herbchristopher Posted July 14, 2012 ID:570497 Share Posted July 14, 2012 My wife downloaded some malware. I had Microsoft Security Essentials running in the background, but it did not catch it then or after scanning my computer. The malware typically would reroute a websearch at Google to a website called Newsfudge. After restarting my computer I cannot run in normal mode, it's too slow, and actually freezes up after 30 seconds after windows is all booted up. I can run safe mode just fine. I installed Malwarebytes and it found three files that needed to be removed. My computer still freezes after boot up. I read that you no longer use HiJackThis. So, I ran the MalwareBytes tool and these are my results:DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORKInternet Explorer: 9.0.8112.16421Run by Chris at 21:28:48 on 2012-07-13Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4010.3185 [GMT -5:00].AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}.============== Running Processes ===============.C:\windows\system32\wininit.exeC:\windows\system32\lsm.exeC:\windows\system32\svchost.exe -k DcomLaunchC:\windows\system32\svchost.exe -k RPCSSC:\Program Files\Microsoft Security Client\MsMpEng.exeC:\windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\windows\system32\svchost.exe -k netsvcsC:\windows\system32\svchost.exe -k LocalSystemNetworkRestrictedC:\windows\system32\svchost.exe -k LocalServiceC:\windows\system32\svchost.exe -k NetworkServiceC:\windows\system32\svchost.exe -k LocalServiceNoNetworkC:\windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\windows\Explorer.EXEC:\windows\system32\ctfmon.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\windows\system32\wbem\wmiprvse.exeC:\windows\system32\NOTEPAD.EXEC:\windows\SysWOW64\cmd.exeC:\windows\system32\conhost.exeC:\windows\SysWOW64\cscript.exeC:\windows\system32\wbem\wmiprvse.exe.============== Pseudo HJT Report ===============.uStart Page = https://www.google.com/uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENNmStart Page = hxxp://lenovo.msn.comuInternet Settings,ProxyOverride = *.localmWinlogon: Userinit=userinit.exe,BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllBHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO: EgisPBIE Class: {7b51ccbe-4af9-44a6-bdab-d7f7e4c4e6f9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dlluRun: [WLSync] "C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe" /backgrounduRun: [Facebook Update] "C:\Users\Chris\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserveruRun: [dysiap] rundll32.exe "C:\Users\Chris\AppData\Roaming\dysiap.dll",FileCreateuRun: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exemRun: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraymPolicies-explorer: NoActiveDesktop = 1 (0x1)mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)IE: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTMLIE: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTMLIE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.htmlIE: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll /100IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLLIE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllDPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} - hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.3.0.cabTCP: DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{8B659D86-C6E6-4607-AC33-8014EC4846CD} : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E} : DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\24F696E676F60284F6473707F647 : DhcpNameServer = 10.1.0.1 66.103.64.5 66.103.80.4TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\3747275676963786F6573747F6E6765756374727F6F6D6 : DhcpNameServer = 4.2.2.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\442716B65686F6D656 : DhcpNameServer = 192.168.1.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\841435D2743747 : DhcpNameServer = 4.2.2.2 4.2.2.1 10.28.54.45 10.28.55.20TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\84562726023557464656E6C496E6B6 : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\D45646963616C602D496C6560275966696 : DhcpNameServer = 97.64.183.164 97.64.209.37Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLLSEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllLSA: Notification Packages = scecli EgisPwdFilter EgisDSPwdFilter EgisPLPwdFilterBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllBHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO-X64: EgisPBIE Class: {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO-X64: EgisPBIE - No FileBHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO-X64: ZeonIEEventHelper Class: {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB-X64: Nuance PDF: {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllmRun-x64: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraySEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll.============= SERVICES / DRIVERS ===============.R0 fbfmon;fbfmon;C:\windows\system32\drivers\fbfmon.sys --> C:\windows\system32\drivers\fbfmon.sys [?]R0 LHDmgr;LHDmgr;C:\windows\system32\DRIVERS\LhdX64.sys --> C:\windows\system32\DRIVERS\LhdX64.sys [?]R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]R3 ACPIVPC;Lenovo Virtual Power Controller Driver;C:\windows\system32\DRIVERS\AcpiVpc.sys --> C:\windows\system32\DRIVERS\AcpiVpc.sys [?]R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --> C:\windows\system32\DRIVERS\HECIx64.sys [?]R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUVStor.sys --> C:\windows\system32\Drivers\RtsUVStor.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]S0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys --> C:\windows\system32\DRIVERS\MpFilter.sys [?]S1 BPntDrv;BPntDrv;C:\windows\system32\drivers\BPntDrv.sys --> C:\windows\system32\drivers\BPntDrv.sys [?]S1 EgisTecFF;EgisTecFF;C:\windows\system32\DRIVERS\EgisTecFF.sys --> C:\windows\system32\DRIVERS\EgisTecFF.sys [?]S1 mwlPSDFilter;mwlPSDFilter;C:\windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\windows\system32\DRIVERS\mwlPSDFilter.sys [?]S1 mwlPSDNServ;mwlPSDNServ;C:\windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\windows\system32\DRIVERS\mwlPSDNServ.sys [?]S1 mwlPSDVDisk;mwlPSDVDisk;C:\windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\windows\system32\DRIVERS\mwlPSDVDisk.sys [?]S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 EgisTec Service Help;EgisTec Service Help;C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [2010-10-22 327024]S2 EgisTec Service;EgisTec Service;C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe [2010-12-13 703856]S2 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-12-13 650096]S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);C:\windows\system32\Drivers\FPSensor.sys --> C:\windows\system32\Drivers\FPSensor.sys [?]S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-12 655944]S2 PDFProFiltSrv;PDFProFiltSrv;C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-7-27 134944]S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-7-13 1153368]S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]S2 SSICloudService;SSICloudService;C:\Program Files (x86)\Software Secure, Inc\SSICloudService\SSICloudService.exe [2012-2-3 220160]S2 SSIRuntimeService;SSIRuntimeService;C:\Program Files (x86)\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe [2012-2-3 33792]S2 SsiSrpDiagnosticsService;SSI SRP Diagnostics Service;C:\Program Files (x86)\Software Secure, Inc\Software Secure, Inc\SsiDiagnosticsService.exe [2010-12-6 15360]S2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-4 2656280]S2 WebUpdate4;Web Update Wizard Service V4;C:\Windows\SysWOW64\WebUpdateSvc4.exe [2007-5-18 229856]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-6 250056]S3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\system32\DRIVERS\clwvd.sys --> C:\windows\system32\DRIVERS\clwvd.sys [?]S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248]S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-3-20 14216]S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-3-20 8456]S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]S3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --> C:\windows\system32\DRIVERS\IntcDAud.sys [?]S3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys --> C:\windows\system32\drivers\mbam.sys [?]S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys --> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]S3 vm331avs;Digital Camera 1;C:\windows\system32\Drivers\vm331avs.sys --> C:\windows\system32\Drivers\vm331avs.sys [?]S3 vmuvcflt;Vimicro USB Camera Filter;C:\windows\system32\Drivers\vmuvcflt.sys --> C:\windows\system32\Drivers\vmuvcflt.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]S3 wsvd;wsvd;C:\windows\system32\DRIVERS\wsvd.sys --> C:\windows\system32\DRIVERS\wsvd.sys [?]S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184].=============== Created Last 30 ================.2012-07-14 02:14:46 -------- dc----w- C:\Users\Chris\AppData\Local\{DB61C036-6D9B-46E8-824F-96E682D2CC1E}2012-07-14 02:14:31 -------- dc----w- C:\Users\Chris\AppData\Local\{FCF97C6A-F02C-40F1-BEA5-A8A67F045541}2012-07-14 01:40:49 -------- dc----w- C:\ProgramData\Spybot - Search & Destroy2012-07-14 01:40:49 -------- dc----w- C:\Program Files (x86)\Spybot - Search & Destroy2012-07-13 03:15:34 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C0ACB4D6-48CA-46C1-8164-EB1614896BE9}\offreg.dll2012-07-13 02:07:37 -------- dc----w- C:\Users\Chris\AppData\Roaming\Malwarebytes2012-07-13 02:07:15 -------- dc----w- C:\ProgramData\Malwarebytes2012-07-13 02:07:11 24904 -c--a-w- C:\windows\System32\drivers\mbam.sys2012-07-13 02:07:10 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware2012-07-13 01:30:17 -------- dc----w- C:\Users\Chris\AppData\Local\{466B1C3D-CC8A-11E1-8270-B8AC6F996F26}2012-07-13 01:30:13 377856 -c--a-w- C:\Users\Chris\AppData\Roaming\dysiap.dll2012-07-12 23:54:28 -------- dc----w- C:\Users\Chris\AppData\Local\{570CB5D4-EBD4-4390-9C37-04D449D74FDF}2012-07-12 14:02:19 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C0ACB4D6-48CA-46C1-8164-EB1614896BE9}\mpengine.dll2012-07-12 11:54:00 -------- dc----w- C:\Users\Chris\AppData\Local\{B3727647-22C6-4954-9E59-EEDCAC8EF799}2012-07-12 11:53:47 -------- dc----w- C:\Users\Chris\AppData\Local\{25BAF4D9-1712-4155-A308-8F0DDCB9C77B}2012-07-12 03:11:14 3148800 ----a-w- C:\windows\System32\win32k.sys2012-07-11 20:36:37 2004480 ----a-w- C:\windows\System32\msxml6.dll2012-07-11 20:30:52 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll2012-07-11 20:30:52 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll2012-07-11 20:30:52 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll2012-07-11 20:30:52 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll2012-07-11 20:30:51 805376 ----a-w- C:\windows\SysWow64\cdosys.dll2012-07-11 20:30:51 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll2012-07-11 