.168.2.1

    FF - ProfilePath - c:\users\Ronald Glickman\AppData\Roaming\Mozilla\Firefox\Profiles\k2hn4jp8.default\

    FF - prefs.js: browser.startup.homepage - hxxp://combatarms.nexon.net/|http://battlelog.battlefield.com/bf3/gate/|http://forums.thecbl.net/ucp.php?mode=login|http://yellowsnowarmy.com/

    FF - user.js: extensions.autoDisableScopes - 14

    .

    - - - - ORPHANS REMOVED - - - -

    .

    Toolbar-Locked - (no file)

    .

    .

    .

    --------------------- LOCKED REGISTRY KEYS ---------------------

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Shockwave Flash Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

    @="0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

    @="ShockwaveFlash.ShockwaveFlash.11"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="ShockwaveFlash.ShockwaveFlash"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

    @Denied: (A 2) (Everyone)

    @="Macromedia Flash Factory Object"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"

    "ThreadingModel"="Apartment"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

    @="FlashFactory.FlashFactory.1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

    @="1.0"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

    @="FlashFactory.FlashFactory"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker4"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

    @Denied: (Full) (Everyone)

    .

    Completion time: 2012-06-22 21:12:56

    ComboFix-quarantined-files.txt 2012-06-23 01:12

    ComboFix2.txt 2012-06-22 01:00

    .

    Pre-Run: 382,098,587,648 bytes free

    Post-Run: 381,901,774,848 bytes free

    .

    - - End Of File - - 26733B94D1EF8A46D71C0A005273615D

  6. I just received the IP block message again from the same IP address.

    2012/06/22 19:36:03 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 56530, Process: chrome.exe)

    2012/06/22 19:36:03 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 56532, Process: chrome.exe)

  7. netsession_win.exe;c:\users\ronald glickman\appdata\local\akamai;Probably DLOADER.Trojan;Incurable.Moved.; netsession_win.exe;c:\users\ronald glickman\appdata\local\akamai;Probably DLOADER.Trojan;Invalid path to file ; netsession_win.exe;C:\Documents and Settings\Ronald Glickman\AppData\Local\Akamai;Probably DLOADER.Trojan;Invalid path to file ; netsession_win.exe;C:\Documents and Settings\Ronald Glickman\AppData\Local\Application Data\Akamai;Probably DLOADER.Trojan;Invalid path to file ; netsession_win.exe;C:\Documents and Settings\Ronald Glickman\DoctorWeb\Quarantine;Probably DLOADER.Trojan;Incurable.Moved.; netsession_win.exe;C:\Users\Ronald Glickman\AppData\Local\Akamai;Probably DLOADER.Trojan;Invalid path to file ; OTL.exe;E:\RSG Downloads;Trojan.Siggen4.6108;Incurable.Moved.;

  8. MiniToolBox by Farbar Version: 09-06-2012

    Ran by Ronald Glickman (administrator) on 22-06-2012 at 11:30:02

    Microsoft Windows 7 Home Premium Service Pack 1 (X64)

    Boot Mode: Normal

    ***************************************************************************

    ========================= Flush DNS: ===================================

    Windows IP Configuration

    Successfully flushed the DNS Resolver Cache.

    ========================= IE Proxy Settings: ==============================

    Proxy is not enabled.

    No Proxy Server is set.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.

    ========================= FF Proxy Settings: ==============================

    "Reset FF Proxy Settings": Firefox Proxy settings were reset.

    ========================= Hosts content: =================================

    127.0.0.1 localhost

    ========================= IP Configuration: ================================

    Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20) = Local Area Connection (Connected)

    Atheros AR9002WB-1NG Wireless Network Adapter = Wireless Network Connection (Media disconnected)

    Bluetooth Device (Personal Area Network) = Bluetooth Network Connection 2 (Media disconnected)

    # ----------------------------------

    # IPv4 Configuration

    # ----------------------------------

    pushd interface ipv4

    reset

    set global

    popd

    # End of IPv4 configuration

    Windows IP Configuration

    Host Name . . . . . . . . . . . . : Jags-Awesome-PC

    Primary Dns Suffix . . . . . . . :

    Node Type . . . . . . . . . . . . : Hybrid

    IP Routing Enabled. . . . . . . . : No

    WINS Proxy Enabled. . . . . . . . : No

    Ethernet adapter Bluetooth Network Connection 2:

    Media State . . . . . . . . . . . : Media disconnected

    Connection-specific DNS Suffix . :

    Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network) #2

    Physical Address. . . . . . . . . : 74-2F-68-B8-8C-CC

    DHCP Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :

    Description . . . . . . . . . . . : Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)

    Physical Address. . . . . . . . . : 14-DA-E9-66-23-F1

    DHCP Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    Link-local IPv6 Address . . . . . : fe80::6511:f4b0:8d4c:6b6f%14(Preferred)

    IPv4 Address. . . . . . . . . . . : 192.168.2.9(Preferred)

    Subnet Mask . . . . . . . . . . . : 255.255.255.0

    Lease Obtained. . . . . . . . . . : Friday, June 22, 2012 8:14:14 AM

    Lease Expires . . . . . . . . . . : Saturday, June 23, 2012 8:14:14 AM

    Default Gateway . . . . . . . . . : 192.168.2.1

    DHCP Server . . . . . . . . . . . : 192.168.2.1

    DHCPv6 IAID . . . . . . . . . . . : 387242729

    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-FE-A1-03-74-2F-68-B9-58-7D

    DNS Servers . . . . . . . . . . . : 192.168.2.1

    NetBIOS over Tcpip. . . . . . . . : Enabled

    Wireless LAN adapter Wireless Network Connection:

    Media State . . . . . . . . . . . : Media disconnected

    Connection-specific DNS Suffix . :

    Description . . . . . . . . . . . : Atheros AR9002WB-1NG Wireless Network Adapter

    Physical Address. . . . . . . . . : 74-2F-68-B9-58-7D

    DHCP Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    Tunnel adapter isatap.{1BC833C7-962F-4E56-A43D-9DE390C45F72}:

    Media State . . . . . . . . . . . : Media disconnected

    Connection-specific DNS Suffix . :

    Description . . . . . . . . . . . : Microsoft ISATAP Adapter

    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

    DHCP Enabled. . . . . . . . . . . : No

    Autoconfiguration Enabled . . . . : Yes

    Tunnel adapter Teredo Tunneling Pseudo-Interface:

    Connection-specific DNS Suffix . :

    Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface

    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0

    DHCP Enabled. . . . . . . . . . . : No

    Autoconfiguration Enabled . . . . : Yes

    IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:245e:3c28:b4ba:2f4d(Preferred)

    Link-local IPv6 Address . . . . . : fe80::245e:3c28:b4ba:2f4d%18(Preferred)

    Default Gateway . . . . . . . . . : ::

    NetBIOS over Tcpip. . . . . . . . : Disabled

    Server: UnKnown

    Address: 192.168.2.1

    Name: google.com

    Addresses: 2607:f8b0:4006:801::1000

    74.125.226.206

    74.125.226.201

    74.125.226.197

    74.125.226.198

    74.125.226.194

    74.125.226.196

    74.125.226.199

    74.125.226.193

    74.125.226.200

    74.125.226.192

    74.125.226.195

    Pinging google.com [173.194.43.8] with 32 bytes of data:

    Reply from 173.194.43.8: bytes=32 time=38ms TTL=54

    Reply from 173.194.43.8: bytes=32 time=40ms TTL=54

    Ping statistics for 173.194.43.8:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 38ms, Maximum = 40ms, Average = 39ms

    Server: UnKnown

    Address: 192.168.2.1

    Name: yahoo.com

    Addresses: 98.139.183.24

    209.191.122.70

    72.30.38.140

    Pinging yahoo.com [98.139.183.24] with 32 bytes of data:

    Reply from 98.139.183.24: bytes=32 time=301ms TTL=50

    Reply from 98.139.183.24: bytes=32 time=287ms TTL=50

    Ping statistics for 98.139.183.24:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 287ms, Maximum = 301ms, Average = 294ms

    Server: UnKnown

    Address: 192.168.2.1

    Name: bleepingcomputer.com

    Address: 208.43.87.2

    Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:

    Reply from 208.43.87.2: Destination host unreachable.