20:30:51 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll2012-07-11 20:30:51 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll2012-07-11 20:30:51 1133568 ----a-w- C:\windows\System32\cdosys.dll2012-07-11 18:12:46 -------- dc----w- C:\Users\Chris\AppData\Local\{E8512AEA-F566-46E6-AD1F-C0A81EC2E7BC}2012-07-11 13:37:57 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll2012-07-11 04:20:21 -------- dc----w- C:\Users\Chris\AppData\Local\{A1020FD3-5904-4424-875E-6A4ED46E726F}2012-07-10 16:19:57 -------- dc----w- C:\Users\Chris\AppData\Local\{26C3EF90-1AA3-4CBE-9AEA-26F45F1ABC6B}2012-07-10 16:19:46 -------- dc----w- C:\Users\Chris\AppData\Local\{090FE3BC-89B4-430D-9116-8591A1283E06}2012-07-10 04:19:21 -------- dc----w- C:\Users\Chris\AppData\Local\{2E2FD7E8-6C3D-4F64-A6C6-EB6104485E89}2012-07-09 14:37:21 -------- dc----w- C:\Users\Chris\AppData\Local\{D47F37C4-A3F6-4F5F-A79D-CB5C83474DBF}2012-07-09 14:37:07 -------- dc----w- C:\Users\Chris\AppData\Local\{43A7FC58-A32E-43FF-9A92-048841C5AC43}2012-07-08 16:05:12 -------- dc----w- C:\Users\Chris\AppData\Local\{B7067734-4A9F-4B6C-BE5B-3F7B14C76F50}2012-07-08 16:04:58 -------- dc----w- C:\Users\Chris\AppData\Local\{27DCC5D2-B198-4A21-9450-BA6BB053A31D}2012-07-07 16:21:52 -------- dc----w- C:\Users\Chris\AppData\Local\{C06882D4-6EBE-4219-AF72-ECE408FA5704}2012-07-07 03:40:43 -------- dc----w- C:\Users\Chris\AppData\Local\{D9E3B73D-FE12-4D80-B74A-BBC8BFE2F453}2012-07-06 15:40:18 -------- dc----w- C:\Users\Chris\AppData\Local\{A358D6C1-CE24-43A2-B5D3-91D815140E1B}2012-07-06 03:39:54 -------- dc----w- C:\Users\Chris\AppData\Local\{1A336D29-03BF-407A-9A1C-4B695EC361EB}2012-07-05 15:39:30 -------- dc----w- C:\Users\Chris\AppData\Local\{CFA67504-011F-42C8-9AF4-75920C0B50EE}2012-07-05 03:39:06 -------- dc----w- C:\Users\Chris\AppData\Local\{84F06CCF-6A0A-4357-867A-0E3B3A59640D}2012-07-04 12:32:12 -------- dc----w- C:\Users\Chris\AppData\Local\{7C13DB0D-274C-4DFD-89B4-4A3C5E6FEADA}2012-07-04 12:32:00 -------- dc----w- C:\Users\Chris\AppData\Local\{2E027742-59F9-4765-8C5C-E70938F658BA}2012-07-04 00:31:34 -------- dc----w- C:\Users\Chris\AppData\Local\{F720AD1D-F796-4B97-8EB4-1347D2334F1A}2012-07-03 21:18:16 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{90504DF0-2127-42AD-A2F9-511AA75917AD}\gapaengine.dll2012-07-03 12:31:10 -------- dc----w- C:\Users\Chris\AppData\Local\{57DE7C23-7513-4599-9F06-4D6A430C871E}2012-07-02 18:06:26 -------- dc----w- C:\Users\Chris\AppData\Local\{9B8FFC94-50B8-4D57-9983-5A4338524D58}2012-07-02 03:08:35 -------- dc----w- C:\Users\Chris\AppData\Local\{4AA1B356-15DE-4C70-83B3-92266EF748DF}2012-06-30 22:58:50 -------- dc----w- C:\Users\Chris\AppData\Local\{FB7EA9AA-F34C-43AE-8EB4-597B795744F1}2012-06-27 21:47:00 -------- dc----w- C:\Users\Chris\AppData\Local\{C7EF70AD-A7C8-48B1-AEE3-825977808AF6}2012-06-27 03:57:53 -------- dc----w- C:\Users\Chris\AppData\Local\{859821BC-1CAC-4B98-9311-5735EEA295F5}2012-06-26 12:43:47 -------- dc----w- C:\Users\Chris\AppData\Local\{8C0CE7F1-B765-440D-B3F3-248033817097}2012-06-25 12:59:25 -------- dc----w- C:\Users\Chris\AppData\Local\{11D3FD59-D01F-43D8-8371-A14856F56A8B}2012-06-25 00:28:43 -------- dc----w- C:\Users\Chris\AppData\Local\{80C479DD-F1D1-4B3A-BC21-A945646147D5}2012-06-25 00:28:30 -------- dc----w- C:\Users\Chris\AppData\Local\{030C6BE1-E8E2-41C4-9A38-06247B64F634}2012-06-19 16:34:05 2622464 ----a-w- C:\windows\System32\wucltux.dll2012-06-19 16:33:46 99840 ----a-w- C:\windows\System32\wudriver.dll2012-06-19 16:33:14 36864 ----a-w- C:\windows\System32\wuapp.exe2012-06-19 16:33:14 186752 ----a-w- C:\windows\System32\wuwebv.dll2012-06-19 14:47:36 -------- dc----w- C:\Users\Chris\AppData\Local\{0F4CB182-767B-46C2-A423-DA8142882239}2012-06-19 14:47:24 -------- dc----w- C:\Users\Chris\AppData\Local\{E2B13B73-A41A-4BBC-909E-A1DD28C5AE9B}2012-06-19 02:46:57 -------- dc----w- C:\Users\Chris\AppData\Local\{EBC7F20E-2DF2-46CA-8A29-2B5FC291C510}2012-06-19 02:46:45 -------- dc----w- C:\Users\Chris\AppData\Local\{0A1176DE-E556-4456-87B9-01A29826AF88}2012-06-17 17:15:50 -------- dc----w- C:\Users\Chris\AppData\Local\{7A6768B1-00E1-49C5-857E-3FC797A67AD6}2012-06-17 17:15:35 -------- dc----w- C:\Users\Chris\AppData\Local\{0E11B8F3-03FE-412F-B524-2D5EF888E5D8}2012-06-15 20:50:18 -------- dc----w- C:\Users\Chris\AppData\Local\{735E2C68-8953-4990-8D0A-509DA0B78BD3}2012-06-15 20:50:07 -------- dc----w- C:\Users\Chris\AppData\Local\{8673A41E-CB9E-44A5-9493-75A495C21F39}2012-06-15 02:59:00 514560 ----a-w- C:\windows\SysWow64\qdvd.dll2012-06-15 02:59:00 366592 ----a-w- C:\windows\System32\qdvd.dll2012-06-15 02:28:58 -------- dc----w- C:\Users\Chris\AppData\Local\{DAA8BFC6-929F-4C55-8BC8-B03E39B25DA2}2012-06-14 14:28:33 -------- dc----w- C:\Users\Chris\AppData\Local\{59FCD77E-0828-482E-8724-6BC0572C1B11}.==================== Find3M ====================.2012-07-12 11:54:30 426184 -c--a-w- C:\windows\SysWow64\FlashPlayerApp.exe2012-07-12 11:54:29 70344 -c--a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-07-12 03:10:15 2048 ----a-w- C:\windows\SysWow64\msxml3r.dll2012-07-12 03:10:15 2048 ----a-w- C:\windows\System32\msxml3r.dll2012-07-12 03:10:15 1881600 ----a-w- C:\windows\System32\msxml3.dll2012-07-12 03:10:15 1390080 ----a-w- C:\windows\SysWow64\msxml6.dll2012-07-12 03:10:15 1236992 ----a-w- C:\windows\SysWow64\msxml3.dll2012-07-12 03:09:08 340992 ----a-w- C:\windows\System32\schannel.dll2012-07-12 03:09:08 307200 ----a-w- C:\windows\System32\ncrypt.dll2012-07-12 03:09:08 225280 ----a-w- C:\windows\SysWow64\schannel.dll2012-07-12 03:09:08 219136 ----a-w- C:\windows\SysWow64\ncrypt.dll2012-07-12 03:09:07 96768 ----a-w- C:\windows\SysWow64\sspicli.dll2012-07-12 03:09:07 95600 ----a-w- C:\windows\System32\drivers\ksecdd.sys2012-07-12 03:09:07 458704 ----a-w- C:\windows\System32\drivers\cng.sys2012-07-12 03:09:07 22016 ----a-w- C:\windows\SysWow64\secur32.dll2012-07-12 03:09:07 151920 ----a-w- C:\windows\System32\drivers\ksecpkg.sys2012-07-12 03:05:09 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb2012-07-12 03:05:09 2382848 ----a-w- C:\windows\System32\mshtml.tlb2012-07-12 03:05:09 2311680 ----a-w- C:\windows\System32\jscript9.dll2012-07-12 03:05:09 1800192 ----a-w- C:\windows\SysWow64\jscript9.dll2012-07-12 03:05:09 173056 ----a-w- C:\windows\System32\ieUnatt.exe2012-07-12 03:05:09 1494528 ----a-w- C:\windows\System32\inetcpl.cpl2012-07-12 03:05:09 142848 ----a-w- C:\windows\SysWow64\ieUnatt.exe2012-07-12 03:05:09 1427968 ----a-w- C:\windows\SysWow64\inetcpl.cpl2012-07-12 03:05:09 1392128 ----a-w- C:\windows\System32\wininet.dll2012-07-12 03:05:08 1129472 ----a-w- C:\windows\SysWow64\wininet.dll2012-06-19 04:12:46 209920 ----a-w- C:\windows\System32\profsvc.dll2012-06-17 17:23:32 9216 ----a-w- C:\windows\System32\rdrmemptylst.exe2012-06-17 17:23:32 77312 ----a-w- C:\windows\System32\rdpwsx.dll2012-06-17 17:23:32 149504 ----a-w- C:\windows\System32\rdpcorekmts.dll2012-06-17 17:18:52 5559664 ----a-w- C:\windows\System32\ntoskrnl.exe2012-06-17 17:18:52 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe2012-06-17 17:18:52 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe2012-06-17 17:18:21 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys2012-06-17 17:18:10 3216384 ----a-w- C:\windows\System32\msi.dll2012-06-17 17:18:10 2342400 ----a-w- C:\windows\SysWow64\msi.dll2012-06-17 17:17:57 184320 ----a-w- C:\windows\System32\cryptsvc.dll2012-06-17 17:17:57 1462272 ----a-w- C:\windows\System32\crypt32.dll2012-06-17 17:17:57 140288 ----a-w- C:\windows\SysWow64\cryptsvc.dll2012-06-17 17:17:57 1158656 ----a-w- C:\windows\SysWow64\crypt32.dll2012-06-17 17:17:57 103936 ----a-w- C:\windows\SysWow64\cryptnet.dll2012-06-17 17:17:56 140288 ----a-w- C:\windows\System32\cryptnet.dll2012-05-18 23:16:19 1544704 ----a-w- C:\windows\System32\DWrite.dll2012-05-18 23:16:19 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll2012-05-18 23:05:16 75120 ----a-w- C:\windows\System32\drivers\partmgr.sys2012-05-18 23:02:39 1918320 ----a-w- C:\windows\System32\drivers\tcpip.sys2012-05-07 14:41:34 50546 -c--a-w- C:\windows\SysWow64\wuwuninst.exe2009-08-14 19:31:00 1370112 -c--a-w- C:\Program Files (x86)\bsgui.dll2009-08-14 19:26:50 3101184 -c--a-w- C:\Program Files (x86)\bsapi.dll.============= FINISH: 21:30:06.89 ===============What are your suggestions? Link to post Share on other sites More sharing options...
Maniac Posted July 14, 2012 ID:570591 Share Posted July 14, 2012 Hello herbchristopher and ! My name is Maniac and I will be glad to help you solve your malware problem.Please note:If you are a paying customer, you have the privilege to contact the help desk at Consumer Support or here (http://helpdesk.malwarebytes.org/home). If you choose this option to get help, please let me know.I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.Make sure you read all of the instructions and fixes thoroughly before continuing with them.Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.To post the content of Attach.txt . Link to post Share on other sites More sharing options...
herbchristopher Posted July 15, 2012 Author ID:570913 Share Posted July 15, 2012 I appreciate the help. Here's my DDS log:.DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORKInternet Explorer: 9.0.8112.16421Run by Chris at 21:28:48 on 2012-07-13Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4010.3185 [GMT -5:00].AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}.============== Running Processes ===============.C:\windows\system32\wininit.exeC:\windows\system32\lsm.exeC:\windows\system32\svchost.exe -k DcomLaunchC:\windows\system32\svchost.exe -k RPCSSC:\Program Files\Microsoft Security Client\MsMpEng.exeC:\windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\windows\system32\svchost.exe -k netsvcsC:\windows\system32\svchost.exe -k LocalSystemNetworkRestrictedC:\windows\system32\svchost.exe -k LocalServiceC:\windows\system32\svchost.exe -k NetworkServiceC:\windows\system32\svchost.exe -k LocalServiceNoNetworkC:\windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\windows\Explorer.EXEC:\windows\system32\ctfmon.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\windows\system32\wbem\wmiprvse.exeC:\windows\system32\NOTEPAD.EXEC:\windows\SysWOW64\cmd.exeC:\windows\system32\conhost.exeC:\windows\SysWOW64\cscript.exeC:\windows\system32\wbem\wmiprvse.exe.