    Reply from 208.43.87.2: Destination host unreachable.

    Ping statistics for 208.43.87.2:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Pinging 127.0.0.1 with 32 bytes of data:

    Reply from 127.0.0.1: bytes=32 time=2ms TTL=128

    Reply from 127.0.0.1: bytes=32 time=1ms TTL=128

    Ping statistics for 127.0.0.1:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 1ms, Maximum = 2ms, Average = 1ms

    ===========================================================================

    Interface List

    17...74 2f 68 b8 8c cc ......Bluetooth Device (Personal Area Network) #2

    14...14 da e9 66 23 f1 ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)

    11...74 2f 68 b9 58 7d ......Atheros AR9002WB-1NG Wireless Network Adapter

    1...........................Software Loopback Interface 1

    20...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter

    18...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface

    ===========================================================================

    IPv4 Route Table

    ===========================================================================

    Active Routes:

    Network Destination Netmask Gateway Interface Metric

    0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.9 20

    127.0.0.0 255.0.0.0 On-link 127.0.0.1 306

    127.0.0.1 255.255.255.255 On-link 127.0.0.1 306

    127.255.255.255 255.255.255.255 On-link 127.0.0.1 306

    192.168.2.0 255.255.255.0 On-link 192.168.2.9 276

    192.168.2.9 255.255.255.255 On-link 192.168.2.9 276

    192.168.2.255 255.255.255.255 On-link 192.168.2.9 276

    224.0.0.0 240.0.0.0 On-link 127.0.0.1 306

    224.0.0.0 240.0.0.0 On-link 192.168.2.9 276

    255.255.255.255 255.255.255.255 On-link 127.0.0.1 306

    255.255.255.255 255.255.255.255 On-link 192.168.2.9 276

    ===========================================================================

    Persistent Routes:

    None

    IPv6 Route Table

    ===========================================================================

    Active Routes:

    If Metric Network Destination Gateway

    18 58 ::/0 On-link

    1 306 ::1/128 On-link

    18 58 2001::/32 On-link

    18 306 2001:0:4137:9e76:245e:3c28:b4ba:2f4d/128

    On-link

    14 276 fe80::/64 On-link

    18 306 fe80::/64 On-link

    18 306 fe80::245e:3c28:b4ba:2f4d/128

    On-link

    14 276 fe80::6511:f4b0:8d4c:6b6f/128

    On-link

    1 306 ff00::/8 On-link

    18 306 ff00::/8 On-link

    14 276 ff00::/8 On-link

    ===========================================================================

    Persistent Routes:

    None

    ========================= Winsock entries =====================================

    Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)

    Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)

    Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)

    Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)

    Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)

    Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)

    Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)

    Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)

    Catalog5 10 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)

    Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)

    x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)

    x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)

    x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)

    x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)

    x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)

    x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)

    x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)

    x64-Catalog5 09 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)

    x64-Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)

    x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

    ========================= Event log errors: ===============================

    Application errors:

    ==================

    Error: (06/22/2012 09:31:54 AM) (Source: Application Error) (User: )

    Description: Faulting application name: sidebar.exe, version: 6.1.7601.17514, time stamp: 0x4ce7a1c7

    Faulting module name: InstantOnCOM.dll, version: 1.0.0.1, time stamp: 0x4e72c267

    Exception code: 0xc0000417

    Fault offset: 0x0000000000013c68

    Faulting process id: 0x1240

    Faulting application start time: 0xsidebar.exe0

    Faulting application path: sidebar.exe1

    Faulting module path: sidebar.exe2

    Report Id: sidebar.exe3

    Error: (06/22/2012 09:06:49 AM) (Source: SideBySide) (User: )

    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.

    A component version required by the application conflicts with another component version already active.

    Conflicting components are:.

    Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

    Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

    Error: (06/22/2012 00:13:01 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: m->NextScheduledSPRetry 8003

    Error: (06/22/2012 00:13:01 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: m->NextScheduledEvent 8003

    Error: (06/22/2012 00:13:01 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (06/22/2012 00:13:00 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: m->NextScheduledSPRetry 7005

    Error: (06/22/2012 00:13:00 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: m->NextScheduledEvent 7005

    Error: (06/22/2012 00:13:00 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (06/22/2012 00:12:59 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: m->NextScheduledSPRetry 6006

    Error: (06/22/2012 00:12:59 AM) (Source: Bonjour Service) (User: )

    Description: Task Scheduling Error: m->NextScheduledEvent 6006

    System errors:

    =============

    Error: (06/21/2012 08:49:31 PM) (Source: Service Control Manager) (User: )

    Description: The Windows Defender service terminated with the following error:

    %%126

    Error: (06/21/2012 08:48:31 PM) (Source: Service Control Manager) (User: )

    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (06/21/2012 08:48:26 PM) (Source: Service Control Manager) (User: )

    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (06/21/2012 08:48:01 PM) (Source: Application Popup) (User: )

    Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

    Error: (06/21/2012 08:46:11 PM) (Source: Service Control Manager) (User: )

    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (06/21/2012 08:41:52 PM) (Source: Service Control Manager) (User: )

    Description: The HP CUE DeviceDiscovery Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (06/21/2012 08:41:52 PM) (Source: Service Control Manager) (User: )

    Description: The hpqcxs08 service terminated unexpectedly. It has done this 1 time(s).

    Error: (06/21/2012 08:22:17 PM) (Source: Service Control Manager) (User: )

    Description: The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (06/20/2012 04:12:31 PM) (Source: Tcpip) (User: )

    Description: The system detected an address conflict for IP address 192.168.2.5 with the system

    having network hardware address 68-B5-99-54-2F-04. Network operations on this system may

    be disrupted as a result.

    Error: (06/19/2012 00:32:07 PM) (Source: Service Control Manager) (User: )

    Description: The Steam Client Service service failed to start due to the following error:

    %%1053

    Microsoft Office Sessions:

    =========================

    =========================== Installed Programs ============================

    Update for Microsoft Office 2007 (KB2508958)

    ??????? Windows Live Mesh ActiveX ??(????) (Version: 15.4.5722.2)

    ??????? Windows Live Mesh ActiveX ??? (Version: 15.4.5722.2)

    4500_G510nz_Help (Version: 000.0.439.000)

    4500G510nz (Version: 000.0.439.000)

    4500G510nz_Software_Min (Version: 000.0.423.000)

    64 Bit HP CIO Components Installer (Version: 6.2.1)

    Adobe Flash Player 11 ActiveX (Version: 11.3.300.257)

    Adobe Flash Player 11 Plugin (Version: 11.3.300.257)

    Adobe Reader X (10.1.3) (Version: 10.1.3)

    Adobe Shockwave Player 11.6 (Version: 11.6.5.635)

    Akamai NetSession Interface

    Alcor Micro USB Card Reader (Version: 1.2.0117.08443)

    Apple Application Support (Version: 2.1.7)

    Apple Mobile Device Support (Version: 5.1.1.4)

    Apple Software Update (Version: 2.1.3.127)

    AsMakeLink

    Asmedia ASM104x USB 3.0 Host Controller Driver (Version: 1.6.3.0)

    ASUS AI Recovery (Version: 1.0.13)

    ASUS FancyStart (Version: 1.1.0)

    ASUS LifeFrame3 (Version: 3.0.22)

    ASUS Music Maker (Version: 17.0.2.22)

    ASUS Power4Gear Hybrid (Version: 1.1.45)

    ASUS Splendid Video Enhancement Technology (Version: 1.02.0033)

    ASUS USB Charger Plus (Version: 2.0.2)

    ASUS Video Magic (Version: 6.0.4710)

    ASUS Virtual Camera (Version: 1.0.21)

    ASUS WebStorage (Version: 3.0.84.161)

    AsusScr_N5_En (Version: 1.0.0001)

    AsusVibe2.0 (Version: 2.0.10.168)

    Atheros Client Installation Program (Version: 7.0)

    ATK Package (Version: 1.0.0008)

    Battlefield 3™ (Version: 1.0.0.0)

    Battlelog Web Plugins (Version: 1.122.0)

    Bing Bar (Version: 7.0.610.0)

    Bluetooth Win7 Suite (64) (Version: 7.2.0.65)

    Bonjour (Version: 3.0.0.10)

    BufferChm (Version: 130.0.331.000)

    CCleaner (Version: 3.19)

    CleanUp!

    Combat Arms

    Counter-Strike: Source

    CyberLink LabelPrint (Version: 2.5.1908)

    CyberLink MediaEspresso (Version: 6.0.1123_32710)

    CyberLink Power2Go (Version: 6.1.3602c)

    CyberLink PowerDirector (Version: 8.0.3327)

    CyberLink PowerDVD 10 (Version: 10.0.2312.52)

    D3DX10 (Version: 15.4.2368.0902)

    Destinations (Version: 130.0.0.0)

    DeviceDiscovery (Version: 130.0.372.000)

    DocMgr (Version: 130.0.000.000)

    DocProc (Version: 13.0.0.0)

    Dropbox (Version: 1.4.7)

    ESET Online Scanner v3

    ESN Sonar (Version: 0.70.4)

    Fast Boot (Version: 1.0.9)

    Fax (Version: 130.0.418.000)

    ffdshow [rev 3154] [2009-12-09] (Version: 1.0)

    Firebird SQL Server - MAGIX Edition (Version: 2.1.29.0)

    Freemake Video Converter version 3.0.2 (Version: 3.0.2)

    Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922)

    Galerie de photos Windows Live (Version: 15.4.3502.0922)

    Galería fotográfica de Windows Live (Version: 15.4.3502.0922)

    Game Booster 3 (Version: 3.4)

    Google Chrome (Version: 19.0.1084.56)

    Google Update Helper (Version: 1.3.21.111)

    GPBaseService2 (Version: 130.0.371.000)

    HP Customer Participation Program 13.0 (Version: 13.0)

    HP Document Manager 2.0 (Version: 2.0)

    HP Imaging Device Functions 13.0 (Version: 13.0)

    HP Officejet 4500 G510n-z (Version: 13.0)

    HP Smart Web Printing 4.5 (Version: 4.5)

    HP Solution Center 13.0 (Version: 13.0)

    HP Update (Version: 4.000.011.006)

    HPProductAssistant (Version: 130.0.371.000)

    HPSSupply (Version: 130.0.371.000)

    ImageShack Uploader 2.2.0 (Version: 2.2.0)

    InstantOn for NB (Version: 2.1.5)

    Intel® Control Center (Version: 1.2.1.1007)

    Intel® Management Engine Components (Version: 7.0.0.1118)

    Intel® OpenCL CPU Runtime

    Intel® Processor Graphics (Version: 8.15.10.2696)

    Intel® Turbo Boost Technology Monitor 2.0 (Version: 2.1.23.0)

    iTunes (Version: 10.6.1.7)

    Java Auto Updater (Version: 2.1.6.0)

    Java 7 Update 4 (Version: 7.0.40)

    JavaFX 2.1.0 (Version: 2.1.0)

    Junk Mail filter update (Version: 15.4.3502.0922)

    KeePass Password Safe 2.19

    Malwarebytes Anti-Malware version 1.61.0.1400 (Version: 1.61.0.1400)

    MarketResearch (Version: 130.0.374.000)

    Mesh Runtime (Version: 15.4.5722.2)

    Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)

    Microsoft .NET Framework 4 Extended (Version: 4.0.30319)

    Microsoft Application Error Reporting (Version: 12.0.6015.5000)

    Microsoft IntelliPoint 8.2 (Version: 8.20.468.0)

    Microsoft Office 2007 Service Pack 3 (SP3)

    Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)

    Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)

    Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)

    Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)

    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)

    Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)

    Microsoft Security Client (Version: 4.0.1526.0)

    Microsoft Security Essentials (Version: 4.0.1526.0)

    Microsoft Silverlight (Version: 4.1.10329.0)

    Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)

    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)

    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)

    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)

    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)

    Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)

    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)

    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)

    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)

    Moffsoft FreeCalc (Version: 1.1)

    Mozilla Firefox 12.0 (x86 en-US) (Version: 12.0)

    Mozilla Maintenance Service (Version: 12.0)

    Mozilla Thunderbird 12.0.1 (x86 en-US) (Version: 12.0.1)

    MSVCRT (Version: 15.4.2862.0708)

    MSVCRT_amd64 (Version: 15.4.2862.0708)

    MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)

    MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)

    Music Now! (Version: 1.0.5.0)

    NETGEAR WNDA3100v2 wireless USB 2.0 adapter (Version: 1.03.000)

    Network64 (Version: 130.0.374.000)

    Network64 (Version: 140.0.221.000)

    Nexon Game Manager

    Nuance PDF Reader (Version: 6.00.0041)

    NVIDIA 3D Vision Driver 301.42 (Version: 301.42)

    NVIDIA Control Panel 301.42 (Version: 301.42)

    NVIDIA Graphics Driver 301.42 (Version: 301.42)

    NVIDIA HD Audio Driver 1.3.16.0 (Version: 1.3.16.0)

    NVIDIA Install Application (Version: 2.1002.75.420)

    NVIDIA Optimus 1.8.15 (Version: 1.8.15)

    NVIDIA PhysX (Version: 9.12.0213)

    NVIDIA PhysX System Software 9.12.0213 (Version: 9.12.0213)

    NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.0142)

    NVIDIA Update 1.8.15 (Version: 1.8.15)

    NVIDIA Update Components (Version: 1.8.15)

    OCR Software by I.R.I.S. 13.0 (Version: 13.0)

    OpenOffice.org 3.4 (Version: 3.4.9590)

    Origin (Version: 8.6.0.357)

    PunkBuster Services (Version: 0.991)

    QuickTime (Version: 7.72.80.56)

    Razer Synapse 2.0 (Version: 1.2.16)

    Realtek High Definition Audio Driver (Version: 6.0.1.6438)

    Scan (Version: 13.0.0.0)

    Shop for HP Supplies (Version: 13.0)

    SmartWebPrinting (Version: 130.0.373.000)

    SolutionCenter (Version: 130.0.373.000)

    SolveigMM AVI Trimmer (Version: 2.0.1204.27)

    SonicMaster (Version: 1.0.0.4)

    Status (Version: 130.0.373.000)

    Steam (Version: 1.0.0.0)

    swMSM (Version: 12.0.0.1)

    Synaptics Pointing Device Driver (Version: 15.3.6.0)

    syncables desktop SE (Version: 5.5.746.11492)

    System Requirements Lab (Version: 4.5.1.0)

    System Requirements Lab CYRI (Version: 4.5.1.0)

    System Requirements Lab for Intel (Version: 4.5.5.0)

    TeamSpeak 3 Client (Version: 3.0.7)

    TeamViewer 7 (Version: 7.0.12979)

    Tipard MKV Video Converter 6.1.12

    Toolbox (Version: 130.0.648.000)

    TrayApp (Version: 130.0.376.000)

    Update for 2007 Microsoft Office System (KB967642)

    Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)

    Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)

    Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)

    Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)

    Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)

    Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)

    Update for Microsoft Office 2007 Help for Common Features (KB963673)

    Update for Microsoft Office Access 2007 Help (KB963663)

    Update for Microsoft Office Excel 2007 Help (KB963678)

    Update for Microsoft Office Infopath 2007 Help (KB963662)

    Update for Microsoft Office OneNote 2007 Help (KB963670)

    Update for Microsoft Office Outlook 2007 Help (KB963677)

    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687267) 32-Bit Edition

    Update for Microsoft Office Powerpoint 2007 Help (KB963669)

    Update for Microsoft Office Publisher 2007 Help (KB963667)

    Update for Microsoft Office Script Editor Help (KB963671)

    Update for Microsoft Office Word 2007 Help (KB963665)

    Virtual Magnifying Glass v3.5

    Visual Studio 2008 x64 Redistributables (Version: 10.0.0.2)