============== Pseudo HJT Report ===============.uStart Page = https://www.google.com/uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENNmStart Page = hxxp://lenovo.msn.comuInternet Settings,ProxyOverride = *.localmWinlogon: Userinit=userinit.exe,BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllBHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO: EgisPBIE Class: {7b51ccbe-4af9-44a6-bdab-d7f7e4c4e6f9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dlluRun: [WLSync] "C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe" /backgrounduRun: [Facebook Update] "C:\Users\Chris\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserveruRun: [dysiap] rundll32.exe "C:\Users\Chris\AppData\Roaming\dysiap.dll",FileCreateuRun: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exemRun: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraymPolicies-explorer: NoActiveDesktop = 1 (0x1)mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)IE: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTMLIE: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTMLIE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.htmlIE: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll /100IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLLIE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllDPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} - hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.3.0.cabTCP: DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{8B659D86-C6E6-4607-AC33-8014EC4846CD} : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E} : DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\24F696E676F60284F6473707F647 : DhcpNameServer = 10.1.0.1 66.103.64.5 66.103.80.4TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\3747275676963786F6573747F6E6765756374727F6F6D6 : DhcpNameServer = 4.2.2.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\442716B65686F6D656 : DhcpNameServer = 192.168.1.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\841435D2743747 : DhcpNameServer = 4.2.2.2 4.2.2.1 10.28.54.45 10.28.55.20TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\84562726023557464656E6C496E6B6 : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\D45646963616C602D496C6560275966696 : DhcpNameServer = 97.64.183.164 97.64.209.37Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLLSEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllLSA: Notification Packages = scecli EgisPwdFilter EgisDSPwdFilter EgisPLPwdFilterBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllBHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO-X64: EgisPBIE Class: {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO-X64: EgisPBIE - No FileBHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO-X64: ZeonIEEventHelper Class: {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB-X64: Nuance PDF: {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllmRun-x64: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraySEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll.============= SERVICES / DRIVERS ===============.R0 fbfmon;fbfmon;C:\windows\system32\drivers\fbfmon.sys --> C:\windows\system32\drivers\fbfmon.sys [?]R0 LHDmgr;LHDmgr;C:\windows\system32\DRIVERS\LhdX64.sys --> C:\windows\system32\DRIVERS\LhdX64.sys [?]R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]R3 ACPIVPC;Lenovo Virtual Power Controller Driver;C:\windows\system32\DRIVERS\AcpiVpc.sys --> C:\windows\system32\DRIVERS\AcpiVpc.sys [?]R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --> C:\windows\system32\DRIVERS\HECIx64.sys [?]R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUVStor.sys --> C:\windows\system32\Drivers\RtsUVStor.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]S0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys --> C:\windows\system32\DRIVERS\MpFilter.sys [?]S1 BPntDrv;BPntDrv;C:\windows\system32\drivers\BPntDrv.sys --> C:\windows\system32\drivers\BPntDrv.sys [?]S1 EgisTecFF;EgisTecFF;C:\windows\system32\DRIVERS\EgisTecFF.sys --> C:\windows\system32\DRIVERS\EgisTecFF.sys [?]S1 mwlPSDFilter;mwlPSDFilter;C:\windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\windows\system32\DRIVERS\mwlPSDFilter.sys [?]S1 mwlPSDNServ;mwlPSDNServ;C:\windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\windows\system32\DRIVERS\mwlPSDNServ.sys [?]S1 mwlPSDVDisk;mwlPSDVDisk;C:\windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\windows\system32\DRIVERS\mwlPSDVDisk.sys [?]S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 EgisTec Service Help;EgisTec Service Help;C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [2010-10-22 327024]S2 EgisTec Service;EgisTec Service;C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe [2010-12-13 703856]S2 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-12-13 650096]S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);C:\windows\system32\Drivers\FPSensor.sys --> C:\windows\system32\Drivers\FPSensor.sys [?]S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-12 655944]S2 PDFProFiltSrv;PDFProFiltSrv;C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-7-27 134944]S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-7-13 1153368]S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]S2 SSICloudService;SSICloudService;C:\Program Files (x86)\Software Secure, Inc\SSICloudService\SSICloudService.exe [2012-2-3 220160]S2 SSIRuntimeService;SSIRuntimeService;C:\Program Files (x86)\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe [2012-2-3 33792]S2 SsiSrpDiagnosticsService;SSI SRP Diagnostics Service;C:\Program Files (x86)\Software Secure, Inc\Software Secure, Inc\SsiDiagnosticsService.exe [2010-12-6 15360]S2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-4 2656280]S2 WebUpdate4;Web Update Wizard Service V4;C:\Windows\SysWOW64\WebUpdateSvc4.exe [2007-5-18 229856]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-6 250056]S3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\system32\DRIVERS\clwvd.sys --> C:\windows\system32\DRIVERS\clwvd.sys [?]S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248]S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-3-20 14216]S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-3-20 8456]S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]S3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --> C:\windows\system32\DRIVERS\IntcDAud.sys [?]S3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys --> C:\windows\system32\drivers\mbam.sys [?]S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys --> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]S3 vm331avs;Digital Camera 1;C:\windows\system32\Drivers\vm331avs.sys --> C:\windows\system32\Drivers\vm331avs.sys [?]S3 vmuvcflt;Vimicro USB Camera Filter;C:\windows\system32\Drivers\vmuvcflt.sys --> C:\windows\system32\Drivers\vmuvcflt.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]S3 wsvd;wsvd;C:\windows\system32\DRIVERS\wsvd.sys --> C:\windows\system32\DRIVERS\wsvd.sys [?]S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184].=============== Created Last 30 ================.2012-07-14 02:14:46 -------- dc----w- C:\Users\Chris\AppData\Local\{DB61C036-6D9B-46E8-824F-96E682D2CC1E}2012-07-14 02:14:31 -------- dc----w- C:\Users\Chris\AppData\Local\{FCF97C6A-F02C-40F1-BEA5-A8A67F045541}2012-07-14 01:40:49 -------- dc----w- C:\ProgramData\Spybot - Search & Destroy2012-07-14 01:40:49 -------- dc----w- C:\Program Files (x86)\Spybot - Search & Destroy2012-07-13 03:15:34 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C0ACB4D6-48CA-46C1-8164-EB1614896BE9}\offreg.dll2012-07-13 02:07:37 -------- dc----w- C:\Users\Chris\AppData\Roaming\Malwarebytes2012-07-13 02:07:15 -------- dc----w- C:\ProgramData\Malwarebytes2012-07-13 02:07:11 24904 -c--a-w- C:\windows\System32\drivers\mbam.sys2012-07-13 02:07:10 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware2012-07-13 01:30:17 -------- dc----w- C:\Users\Chris\AppData\Local\{466B1C3D-CC8A-11E1-8270-B8AC6F996F26}2012-07-13 01:30:13 377856 -c--a-w- C:\Users\Chris\AppData\Roaming\dysiap.dll2012-07-12 23:54:28 -------- dc----w- C:\Users\Chris\AppData\Local\{570CB5D4-EBD4-4390-9C37-04D449D74FDF}2012-07-12 14:02:19 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C0ACB4D6-48CA-46C1-8164-EB1614896BE9}\mpengine.dll2012-07-12 11:54:00 -------- dc----w- C:\Users\Chris\AppData\Local\{B3727647-22C6-4954-9E59-EEDCAC8EF799}2012-07-12 11:53:47 -------- dc----w- C:\Users\Chris\AppData\Local\{25BAF4D9-1712-4155-A308-8F0DDCB9C77B}2012-07-12 03:11:14 3148800 ----a-w- C:\windows\System32\win32k.sys2012-07-11 20:36:37 2004480 ----a-w- C:\windows\System32\msxml6.dll2012-07-11 20:30:52 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll2012-07-11 20:30:52 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll2012-07-11 20:30:52 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll2012-07-11 20:30:52 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll2012-07-11 20:30:51 805376 ----a-w- C:\windows\SysWow64\cdosys.dll2012-07-11 20:30:51 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll2012-07-11 20:30:51 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll2012-07-11 20:30:51 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll2012-07-11 20:30:51 1133568 ----a-w- C:\windows\System32\cdosys.dll2012-07-11 18:12:46 -------- dc----w- C:\Users\Chris\AppData\Local\{E8512AEA-F566-46E6-AD1F-C0A81EC2E7BC}2012-07-11 13:37:57 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll2012-07-11 04:20:21 -------- dc----w- C:\Users\Chris\AppData\Local\{A1020FD3-5904-4424-875E-6A4ED46E726F}2012-07-10 16:19:57 -------- dc----w- C:\Users\Chris\AppData\Local\{26C3EF90-1AA3-4CBE-9AEA-26F45F1ABC6B}2012-07-10 16:19:46 -------- dc----w- C:\Users\Chris\AppData\Local\{090FE3BC-89B4-430D-9116-8591A1283E06}2012-07-10 04:19:21 -------- dc----w- C:\Users\Chris\AppData\Local\{2E2FD7E8-6C3D-4F64-A6C6-EB6104485E89}2012-07-09 14:37:21 -------- dc----w- C:\Users\Chris\AppData\Local\{D47F37C4-A3F6-4F5F-A79D-CB5C83474DBF}2012-07-09 14:37:07 -------- dc----w- C:\Users\Chris\AppData\Local\{43A7FC58-A32E-43FF-9A92-048841C5AC43}2012-07-08 16:05:12 -------- dc----w- C:\Users\Chris\AppData\Local\{B7067734-4A9F-4B6C-BE5B-3F7B14C76F50}2012-07-08 16:04:58 -------- dc----w- C:\Users\Chris\AppData\Local\{27DCC5D2-B198-4A21-9450-BA6BB053A31D}2012-07-07 16:21:52 -------- dc----w- C:\Users\Chris\AppData\Local\{C06882D4-6EBE-4219-AF72-ECE408FA5704}2012-07-07 03:40:43 -------- dc----w- C:\Users\Chris\AppData\Local\{D9E3B73D-FE12-4D80-B74A-BBC8BFE2F453}2012-07-06 15:40:18 -------- dc----w- C:\Users\Chris\AppData\Local\{A358D6C1-CE24-43A2-B5D3-91D815140E1B}2012-07-06 03:39:54 -------- dc----w- C:\Users\Chris\AppData\Local\{1A336D29-03BF-407A-9A1C-4B695EC361EB}2012-07-05 15:39:30 -------- dc----w- C:\Users\Chris\AppData\Local\{CFA67504-011F-42C8-9AF4-75920C0B50EE}2012-07-05 03:39:06 -------- dc----w- C:\Users\Chris\AppData\Local\{84F06CCF-6A0A-4357-867A-0E3B3A59640D}2012-07-04 12:32:12 -------- dc----w- C:\Users\Chris\AppData\Local\{7C13DB0D-274C-4DFD-89B4-4A3C5E6FEADA}2012-07-04 12:32:00 -------- dc----w- C:\Users\Chris\AppData\Local\{2E027742-59F9-4765-8C5C-E70938F658BA}2012-07-04 00:31:34 -------- dc----w- C:\Users\Chris\AppData\Local\{F720AD1D-F796-4B97-8EB4-1347D2334F1A}2012-07-03 21:18:16 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{90504DF0-2127-42AD-A2F9-511AA75917AD}\gapaengine.dll2012-07-03 12:31:10 -------- dc----w- C:\Users\Chris\AppData\Local\{57DE7C23-7513-4599-9F06-4D6A430C871E}2012-07-02 18:06:26 -------- dc----w- C:\Users\Chris\AppData\Local\{9B8FFC94-50B8-4D57-9983-5A4338524D58}2012-07-02 03:08:35 -------- dc----w- C:\Users\Chris\AppData\Local\{4AA1B356-15DE-4C70-83B3-92266EF748DF}2012-06-30 22:58:50 -------- dc----w- C:\Users\Chris\AppData\Local\{FB7EA9AA-F34C-43AE-8EB4-597B795744F1}2012-06-27 21:47:00 -------- dc----w- C:\Users\Chris\AppData\Local\{C7EF70AD-A7C8-48B1-AEE3-825977808AF6}2012-06-27 03:57:53 -------- dc----w- C:\Users\Chris\AppData\Local\{859821BC-1CAC-4B98-9311-5735EEA295F5}2012-06-26 12:43:47 -------- dc----w- C:\Users\Chris\AppData\Local\{8C0CE7F1-B765-440D-B3F3-248033817097}2012-06-25 12:59:25 -------- dc----w- C:\Users\Chris\AppData\Local\{11D3FD59-D01F-43D8-8371-A14856F56A8B}2012-06-25 00:28:43 -------- dc----w- C:\Users\Chris\AppData\Local\{80C479DD-F1D1-4B3A-BC21-A945646147D5}2012-06-25 00:28:30 -------- dc----w- C:\Users\Chris\AppData\Local\{030C6BE1-E8E2-41C4-9A38-06247B64F634}2012-06-19 16:34:05 2622464 ----a-w- C:\windows\System32\wucltux.dll2012-06-19 16:33:46 99840 ----a-w- C:\windows\System32\wudriver.dll2012-06-19 16:33:14 36864 ----a-w- C:\windows\System32\wuapp.exe2012-06-19 16:33:14 186752 ----a-w- C:\windows\System32\wuwebv.dll2012-06-19 14:47:36 -------- dc----w- C:\Users\Chris\AppData\Local\{0F4CB182-767B-46C2-A423-DA8142882239}2012-06-19 14:47:24 -------- dc----w- C:\Users\Chris\AppData\Local\{E2B13B73-A41A-4BBC-909E-A1DD28C5AE9B}2012-06-19 02:46:57 -------- dc----w- C:\Users\Chris\AppData\Local\{EBC7F20E-2DF2-46CA-8A29-2B5FC291C510}2012-06-19 02:46:45 -------- dc----w- C:\Users\Chris\AppData\Local\{0A1176DE-E556-4456-87B9-01A29826AF88}2012-06-17 17:15:50 -------- dc----w- C:\Users\Chris\AppData\Local\{7A6768B1-00E1-49C5-857E-3FC797A67AD6}2012-06-17 17:15:35 -------- dc----w- C:\Users\Chris\AppData\Local\{0E11B8F3-03FE-412F-B524-2D5EF888E5D8}2012-06-15 20:50:18 -------- dc----w- C:\Users\Chris\AppData\Local\{735E2C68-8953-4990-8D0A-509DA0B78BD3}2012-06-15 20:50:07 -------- dc----w- C:\Users\Chris\AppData\Local\{8673A41E-CB9E-44A5-9493-75A495C21F39}2012-06-15 02:59:00 514560 ----a-w- C:\windows\SysWow64\qdvd.dll2012-06-15 02:59:00 366592 ----a-w- C:\windows\System32\qdvd.dll2012-06-15 02:28:58 -------- dc----w- C:\Users\Chris\AppData\Local\{DAA8BFC6-929F-4C55-8BC8-B03E39B25DA2}2012-06-14 14:28:33 -------- dc----w- C:\Users\Chris\AppData\Local\{59FCD77E-0828-482E-8724-6BC0572C1B11}.==================== Find3M ====================.2012-07-12 11:54:30 426184 -c--a-w- C:\windows\SysWow64\FlashPlayerApp.exe2012-07-12 11:54:29 70344 -c--a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-07-12 03:10:15 2048 ----a-w- C:\windows\SysWow64\msxml3r.dll2012-07-12 03:10:15 2048 ----a-w- C:\windows\System32\msxml3r.dll2012-07-12 03:10:15 1881600 ----a-w- C:\windows\System32\msxml3.dll2012-07-12 03:10:15 1390080 ----a-w- C:\windows\SysWow64\msxml6.dll2012-07-12 03:10:15 1236992 ----a-w- C:\windows\SysWow64\msxml3.dll2012-07-12 03:09:08 340992 ----a-w- C:\windows\System32\schannel.dll2012-07-12 03:09:08 307200 ----a-w- C:\windows\System32\ncrypt.dll2012-07-12 03:09:08 225280 ----a-w- C:\windows\SysWow64\schannel.dll2012-07-12 03:09:08 219136 ----a-w- C:\windows\SysWow64\ncrypt.dll2012-07-12 03:09:07 96768 ----a-w- C:\windows\SysWow64\sspicli.dll2012-07-12 03:09:07 95600 ----a-w- C:\windows\System32\drivers\ksecdd.sys2012-07-12 03:09:07 458704 ----a-w- C:\windows\System32\drivers\cng.sys2012-07-12 03:09:07 22016 ----a-w- C:\windows\SysWow64\secur32.dll2012-07-12 03:09:07 151920 ----a-w- C:\windows\System32\drivers\ksecpkg.sys2012-07-12 03:05:09 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb2012-07-12 03:05:09 2382848 ----a-w- C:\windows\System32\mshtml.tlb2012-07-12 03:05:09 2311680 ----a-w- C:\windows\System32\jscript9.dll2012-07-12 03:05:09 1800192 ----a-w- C:\windows\SysWow64\jscript9.dll2012-07-12 03:05:09 173056 ----a-w- C:\windows\System32\ieUnatt.exe2012-07-12 03:05:09 1494528 ----a-w- C:\windows\System32\inetcpl.cpl2012-07-12 03:05:09 142848 ----a-w- C:\windows\SysWow64\ieUnatt.exe2012-07-12 03:05:09 1427968 ----a-w- C:\windows\SysWow64\inetcpl.cpl2012-07-12 03:05:09 1392128 ----a-w- C:\windows\System32\wininet.dll2012-07-12 03:05:08 1129472 ----a-w- C:\windows\SysWow64\wininet.dll2012-06-19 04:12:46 209920 ----a-w- C:\windows\System32\profsvc.dll2012-06-17 17:23:32 9216 ----a-w- C:\windows\System32\rdrmemptylst.exe2012-06-17 17:23:32 77312 ----a-w- C:\windows\System32\rdpwsx.dll2012-06-17 17:23:32 149504 ----a-w- C:\windows\System32\rdpcorekmts.dll2012-06-17 17:18:52 5559664 ----a-w- C:\windows\System32\ntoskrnl.exe2012-06-17 17:18:52 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe2012-06-17 17:18:52 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe2012-06-17 17:18:21 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys2012-06-17 17:18:10 3216384 ----a-w- C:\windows\System32\msi.dll2012-06-17 17:18:10 2342400 ----a-w- C:\windows\SysWow64\msi.dll2012-06-17 17:17:57 184320 ----a-w- C:\windows\System32\cryptsvc.dll2012-06-17 17:17:57 1462272 ----a-w- C:\windows\System32\crypt32.dll2012-06-17 17:17:57 140288 ----a-w- C:\windows\SysWow64\cryptsvc.dll2012-06-17 17:17:57 1158656 ----a-w- C:\windows\SysWow64\crypt32.dll2012-06-17 17:17:57 103936 ----a-w- C:\windows\SysWow64\cryptnet.dll2012-06-17 17:17:56 140288 ----a-w- C:\windows\System32\cryptnet.dll2012-05-18 23:16:19 1544704 ----a-w- C:\windows\System32\DWrite.dll2012-05-18 23:16:19 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll2012-05-18 23:05:16 75120 ----a-w- C:\windows\System32\drivers\partmgr.sys2012-05-18 23:02:39 1918320 ----a-w- C:\windows\System32\drivers\tcpip.sys2012-05-07 14:41:34 50546 -c--a-w- C:\windows\SysWow64\wuwuninst.exe2009-08-14 19:31:00 1370112 -c--a-w- C:\Program Files (x86)\bsgui.dll2009-08-14 19:26:50 3101184 -c--a-w- C:\Program Files (x86)\bsapi.dll.============= FINISH: 21:30:06.89 ===============And, here's my Attach file:.DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORKInternet Explorer: 9.0.8112.16421Run by Chris at 21:28:48 on 2012-07-13Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4010.3185 [GMT -5:00].AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}.============== Running Processes ===============.C:\windows\system32\wininit.exeC:\windows\system32\lsm.exeC:\windows\system32\svchost.exe -k DcomLaunchC:\windows\system32\svchost.exe -k RPCSSC:\Program Files\Microsoft Security Client\MsMpEng.exeC:\windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\windows\system32\svchost.exe -k netsvcsC:\windows\system32\svchost.exe -k LocalSystemNetworkRestrictedC:\windows\system32\svchost.exe -k LocalServiceC:\windows\system32\svchost.exe -k NetworkServiceC:\windows\system32\svchost.exe -k LocalServiceNoNetworkC:\windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\windows\Explorer.EXEC:\windows\system32\ctfmon.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\windows\system32\wbem\wmiprvse.exeC:\windows\system32\NOTEPAD.EXEC:\windows\SysWOW64\cmd.exeC:\windows\system32\conhost.exeC:\windows\SysWOW64\cscript.exeC:\windows\system32\wbem\wmiprvse.exe.============== Pseudo HJT Report ===============.uStart Page = https://www.google.com/uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENNmStart Page = hxxp://lenovo.msn.comuInternet Settings,ProxyOverride = *.localmWinlogon: Userinit=userinit.exe,BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllBHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO: EgisPBIE Class: {7b51ccbe-4af9-44a6-bdab-d7f7e4c4e6f9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dlluRun: [WLSync] "C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe" /backgrounduRun: [Facebook Update] "C:\Users\Chris\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserveruRun: [dysiap] rundll32.exe "C:\Users\Chris\AppData\Roaming\dysiap.dll",FileCreateuRun: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exemRun: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraymPolicies-explorer: NoActiveDesktop = 1 (0x1)mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)IE: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTMLIE: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTMLIE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.htmlIE: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll /100IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLLIE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllDPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} - hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.3.0.cabTCP: DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{8B659D86-C6E6-4607-AC33-8014EC4846CD} : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E} : DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\24F696E676F60284F6473707F647 : DhcpNameServer = 10.1.0.1 66.103.64.5 66.103.80.4TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\3747275676963786F6573747F6E6765756374727F6F6D6 : DhcpNameServer = 4.2.2.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\442716B65686F6D656 : DhcpNameServer = 192.168.1.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\841435D2743747 : DhcpNameServer = 4.2.2.2 4.2.2.1 10.28.54.45 10.28.55.20TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\84562726023557464656E6C496E6B6 : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\D45646963616C602D496C6560275966696 : DhcpNameServer = 97.64.183.164 97.64.209.37Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLLSEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllLSA: Notification Packages = scecli EgisPwdFilter EgisDSPwdFilter EgisPLPwdFilterBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dllBHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO-X64: EgisPBIE Class: {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO-X64: EgisPBIE - No FileBHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO-X64: ZeonIEEventHelper Class: {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB-X64: Nuance PDF: {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllmRun-x64: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraySEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll.============= SERVICES / DRIVERS ===============.R0 fbfmon;fbfmon;C:\windows\system32\drivers\fbfmon.sys --> C:\windows\system32\drivers\fbfmon.sys [?]R0 LHDmgr;LHDmgr;C:\windows\system32\DRIVERS\LhdX64.sys --> C:\windows\system32\DRIVERS\LhdX64.sys [?]R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]R3 ACPIVPC;Lenovo Virtual Power Controller Driver;C:\windows\system32\DRIVERS\AcpiVpc.sys --> C:\windows\system32\DRIVERS\AcpiVpc.sys [?]R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --> C:\windows\system32\DRIVERS\HECIx64.sys [?]R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUVStor.sys --> C:\windows\system32\Drivers\RtsUVStor.