    VLC media player 2.0.1 (Version: 2.0.1)

    WebReg (Version: 130.0.132.017)

    Windows Live ??? (Version: 15.4.3502.0922)

    Windows Live ???? (Version: 15.4.3502.0922)

    Windows Live Communications Platform (Version: 15.4.3502.0922)

    Windows Live Essentials (Version: 15.4.3502.0922)

    Windows Live Essentials (Version: 15.4.3508.1109)

    Windows Live Family Safety (Version: 15.4.3502.0922)

    Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)

    Windows Live Installer (Version: 15.4.3502.0922)

    Windows Live Language Selector (Version: 15.4.3508.1109)

    Windows Live Mail (Version: 15.4.3502.0922)

    Windows Live Mesh (Version: 15.4.3502.0922)

    Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)

    Windows Live Messenger (Version: 15.4.3502.0922)

    Windows Live MIME IFilter (Version: 15.4.3502.0922)

    Windows Live Movie Maker (Version: 15.4.3502.0922)

    Windows Live Photo Common (Version: 15.4.3502.0922)

    Windows Live Photo Gallery (Version: 15.4.3502.0922)

    Windows Live PIMT Platform (Version: 15.4.3508.1109)

    Windows Live Remote Client (Version: 15.4.5722.2)

    Windows Live Remote Client Resources (Version: 15.4.5722.2)

    Windows Live Remote Service (Version: 15.4.5722.2)

    Windows Live Remote Service Resources (Version: 15.4.5722.2)

    Windows Live SOXE (Version: 15.4.3502.0922)

    Windows Live SOXE Definitions (Version: 15.4.3502.0922)

    Windows Live UX Platform (Version: 15.4.3502.0922)

    Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)

    Windows Live Writer (Version: 15.4.3502.0922)

    Windows Live Writer Resources (Version: 15.4.3502.0922)

    WinFlash (Version: 2.31.1)

    WinRAR 4.11 (64-bit) (Version: 4.11.0)

    WinSCP 4.3.7 (Version: 4.3.7)

    XChat 2 (remove only)

    Xilisoft Video Converter Ultimate 6 (Version: 6.0.3.0416)

    ========================= Devices: ================================

    Name: Officejet 4500 G510n-z

    Description: Officejet 4500 G510n-z

    Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}

    Manufacturer: HP

    Service:

    Problem: : This device is disabled. (Code 22)

    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    ========================= Memory info: ===================================

    Percentage of memory in use: 36%

    Total physical RAM: 8102.06 MB

    Available physical RAM: 5143.06 MB

    Total Pagefile: 16202.31 MB

    Available Pagefile: 13043.04 MB

    Total Virtual: 4095.88 MB

    Available Virtual: 3975.09 MB

    ========================= Partitions: =====================================

    1 Drive c: (OS) (Fixed) (Total:440.76 GB) (Free:356.82 GB) NTFS

    2 Drive e: (DATA) (Fixed) (Total:465.75 GB) (Free:405.29 GB) NTFS

    ========================= Users: ========================================

    User accounts for \\JAGS-AWESOME-PC

    Administrator Guest Ronald Glickman

    UpdatusUser

    ========================= Minidump Files ==================================

    No minidump file found

    **** End of log ****

    Farbar Service Scanner Version: 22-06-2012

    Ran by Ronald Glickman (administrator) on 22-06-2012 at 11:31:16

    Running from "E:\RSG Downloads"

    Microsoft Windows 7 Home Premium Service Pack 1 (X64)

    Boot Mode: Normal

    ****************************************************************

    Internet Services:

    ============

    Connection Status:

    ==============

    Localhost is accessible.

    LAN connected.

    Google IP is accessible.

    Google.com is accessible.

    Yahoo IP is accessible.

    Yahoo.com is accessible.