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]S0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys --> C:\windows\system32\DRIVERS\MpFilter.sys [?]S1 BPntDrv;BPntDrv;C:\windows\system32\drivers\BPntDrv.sys --> C:\windows\system32\drivers\BPntDrv.sys [?]S1 EgisTecFF;EgisTecFF;C:\windows\system32\DRIVERS\EgisTecFF.sys --> C:\windows\system32\DRIVERS\EgisTecFF.sys [?]S1 mwlPSDFilter;mwlPSDFilter;C:\windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\windows\system32\DRIVERS\mwlPSDFilter.sys [?]S1 mwlPSDNServ;mwlPSDNServ;C:\windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\windows\system32\DRIVERS\mwlPSDNServ.sys [?]S1 mwlPSDVDisk;mwlPSDVDisk;C:\windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\windows\system32\DRIVERS\mwlPSDVDisk.sys [?]S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 EgisTec Service Help;EgisTec Service Help;C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [2010-10-22 327024]S2 EgisTec Service;EgisTec Service;C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe [2010-12-13 703856]S2 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-12-13 650096]S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);C:\windows\system32\Drivers\FPSensor.sys --> C:\windows\system32\Drivers\FPSensor.sys [?]S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-12 655944]S2 PDFProFiltSrv;PDFProFiltSrv;C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-7-27 134944]S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-7-13 1153368]S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]S2 SSICloudService;SSICloudService;C:\Program Files (x86)\Software Secure, Inc\SSICloudService\SSICloudService.exe [2012-2-3 220160]S2 SSIRuntimeService;SSIRuntimeService;C:\Program Files (x86)\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe [2012-2-3 33792]S2 SsiSrpDiagnosticsService;SSI SRP Diagnostics Service;C:\Program Files (x86)\Software Secure, Inc\Software Secure, Inc\SsiDiagnosticsService.exe [2010-12-6 15360]S2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-4 2656280]S2 WebUpdate4;Web Update Wizard Service V4;C:\Windows\SysWOW64\WebUpdateSvc4.exe [2007-5-18 229856]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-6 250056]S3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\system32\DRIVERS\clwvd.sys --> C:\windows\system32\DRIVERS\clwvd.sys [?]S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248]S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-3-20 14216]S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-3-20 8456]S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]S3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --> C:\windows\system32\DRIVERS\IntcDAud.sys [?]S3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys --> C:\windows\system32\drivers\mbam.sys [?]S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys --> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]S3 vm331avs;Digital Camera 1;C:\windows\system32\Drivers\vm331avs.sys --> C:\windows\system32\Drivers\vm331avs.sys [?]S3 vmuvcflt;Vimicro USB Camera Filter;C:\windows\system32\Drivers\vmuvcflt.sys --> C:\windows\system32\Drivers\vmuvcflt.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]S3 wsvd;wsvd;C:\windows\system32\DRIVERS\wsvd.sys --> C:\windows\system32\DRIVERS\wsvd.sys [?]S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184].=============== Created Last 30 ================.2012-07-14 02:14:46 -------- dc----w- C:\Users\Chris\AppData\Local\{DB61C036-6D9B-46E8-824F-96E682D2CC1E}2012-07-14 02:14:31 -------- dc----w- C:\Users\Chris\AppData\Local\{FCF97C6A-F02C-40F1-BEA5-A8A67F045541}2012-07-14 01:40:49 -------- dc----w- C:\ProgramData\Spybot - Search & Destroy2012-07-14 01:40:49 -------- dc----w- C:\Program Files (x86)\Spybot - Search & Destroy2012-07-13 03:15:34 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C0ACB4D6-48CA-46C1-8164-EB1614896BE9}\offreg.dll2012-07-13 02:07:37 -------- dc----w- C:\Users\Chris\AppData\Roaming\Malwarebytes2012-07-13 02:07:15 -------- dc----w- C:\ProgramData\Malwarebytes2012-07-13 02:07:11 24904 -c--a-w- C:\windows\System32\drivers\mbam.sys2012-07-13 02:07:10 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware2012-07-13 01:30:17 -------- dc----w- C:\Users\Chris\AppData\Local\{466B1C3D-CC8A-11E1-8270-B8AC6F996F26}2012-07-13 01:30:13 377856 -c--a-w- C:\Users\Chris\AppData\Roaming\dysiap.dll2012-07-12 23:54:28 -------- dc----w- C:\Users\Chris\AppData\Local\{570CB5D4-EBD4-4390-9C37-04D449D74FDF}2012-07-12 14:02:19 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C0ACB4D6-48CA-46C1-8164-EB1614896BE9}\mpengine.dll2012-07-12 11:54:00 -------- dc----w- C:\Users\Chris\AppData\Local\{B3727647-22C6-4954-9E59-EEDCAC8EF799}2012-07-12 11:53:47 -------- dc----w- C:\Users\Chris\AppData\Local\{25BAF4D9-1712-4155-A308-8F0DDCB9C77B}2012-07-12 03:11:14 3148800 ----a-w- C:\windows\System32\win32k.sys2012-07-11 20:36:37 2004480 ----a-w- C:\windows\System32\msxml6.dll2012-07-11 20:30:52 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll2012-07-11 20:30:52 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll2012-07-11 20:30:52 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll2012-07-11 20:30:52 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll2012-07-11 20:30:51 805376 ----a-w- C:\windows\SysWow64\cdosys.dll2012-07-11 20:30:51 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll2012-07-11 20:30:51 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll2012-07-11 20:30:51 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll2012-07-11 20:30:51 1133568 ----a-w- C:\windows\System32\cdosys.dll2012-07-11 18:12:46 -------- dc----w- C:\Users\Chris\AppData\Local\{E8512AEA-F566-46E6-AD1F-C0A81EC2E7BC}2012-07-11 13:37:57 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll2012-07-11 04:20:21 -------- dc----w- C:\Users\Chris\AppData\Local\{A1020FD3-5904-4424-875E-6A4ED46E726F}2012-07-10 16:19:57 -------- dc----w- C:\Users\Chris\AppData\Local\{26C3EF90-1AA3-4CBE-9AEA-26F45F1ABC6B}2012-07-10 16:19:46 -------- dc----w- C:\Users\Chris\AppData\Local\{090FE3BC-89B4-430D-9116-8591A1283E06}2012-07-10 04:19:21 -------- dc----w- C:\Users\Chris\AppData\Local\{2E2FD7E8-6C3D-4F64-A6C6-EB6104485E89}2012-07-09 14:37:21 -------- dc----w- C:\Users\Chris\AppData\Local\{D47F37C4-A3F6-4F5F-A79D-CB5C83474DBF}2012-07-09 14:37:07 -------- dc----w- C:\Users\Chris\AppData\Local\{43A7FC58-A32E-43FF-9A92-048841C5AC43}2012-07-08 16:05:12 -------- dc----w- C:\Users\Chris\AppData\Local\{B7067734-4A9F-4B6C-BE5B-3F7B14C76F50}2012-07-08 16:04:58 -------- dc----w- C:\Users\Chris\AppData\Local\{27DCC5D2-B198-4A21-9450-BA6BB053A31D}2012-07-07 16:21:52 -------- dc----w- C:\Users\Chris\AppData\Local\{C06882D4-6EBE-4219-AF72-ECE408FA5704}2012-07-07 03:40:43 -------- dc----w- C:\Users\Chris\AppData\Local\{D9E3B73D-FE12-4D80-B74A-BBC8BFE2F453}2012-07-06 15:40:18 -------- dc----w- C:\Users\Chris\AppData\Local\{A358D6C1-CE24-43A2-B5D3-91D815140E1B}2012-07-06 03:39:54 -------- dc----w- C:\Users\Chris\AppData\Local\{1A336D29-03BF-407A-9A1C-4B695EC361EB}2012-07-05 15:39:30 -------- dc----w- C:\Users\Chris\AppData\Local\{CFA67504-011F-42C8-9AF4-75920C0B50EE}2012-07-05 03:39:06 -------- dc----w- C:\Users\Chris\AppData\Local\{84F06CCF-6A0A-4357-867A-0E3B3A59640D}2012-07-04 12:32:12 -------- dc----w- C:\Users\Chris\AppData\Local\{7C13DB0D-274C-4DFD-89B4-4A3C5E6FEADA}2012-07-04 12:32:00 -------- dc----w- C:\Users\Chris\AppData\Local\{2E027742-59F9-4765-8C5C-E70938F658BA}2012-07-04 00:31:34 -------- dc----w- C:\Users\Chris\AppData\Local\{F720AD1D-F796-4B97-8EB4-1347D2334F1A}2012-07-03 21:18:16 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{90504DF0-2127-42AD-A2F9-511AA75917AD}\gapaengine.dll2012-07-03 12:31:10 -------- dc----w- C:\Users\Chris\AppData\Local\{57DE7C23-7513-4599-9F06-4D6A430C871E}2012-07-02 18:06:26 -------- dc----w- C:\Users\Chris\AppData\Local\{9B8FFC94-50B8-4D57-9983-5A4338524D58}2012-07-02 03:08:35 -------- dc----w- C:\Users\Chris\AppData\Local\{4AA1B356-15DE-4C70-83B3-92266EF748DF}2012-06-30 22:58:50 -------- dc----w- C:\Users\Chris\AppData\Local\{FB7EA9AA-F34C-43AE-8EB4-597B795744F1}2012-06-27 21:47:00 -------- dc----w- C:\Users\Chris\AppData\Local\{C7EF70AD-A7C8-48B1-AEE3-825977808AF6}2012-06-27 03:57:53 -------- dc----w- C:\Users\Chris\AppData\Local\{859821BC-1CAC-4B98-9311-5735EEA295F5}2012-06-26 12:43:47 -------- dc----w- C:\Users\Chris\AppData\Local\{8C0CE7F1-B765-440D-B3F3-248033817097}2012-06-25 12:59:25 -------- dc----w- C:\Users\Chris\AppData\Local\{11D3FD59-D01F-43D8-8371-A14856F56A8B}2012-06-25 00:28:43 -------- dc----w- C:\Users\Chris\AppData\Local\{80C479DD-F1D1-4B3A-BC21-A945646147D5}2012-06-25 00:28:30 -------- dc----w- C:\Users\Chris\AppData\Local\{030C6BE1-E8E2-41C4-9A38-06247B64F634}2012-06-19 16:34:05 2622464 ----a-w- C:\windows\System32\wucltux.dll2012-06-19 16:33:46 99840 ----a-w- C:\windows\System32\wudriver.dll2012-06-19 16:33:14 36864 ----a-w- C:\windows\System32\wuapp.exe2012-06-19 16:33:14 186752 ----a-w- C:\windows\System32\wuwebv.dll2012-06-19 14:47:36 -------- dc----w- C:\Users\Chris\AppData\Local\{0F4CB182-767B-46C2-A423-DA8142882239}2012-06-19 14:47:24 -------- dc----w- C:\Users\Chris\AppData\Local\{E2B13B73-A41A-4BBC-909E-A1DD28C5AE9B}2012-06-19 02:46:57 -------- dc----w- C:\Users\Chris\AppData\Local\{EBC7F20E-2DF2-46CA-8A29-2B5FC291C510}2012-06-19 02:46:45 -------- dc----w- C:\Users\Chris\AppData\Local\{0A1176DE-E556-4456-87B9-01A29826AF88}2012-06-17 17:15:50 -------- dc----w- C:\Users\Chris\AppData\Local\{7A6768B1-00E1-49C5-857E-3FC797A67AD6}2012-06-17 17:15:35 -------- dc----w- C:\Users\Chris\AppData\Local\{0E11B8F3-03FE-412F-B524-2D5EF888E5D8}2012-06-15 20:50:18 -------- dc----w- C:\Users\Chris\AppData\Local\{735E2C68-8953-4990-8D0A-509DA0B78BD3}2012-06-15 20:50:07 -------- dc----w- C:\Users\Chris\AppData\Local\{8673A41E-CB9E-44A5-9493-75A495C21F39}2012-06-15 02:59:00 514560 ----a-w- C:\windows\SysWow64\qdvd.dll2012-06-15 02:59:00 366592 ----a-w- C:\windows\System32\qdvd.dll2012-06-15 02:28:58 -------- dc----w- C:\Users\Chris\AppData\Local\{DAA8BFC6-929F-4C55-8BC8-B03E39B25DA2}2012-06-14 14:28:33 -------- dc----w- C:\Users\Chris\AppData\Local\{59FCD77E-0828-482E-8724-6BC0572C1B11}.==================== Find3M ====================.2012-07-12 11:54:30 426184 -c--a-w- C:\windows\SysWow64\FlashPlayerApp.exe2012-07-12 11:54:29 70344 -c--a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-07-12 03:10:15 2048 ----a-w- C:\windows\SysWow64\msxml3r.dll2012-07-12 03:10:15 2048 ----a-w- C:\windows\System32\msxml3r.dll2012-07-12 03:10:15 1881600 ----a-w- C:\windows\System32\msxml3.dll2012-07-12 03:10:15 1390080 ----a-w- C:\windows\SysWow64\msxml6.dll2012-07-12 03:10:15 1236992 ----a-w- C:\windows\SysWow64\msxml3.dll2012-07-12 03:09:08 340992 ----a-w- C:\windows\System32\schannel.dll2012-07-12 03:09:08 307200 ----a-w- C:\windows\System32\ncrypt.dll2012-07-12 03:09:08 225280 ----a-w- C:\windows\SysWow64\schannel.dll2012-07-12 03:09:08 219136 ----a-w- C:\windows\SysWow64\ncrypt.dll2012-07-12 03:09:07 96768 ----a-w- C:\windows\SysWow64\sspicli.dll2012-07-12 03:09:07 95600 ----a-w- C:\windows\System32\drivers\ksecdd.sys2012-07-12 03:09:07 458704 ----a-w- C:\windows\System32\drivers\cng.sys2012-07-12 03:09:07 22016 ----a-w- C:\windows\SysWow64\secur32.dll2012-07-12 03:09:07 151920 ----a-w- C:\windows\System32\drivers\ksecpkg.sys2012-07-12 03:05:09 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb2012-07-12 03:05:09 2382848 ----a-w- C:\windows\System32\mshtml.tlb2012-07-12 03:05:09 2311680 ----a-w- C:\windows\System32\jscript9.dll2012-07-12 03:05:09 1800192 ----a-w- C:\windows\SysWow64\jscript9.dll2012-07-12 03:05:09 173056 ----a-w- C:\windows\System32\ieUnatt.exe2012-07-12 03:05:09 1494528 ----a-w- C:\windows\System32\inetcpl.cpl2012-07-12 03:05:09 142848 ----a-w- C:\windows\SysWow64\ieUnatt.exe2012-07-12 03:05:09 1427968 ----a-w- C:\windows\SysWow64\inetcpl.cpl2012-07-12 03:05:09 1392128 ----a-w- C:\windows\System32\wininet.dll2012-07-12 03:05:08 1129472 ----a-w- C:\windows\SysWow64\wininet.dll2012-06-19 04:12:46 209920 ----a-w- C:\windows\System32\profsvc.dll2012-06-17 17:23:32 9216 ----a-w- C:\windows\System32\rdrmemptylst.exe2012-06-17 17:23:32 77312 ----a-w- C:\windows\System32\rdpwsx.dll2012-06-17 17:23:32 149504 ----a-w- C:\windows\System32\rdpcorekmts.dll2012-06-17 17:18:52 5559664 ----a-w- C:\windows\System32\ntoskrnl.exe2012-06-17 17:18:52 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe2012-06-17 17:18:52 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe2012-06-17 17:18:21 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys2012-06-17 17:18:10 3216384 ----a-w- C:\windows\System32\msi.dll2012-06-17 17:18:10 2342400 ----a-w- C:\windows\SysWow64\msi.dll2012-06-17 17:17:57 184320 ----a-w- C:\windows\System32\cryptsvc.dll2012-06-17 17:17:57 1462272 ----a-w- C:\windows\System32\crypt32.dll2012-06-17 17:17:57 140288 ----a-w- C:\windows\SysWow64\cryptsvc.dll2012-06-17 17:17:57 1158656 ----a-w- C:\windows\SysWow64\crypt32.dll2012-06-17 17:17:57 103936 ----a-w- C:\windows\SysWow64\cryptnet.dll2012-06-17 17:17:56 140288 ----a-w- C:\windows\System32\cryptnet.dll2012-05-18 23:16:19 1544704 ----a-w- C:\windows\System32\DWrite.dll2012-05-18 23:16:19 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll2012-05-18 23:05:16 75120 ----a-w- C:\windows\System32\drivers\partmgr.sys2012-05-18 23:02:39 1918320 ----a-w- C:\windows\System32\drivers\tcpip.sys2012-05-07 14:41:34 50546 -c--a-w- C:\windows\SysWow64\wuwuninst.exe2009-08-14 19:31:00 1370112 -c--a-w- C:\Program Files (x86)\bsgui.dll2009-08-14 19:26:50 3101184 -c--a-w- C:\Program Files (x86)\bsapi.dll.============= FINISH: 21:30:06.89 ===============It looks like the same thing as the DDS. Link to post Share on other sites More sharing options...
Maniac Posted July 15, 2012 ID:570958 Share Posted July 15, 2012 No, this is not the Attach.txt . Please re-run DDS and try again. Link to post Share on other sites More sharing options...
herbchristopher Posted July 15, 2012 Author ID:571060 Share Posted July 15, 2012 Alright, let's try this:UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-08-26.01).Microsoft Windows 7 Home PremiumBoot Device: \Device\HarddiskVolume1Install Date: 11/28/2011 2:46:33 PMSystem Uptime: 7/13/2012 9:18:08 PM (0 hours ago).Motherboard: LENOVO | | Emerald LakeProcessor: Intel® Core i3-2330M CPU @ 2.20GHz | CPU | 2195/100mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 254 GiB total, 9.786 GiB free.D: is FIXED (NTFS) - 29 GiB total, 26.8 GiB free.F: is CDROM ().==== Disabled Device Manager Items =============.Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}Description: Security Processor Loader DriverDevice ID: ROOT\LEGACY_SPLDR\0000Manufacturer:Name: Security Processor Loader DriverPNP Device ID: ROOT\LEGACY_SPLDR\0000Service: spldr.==== System Restore Points ===================.RP143: 7/8/2012 4:44:48 PM - Windows UpdateRP144: 7/11/2012 10:02:43 PM - Windows Update.==== Installed Programs ======================. Update for Microsoft Office 2007 (KB2508958)Adobe Flash Player 11 ActiveXAdobe Reader X (10.1.3)Best Buy pc appBioExcessBytescout Lossless CodecCyberLink YouCamD3DX10EASEUS Partition Master 9.1.1 Home EditionEgisTec ES603 WDM DriverEnergy ManagementES603 WDM DriverFacebook Video Calling 1.2.0.159ffdshow v1.1.3562 [2010-09-07]Google ChromeGoogle Update HelperHijackThis 1.99.1Intel® Control CenterIntel® Management Engine ComponentsIntel® Processor GraphicsIntel® Rapid Storage TechnologyJava Auto UpdaterJava 6 Update 31JBidwatcher 2.5Lenovo EasyCameraLenovo OneKey RecoveryLenovo Security SuiteLenovo_Wireless_DriverMalwarebytes Anti-Malware version 1.62.0.1300Mesh RuntimeMicrosoft Office 2007 Service Pack 3 (SP3)Microsoft Office Access MUI (English) 2007Microsoft Office Access Setup Metadata MUI (English) 2007Microsoft Office Enterprise 2007Microsoft Office Excel MUI (English) 2007Microsoft Office File Validation Add-InMicrosoft Office Groove MUI (English) 2007Microsoft Office Groove Setup Metadata MUI (English) 2007Microsoft Office InfoPath MUI (English) 2007Microsoft Office OneNote MUI (English) 2007Microsoft Office Outlook MUI (English) 2007Microsoft Office PowerPoint MUI (English) 2007Microsoft Office Proof (English) 2007Microsoft Office Proof (French) 2007Microsoft Office Proof (Spanish) 2007Microsoft Office Proofing (English) 2007Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)Microsoft Office Publisher MUI (English) 2007Microsoft Office Shared MUI (English) 2007Microsoft Office Shared Setup Metadata MUI (English) 2007Microsoft Office Word MUI (English) 2007Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219MSVCRTMSXML 4.0 SP2 (KB954430)MSXML 4.0 SP2 (KB973688)Oracle Crystal BallOriginPort LockerPower2GoPowerPoint Add-in for PPT To Video ScoutPPT To Video ScoutRealtek Ethernet Controller Driver For Windows 7Realtek High Definition Audio DriverRealtek USB 2.0 Reader DriverScansoft PDF ProfessionalSecurexam Browser v7Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2596672) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2596744) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2596785) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2596792) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2596871) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2596880) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2597162) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2597969) 32-Bit EditionSecurity Update for Microsoft Office 2007 suites (KB2598041) 32-Bit EditionSecurity Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit EditionSecurity Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit EditionSecurity Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit EditionSecurity Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit EditionSecurity Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit EditionSecurity Update for Microsoft Office Word 2007 (KB2596917) 32-Bit EditionSkype™ 5.8Spybot - Search & DestroySSI SRP DiagnosticsSSICloudServiceSSIRuntimeServiceInstallerStar Wars Empire at WarStar Wars: The Old RepublicSystem Requirements Lab for IntelSystem UpdateTipard Free PDF to BMP ConverterUpdate for 2007 Microsoft Office System (KB967642)Update for Microsoft .NET Framework 4 Client Profile (KB2468871)Update for Microsoft .NET Framework 4 Client Profile (KB2533523)Update for Microsoft .NET Framework 4 Client Profile (KB2600217)Update for Microsoft Office 2007 Help for Common Features (KB963673)Update for Microsoft Office Access 2007 Help (KB963663)Update for Microsoft Office Excel 2007 Help (KB963678)Update for Microsoft Office Infopath 2007 Help (KB963662)Update for Microsoft Office OneNote 2007 Help (KB963670)Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit EditionUpdate for Microsoft Office Outlook 2007 Help (KB963677)Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit EditionUpdate for Microsoft Office Powerpoint 2007 Help (KB963669)Update for Microsoft Office Publisher 2007 Help (KB963667)Update for Microsoft Office Script Editor Help (KB963671)Update for Microsoft Office Word 2007 Help (KB963665)VeriFaceWeb Update Wizard (Redistributable) 4.0Windows Live Communications PlatformWindows Live EssentialsWindows Live InstallerWindows Live MeshWindows Live Mesh ActiveX Control for Remote ConnectionsWindows Live PIMT PlatformWindows Live SOXEWindows Live SOXE DefinitionsWindows Live UX PlatformWindows Live UX Platform Language Pack.==== Event Viewer Messages From Past Week ========.7/9/2012 7:42:05 AM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.7/8/2012 12:00:45 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.7/8/2012 12:00:45 PM, Error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.7/8/2012 12:00:45 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.7/8/2012 11:42:44 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.7/8/2012 10:15:26 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Lenovo\Chris SID (S-1-5-21-1601185161-3566255987-2677368337-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.7/8/2012 10:15:26 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Lenovo\Chris SID (S-1-5-21-1601185161-3566255987-2677368337-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.7/8/2012 10:15:25 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {B77C4C36-0154-4C52-AB49-FAA03837E47F} and APPID {EA022610-0748-4C24-B229-6C507EBDFDBB} to the user Lenovo\Chris SID (S-1-5-21-1601185161-3566255987-2677368337-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.7/13/2012 9:29:08 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1535.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode7/13/2012 9:29:07 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 9:29:07 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}7/13/2012 9:19:23 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 9:19:23 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}7/13/2012 9:19:23 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}7/13/2012 9:19:17 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}7/13/2012 9:19:08 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}7/13/2012 9:18:59 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\windows\System32\bcmihvsrv64.dll Error Code: 217/13/2012 9:18:43 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BPntDrv discache EgisTecFF MpFilter mwlPSDFilter mwlPSDNServ mwlPSDVDisk spldr Wanarpv67/13/2012 9:17:06 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.7/13/2012 9:17:06 PM, Error: Service Control Manager [7000] - The Windows Update service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.7/13/2012 9:16:36 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the System Update service to connect.7/13/2012 9:16:36 PM, Error: Service Control Manager [7000] - The System Update service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.7/13/2012 9:15:59 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the file specified.7/13/2012 9:01:27 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1535.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode7/13/2012 7:57:49 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1535.