    Windows Firewall:

    =============

    Firewall Disabled Policy:

    ==================

    System Restore:

    ============

    System Restore Disabled Policy:

    ========================

    Action Center:

    ============

    Windows Update:

    ============

    Windows Autoupdate Disabled Policy:

    ============================

    File Check:

    ========

    C:\Windows\System32\nsisvc.dll => MD5 is legit

    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit

    C:\Windows\System32\dhcpcore.dll => MD5 is legit

    C:\Windows\System32\drivers\afd.sys => MD5 is legit

    C:\Windows\System32\drivers\tdx.sys => MD5 is legit

    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit

    C:\Windows\System32\dnsrslvr.dll => MD5 is legit

    C:\Windows\System32\mpssvc.dll => MD5 is legit

    C:\Windows\System32\bfe.dll => MD5 is legit

    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit

    C:\Windows\System32\SDRSVC.dll => MD5 is legit

    C:\Windows\System32\vssvc.exe => MD5 is legit

    C:\Windows\System32\wscsvc.dll => MD5 is legit

    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit

    C:\Windows\System32\wuaueng.dll => MD5 is legit

    C:\Windows\System32\qmgr.dll => MD5 is legit

    C:\Windows\System32\es.dll => MD5 is legit

    C:\Windows\System32\cryptsvc.dll => MD5 is legit

    C:\Windows\System32\svchost.exe => MD5 is legit

    C:\Windows\System32\rpcss.dll => MD5 is legit

    **** End of log ****

  9. Kaspersky AVP log was nothing there. I clicked on the Detected Threats buttons as you instructed and the Save button was greyed out, not allowing me to save anything because it didn't detect anything.

    aswMBR.log is as follows.....

    aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software

    Run date: 2012-06-22 11:20:55

    -----------------------------

    11:20:55.560 OS Version: Windows x64 6.1.7601 Service Pack 1

    11:20:55.560 Number of processors: 8 586 0x2A07

    11:20:55.560 ComputerName: JAGS-AWESOME-PC UserName: Ronald Glickman

    11:20:59.726 Initialize success

    11:21:35.631 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1

    11:21:35.631 Disk 0 Vendor: ST950042 0002 Size: 476940MB BusType: 3

    11:21:35.631 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2

    11:21:35.631 Disk 1 Vendor: ST950042 0002 Size: 476940MB BusType: 3

    11:21:35.647 Disk 0 MBR read successfully

    11:21:35.662 Disk 0 MBR scan

    11:21:35.662 Disk 0 Windows 7 default MBR code

    11:21:35.662 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048

    11:21:35.678 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 451337 MB offset 52430848

    11:21:35.693 Disk 0 scanning C:\Windows\system32\drivers

    11:21:41.731 Service scanning

    11:21:54.179 Modules scanning

    11:21:54.179 Disk 0 trace - called modules:

    11:21:54.273 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll

    11:21:54.273 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008126790]

    11:21:54.601 3 CLASSPNP.SYS[fffff88001dbb43f] -> nt!IofCallDriver -> [0xfffffa8007bc9550]

    11:21:54.601 5 ACPI.sys[fffff88000f427a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007bd0050]

    11:21:54.601 Scan finished successfully

    11:22:07.845 Disk 0 MBR has been saved successfully to "C:\Users\Ronald Glickman\Desktop\MBR.dat"

    11:22:07.892 The log file has been saved successfully to "C:\Users\Ronald Glickman\Desktop\aswMBR.txt"

  10. I ran the otl fix and the combofix last night and they were posted already. I just got that same ip block message for the same ip this morning

    2012/06/22 06:39:31 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE Starting protection

    2012/06/22 06:39:33 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE Protection started successfully

    2012/06/22 06:39:36 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE Starting IP protection

    2012/06/22 06:39:37 -0400 JAGS-AWESOME-PC Ronald Glickman MESSAGE IP Protection started successfully

    2012/06/22 06:40:24 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49332, Process: chrome.exe)

    2012/06/22 06:41:13 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49339, Process: chrome.exe)

    2012/06/22 06:47:41 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49447, Process: chrome.exe)

    2012/06/22 06:48:29 -0400 JAGS-AWESOME-PC Ronald Glickman IP-BLOCK 74.208.30.205 (Type: outgoing, Port: 49458, Process: chrome.exe)

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.