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode7/13/2012 7:24:47 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1535.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode7/13/2012 7:20:28 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}7/13/2012 7:20:28 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}7/13/2012 6:08:37 PM, Error: Service Control Manager [7022] - The Background Intelligent Transfer Service service hung on starting.7/13/2012 6:06:31 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.7/13/2012 6:06:24 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Spooler service.7/13/2012 5:59:16 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}7/13/2012 5:59:10 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1535.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode7/13/2012 5:42:44 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 4:41:15 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1535.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode7/13/2012 4:31:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}7/13/2012 4:31:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}7/13/2012 4:31:09 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BPntDrv DfsC discache EgisTecFF MpFilter mwlPSDFilter mwlPSDNServ mwlPSDVDisk NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf7/13/2012 4:31:09 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.7/13/2012 4:31:09 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 4:31:09 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 4:31:09 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 4:31:08 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.7/13/2012 4:31:08 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.7/13/2012 4:31:08 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.7/13/2012 4:31:08 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.7/13/2012 4:31:08 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.7/12/2012 11:27:35 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Lenovo\Emily SID (S-1-5-21-1601185161-3566255987-2677368337-1003) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.7/12/2012 11:27:35 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {B77C4C36-0154-4C52-AB49-FAA03837E47F} and APPID {EA022610-0748-4C24-B229-6C507EBDFDBB} to the user Lenovo\Emily SID (S-1-5-21-1601185161-3566255987-2677368337-1003) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.7/12/2012 11:27:35 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Lenovo\Emily SID (S-1-5-21-1601185161-3566255987-2677368337-1003) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool..==== End Of File =========================== Link to post Share on other sites More sharing options...
Maniac Posted July 16, 2012 ID:571462 Share Posted July 16, 2012 That's it! Step 1I see you are running Teatimer.I suggest you to disable it because it can interfere with the changes you'll make on your system.When everything is done and your log is clean again, you can enable it again.If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.How to disable TeaTimer <== click me for instructions.After you disabled Teatimer, download ResetTeaTimer.exe to your desktop. Then run ResetTeaTimer.exe.This will only take a few seconds.Step 2Launch Malwarebytes' Anti-MalwareGo to Update tab and select Check for Updates. If an update is found, it will download and install the latest version. Go to Scanner tab and select Perform Quick Scan, then click Scan.The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.Step 3Download aswMBR.exe to your desktop. Double click the aswMBR.exe to run it Click the "Scan" button to start scan On completion of the scan click save log, save it to your desktop and post in your next reply In your next reply, post the following log files:Malwarebytes' Anti-Malware logaswMBR loga new fresh DDS log file Link to post Share on other sites More sharing options...
herbchristopher Posted July 17, 2012 Author ID:572093 Share Posted July 17, 2012 Alright, here's what I got:MalwarebytesWindows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)Internet Explorer 9.0.8112.16421Chris :: LENOVO [administrator]Protection: Disabled7/17/2012 3:32:21 PMmbam-log-2012-07-17 (15-32-21).txtScan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 230585Time elapsed: 2 minute(s), 34 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)(end)aswMBRaswMBR version 0.9.9.1665 Copyright© 2011 AVAST SoftwareRun date: 2012-07-17 15:37:50-----------------------------15:37:50.152 OS Version: Windows x64 6.1.7601 Service Pack 115:37:50.152 Number of processors: 4 586 0x2A0715:37:50.152 ComputerName: LENOVO UserName: Chris15:37:51.088 Initialize success15:43:11.185 AVAST engine defs: 1207170115:43:41.200 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-115:43:41.200 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 315:43:41.215 Disk 0 MBR read successfully15:43:41.215 Disk 0 MBR scan15:43:41.215 Disk 0 Windows VISTA default MBR code15:43:41.215 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 200 MB offset 204815:43:41.231 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 260243 MB offset 41164815:43:41.231 Disk 0 Partition - 00 0F Extended LBA 29692 MB offset 53338931215:43:41.262 Disk 0 Partition 3 00 12 Compaq diag NTFS 15109 MB offset 59419852815:43:41.293 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 29691 MB offset 53339136015:43:41.340 Disk 0 scanning C:\windows\system32\drivers15:43:49.358 Service scanning15:44:12.946 Modules scanning15:44:12.946 Disk 0 trace - called modules:15:44:12.961 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll15:44:12.977 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80055d5060]15:44:12.977 3 CLASSPNP.SYS[fffff8800181743f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ac8050]15:44:14.116 AVAST engine scan C:\windows15:44:16.409 AVAST engine scan C:\windows\system3215:46:24.953 AVAST engine scan C:\windows\system32\drivers15:46:33.954 AVAST engine scan C:\Users\Chris15:51:49.980 AVAST engine scan C:\ProgramData15:52:51.085 Scan finished successfully15:56:57.581 Disk 0 MBR has been saved successfully to "C:\Users\Chris\Documents\MBR.dat"15:56:57.581 The log file has been saved successfully to "C:\Users\Chris\Documents\aswMBR.txt"DDS.DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORKInternet Explorer: 9.0.8112.16421Run by Chris at 16:07:46 on 2012-07-17Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4010.2712 [GMT -5:00].AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}.============== Running Processes ===============.C:\windows\system32\wininit.exeC:\windows\system32\lsm.exeC:\windows\system32\svchost.exe -k DcomLaunchC:\windows\system32\svchost.exe -k RPCSSC:\Program Files\Microsoft Security Client\MsMpEng.exeC:\windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\windows\system32\svchost.exe -k netsvcsC:\windows\system32\svchost.exe -k LocalSystemNetworkRestrictedC:\windows\system32\svchost.exe -k LocalServiceC:\windows\system32\svchost.exe -k NetworkServiceC:\windows\system32\svchost.exe -k LocalServiceNoNetworkC:\windows\Explorer.EXEC:\windows\system32\ctfmon.exeC:\windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\windows\SysWOW64\cmd.exeC:\windows\system32\conhost.exeC:\windows\SysWOW64\cscript.exeC:\windows\system32\wbem\wmiprvse.exe.============== Pseudo HJT Report ===============.uStart Page = https://www.google.com/uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENNmStart Page = hxxp://lenovo.msn.comuInternet Settings,ProxyOverride = *.localmWinlogon: Userinit=userinit.exe,BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO: EgisPBIE Class: {7b51ccbe-4af9-44a6-bdab-d7f7e4c4e6f9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dlluRun: [dysiap] "C:\Windows\System32\rundll32.exe" "C:\Users\Chris\AppData\Roaming\dysiap.dll",FileCreatemRun: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraymPolicies-explorer: NoActiveDesktop = 1 (0x1)mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)IE: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTMLIE: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTMLIE: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTMLIE: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTMLIE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.htmlIE: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll /100IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLLDPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} - hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.3.0.cabTCP: DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{8B659D86-C6E6-4607-AC33-8014EC4846CD} : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E} : DhcpNameServer = 208.180.42.68 208.180.42.100TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\24F696E676F60284F6473707F647 : DhcpNameServer = 10.1.0.1 66.103.64.5 66.103.80.4TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\3747275676963786F6573747F6E6765756374727F6F6D6 : DhcpNameServer = 4.2.2.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\442716B65686F6D656 : DhcpNameServer = 192.168.1.1TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\841435D2743747 : DhcpNameServer = 4.2.2.2 4.2.2.1 10.28.54.45 10.28.55.20TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\84562726023557464656E6C496E6B6 : DhcpNameServer = 208.180.42.100 208.180.42.68TCP: Interfaces\{917ADF30-AF7E-4E4A-AE06-41E500A3685E}\D45646963616C602D496C6560275966696 : DhcpNameServer = 97.64.183.164 97.64.209.37Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLLSEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllLSA: Notification Packages = scecli EgisPwdFilter EgisDSPwdFilter EgisPLPwdFilterBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dllBHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dllBHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO-X64: EgisPBIE Class: {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} - C:\Program Files (x86)\EgisTec BioExcess\EgisPBIE.dllBHO-X64: EgisPBIE - No FileBHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO-X64: ZeonIEEventHelper Class: {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllBHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB-X64: Nuance PDF: {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dllmRun-x64: [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe"mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraySEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll.============= SERVICES / DRIVERS ===============.R0 fbfmon;fbfmon;C:\windows\system32\drivers\fbfmon.sys --> C:\windows\system32\drivers\fbfmon.sys [?]R0 LHDmgr;LHDmgr;C:\windows\system32\DRIVERS\LhdX64.sys --> C:\windows\system32\DRIVERS\LhdX64.sys [?]R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]R3 ACPIVPC;Lenovo Virtual Power Controller Driver;C:\windows\system32\DRIVERS\AcpiVpc.sys --> C:\windows\system32\DRIVERS\AcpiVpc.sys [?]R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --> C:\windows\system32\DRIVERS\HECIx64.sys [?]R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUVStor.sys --> C:\windows\system32\Drivers\RtsUVStor.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]S0 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys --> C:\windows\system32\DRIVERS\MpFilter.sys [?]S1 BPntDrv;BPntDrv;C:\windows\system32\drivers\BPntDrv.sys --> C:\windows\system32\drivers\BPntDrv.sys [?]S1 EgisTecFF;EgisTecFF;C:\windows\system32\DRIVERS\EgisTecFF.sys --> C:\windows\system32\DRIVERS\EgisTecFF.sys [?]S1 mwlPSDFilter;mwlPSDFilter;C:\windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\windows\system32\DRIVERS\mwlPSDFilter.sys [?]S1 mwlPSDNServ;mwlPSDNServ;C:\windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\windows\system32\DRIVERS\mwlPSDNServ.sys [?]S1 mwlPSDVDisk;mwlPSDVDisk;C:\windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\windows\system32\DRIVERS\mwlPSDVDisk.sys [?]S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 EgisTec Service Help;EgisTec Service Help;C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [2010-10-22 327024]S2 EgisTec Service;EgisTec Service;C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe [2010-12-13 703856]S2 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2010-12-13 650096]S2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);C:\windows\system32\Drivers\FPSensor.sys --> C:\windows\system32\Drivers\FPSensor.sys [?]S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-12 655944]S2 PDFProFiltSrv;PDFProFiltSrv;C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-7-27 134944]S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]S2 SSICloudService;SSICloudService;C:\Program Files (x86)\Software Secure, Inc\SSICloudService\SSICloudService.exe [2012-2-3 220160]S2 SSIRuntimeService;SSIRuntimeService;C:\Program Files (x86)\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe [2012-2-3 33792]S2 SsiSrpDiagnosticsService;SSI SRP Diagnostics Service;C:\Program Files (x86)\Software Secure, Inc\Software Secure, Inc\SsiDiagnosticsService.exe [2010-12-6 15360]S2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-4 2656280]S2 WebUpdate4;Web Update Wizard Service V4;C:\Windows\SysWOW64\WebUpdateSvc4.exe [2007-5-18 229856]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-6 250056]S3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\system32\DRIVERS\clwvd.sys --> C:\windows\system32\DRIVERS\clwvd.sys [?]S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-3-19 276248]S3 epmntdrv;epmntdrv;C:\Windows\System32\epmntdrv.sys [2012-3-20 14216]S3 EuGdiDrv;EuGdiDrv;C:\Windows\System32\EuGdiDrv.sys [2012-3-20 8456]S3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --> C:\windows\system32\DRIVERS\IntcDAud.sys [?]S3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys --> C:\windows\system32\drivers\mbam.sys [?]S3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys --> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]S3 vm331avs;Digital Camera 1;C:\windows\system32\Drivers\vm331avs.sys --> C:\windows\system32\Drivers\vm331avs.sys [?]S3 vmuvcflt;Vimicro USB Camera Filter;C:\windows\system32\Drivers\vmuvcflt.sys --> C:\windows\system32\Drivers\vmuvcflt.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]S3 wsvd;wsvd;C:\windows\system32\DRIVERS\wsvd.sys --> C:\windows\system32\DRIVERS\wsvd.sys [?]S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184].=============== Created Last 30 ================.2012-07-16 21:31:53 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{36AD9D12-C370-417A-B8D7-FDEDD7BFDAD6}\mpengine.dll2012-07-16 15:03:41 9013136 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll2012-07-16 14:02:26 -------- dc----w- C:\Users\Chris\AppData\Local\{3291C91C-2D3D-4D14-858F-EAD2859F8437}2012-07-16 14:02:13 -------- dc----w- C:\Users\Chris\AppData\Local\{68ECF6A5-E208-42B4-B3B2-D92961DC269F}2012-07-16 12:57:57 -------- dc----w- C:\Program Files\CCleaner2012-07-14 02:14:46 -------- dc----w- C:\Users\Chris\AppData\Local\{DB61C036-6D9B-46E8-824F-96E682D2CC1E}2012-07-14 02:14:31 -------- dc----w- C:\Users\Chris\AppData\Local\{FCF97C6A-F02C-40F1-BEA5-A8A67F045541}2012-07-14 01:40:49 -------- dc----w- C:\ProgramData\Spybot - Search & Destroy2012-07-14 01:40:49 -------- dc----w- C:\Program Files (x86)\Spybot - Search & Destroy2012-07-13 02:07:37 -------- dc----w- C:\Users\Chris\AppData\Roaming\Malwarebytes2012-07-13 02:07:15 -------- dc----w- C:\ProgramData\Malwarebytes2012-07-13 02:07:11 24904 -c--a-w- C:\windows\System32\drivers\mbam.sys2012-07-13 02:07:10 -------- dc----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware2012-07-13 01:30:17 -------- dc----w- C:\Users\Chris\AppData\Local\{466B1C3D-CC8A-11E1-8270-B8AC6F996F26}2012-07-13 01:30:13 377856 -c--a-w- C:\Users\Chris\AppData\Roaming\dysiap.dll2012-07-12 23:54:28 -------- dc----w- C:\Users\Chris\AppData\Local\{570CB5D4-EBD4-4390-9C37-04D449D74FDF}2012-07-12 11:54:00 -------- dc----w- C:\Users\Chris\AppData\Local\{B3727647-22C6-4954-9E59-EEDCAC8EF799}2012-07-12 11:53:47 -------- dc----w- C:\Users\Chris\AppData\Local\{25BAF4D9-1712-4155-A308-8F0DDCB9C77B}2012-07-12 03:11:14 3148800 ----a-w- C:\windows\System32\win32k.sys2012-07-11 20:36:37 2004480 ----a-w- C:\windows\System32\msxml6.dll2012-07-11 20:30:52 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll2012-07-11 20:30:52 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll2012-07-11 20:30:52 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll2012-07-11 20:30:52 1019904 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll2012-07-11 20:30:51 805376 ----a-w- C:\windows\SysWow64\cdosys.dll2012-07-11 20:30:51 61440 ----a-w- C:\Program Files\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 57344 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msador15.dll2012-07-11 20:30:51 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll2012-07-11 20:30:51 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll2012-07-11 20:30:51 212992 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll2012-07-11 20:30:51 143360 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msjro.dll2012-07-11 20:30:51 1133568 ----a-w- C:\windows\System32\cdosys.dll2012-07-11 18:12:46 -------- dc----w- C:\Users\Chris\AppData\Local\{E8512AEA-F566-46E6-AD1F-C0A81EC2E7BC}2012-07-11 04:20:21 -------- dc----w- C:\Users\Chris\AppData\Local\{A1020FD3-5904-4424-875E-6A4ED46E726F}2012-07-10 16:19:57 -------- dc----w- C:\Users\Chris\AppData\Local\{26C3EF90-1AA3-4CBE-9AEA-26F45F1ABC6B}2012-07-10 16:19:46 -------- dc----w- C:\Users\Chris\AppData\Local\{090FE3BC-89B4-430D-9116-8591A1283E06}2012-07-10 04:19:21 -------- dc----w- C:\Users\Chris\AppData\Local\{2E2FD7E8-6C3D-4F64-A6C6-EB6104485E89}2012-07-09 14:37:21 -------- dc----w- C:\Users\Chris\AppData\Local\{D47F37C4-A3F6-4F5F-A79D-CB5C83474DBF}2012-07-09 14:37:07 -------- dc----w- C:\Users\Chris\AppData\Local\{43A7FC58-A32E-43FF-9A92-048841C5AC43}2012-07-08 16:05:12 -------- dc----w- C:\Users\Chris\AppData\Local\{B7067734-4A9F-4B6C-BE5B-3F7B14C76F50}2012-07-08 16:04:58 -------- dc----w- C:\Users\Chris\AppData\Local\{27DCC5D2-B198-4A21-9450-BA6BB053A31D}2012-07-07 16:21:52 -------- dc----w- C:\Users\Chris\AppData\Local\{C06882D4-6EBE-4219-AF72-ECE408FA5704}2012-07-07 03:40:43 -------- dc----w- C:\Users\Chris\AppData\Local\{D9E3B73D-FE12-4D80-B74A-BBC8BFE2F453}2012-07-06 15:40:18 -------- dc----w- C:\Users\Chris\AppData\Local\{A358D6C1-CE24-43A2-B5D3-91D815140E1B}2012-07-06 03:39:54 -------- dc----w- C:\Users\Chris\AppData\Local\{1A336D29-03BF-407A-9A1C-4B695EC361EB}2012-07-05 15:39:30 -------- dc----w- C:\Users\Chris\AppData\Local\{CFA67504-011F-42C8-9AF4-75920C0B50EE}2012-07-05 03:39:06 -------- dc----w- C:\Users\Chris\AppData\Local\{84F06CCF-6A0A-4357-867A-0E3B3A59640D}2012-07-04 12:32:12 -------- dc----w- C:\Users\Chris\AppData\Local\{7C13DB0D-274C-4DFD-89B4-4A3C5E6FEADA}2012-07-04 12:32:00 -------- dc----w- C:\Users\Chris\AppData\Local\{2E027742-59F9-4765-8C5C-E70938F658BA}2012-07-04 00:31:34 -------- dc----w- C:\Users\Chris\AppData\Local\{F720AD1D-F796-4B97-8EB4-1347D2334F1A}2012-07-03 21:18:16 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{90504DF0-2127-42AD-A2F9-511AA75917AD}\gapaengine.dll2012-07-03 12:31:10 -------- dc----w- C:\Users\Chris\AppData\Local\{57DE7C23-7513-4599-9F06-4D6A430C871E}2012-07-02 18:06:26 -------- dc----w- C:\Users\Chris\AppData\Local\{9B8FFC94-50B8-4D57-9983-5A4338524D58}2012-07-02 03:08:35 -------- dc----w- C:\Users\Chris\AppData\Local\{4AA1B356-15DE-4C70-83B3-92266EF748DF}2012-06-30 22:58:50 -------- dc----w- C:\Users\Chris\AppData\Local\{FB7EA9AA-F34C-43AE-8EB4-597B795744F1}2012-06-27 21:47:00 -------- dc----w- C:\Users\Chris\AppData\Local\{C7EF70AD-A7C8-48B1-AEE3-825977808AF6}2012-06-27 03:57:53 -------- dc----w- C:\Users\Chris\AppData\Local\{859821BC-1CAC-4B98-9311-5735EEA295F5}2012-06-26 12:43:47 -------- dc----w- C:\Users\Chris\AppData\Local\{8C0CE7F1-B765-440D-B3F3-248033817097}2012-06-25 12:59:25 -------- dc----w- C:\Users\Chris\AppData\Local\{11D3FD59-D01F-43D8-8371-A14856F56A8B}2012-06-25 00:28:43 -------- dc----w- C:\Users\Chris\AppData\Local\{80C479DD-F1D1-4B3A-BC21-A945646147D5}2012-06-25 00:28:30 -------- dc----w- C:\Users\Chris\AppData\Local\{030C6BE1-E8E2-41C4-9A38-06247B64F634}2012-06-19 16:34:05 2622464 ----a-w- C:\windows\System32\wucltux.dll2012-06-19 16:33:46 99840 ----a-w- C:\windows\System32\wudriver.dll2012-06-19 16:33:14 36864 ----a-w- C:\windows\System32\wuapp.exe2012-06-19 16:33:14 186752 ----a-w- C:\windows\System32\wuwebv.dll2012-06-19 14:47:36 -------- dc----w- C:\Users\Chris\AppData\Local\{0F4CB182-767B-46C2-A423-DA8142882239}2012-06-19 14:47:24 -------- dc----w- C:\Users\Chris\AppData\Local\{E2B13B73-A41A-4BBC-909E-A1DD28C5AE9B}2012-06-19 02:46:57 -------- dc----w- C:\Users\Chris\AppData\Local\{EBC7F20E-2DF2-46CA-8A29-2B5FC291C510}2012-06-19 02:46:45 -------- dc----w- C:\Users\Chris\AppData\Local\{0A1176DE-E556-4456-87B9-01A29826AF88}.==================== Find3M ====================.2012-07-12 11:54:30 426184 -c--a-w- C:\windows\SysWow64\FlashPlayerApp.exe2012-07-12 11:54:29 70344 -c--a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-07-12 03:11:09 514560 ----a-w- C:\windows\SysWow64\qdvd.dll2012-07-12 03:11:09 366592 ----a-w- C:\windows\System32\qdvd.dll2012-07-12 03:10:15 2048 ----a-w- C:\windows\SysWow64\msxml3r.dll2012-07-12 03:10:15 2048 ----a-w- C:\windows\System32\msxml3r.dll2012-07-12 03:10:15 1881600 ----a-w- C:\windows\System32\msxml3.dll2012-07-12 03:10:15 1390080 ----a-w- C:\windows\SysWow64\msxml6.dll2012-07-12 03:10:15 1236992 ----a-w- C:\windows\SysWow64\msxml3.dll2012-07-12 03:09:08 340992 ----a-w- C:\windows\System32\schannel.dll2012-07-12 03:09:08 307200 ----a-w- C:\windows\System32\ncrypt.dll2012-07-12 03:09:08 225280 ----a-w- C:\windows\SysWow64\schannel.dll2012-07-12 03:09:08 219136 ----a-w- C:\windows\SysWow64\ncrypt.dll2012-07-12 03:09:07 96768 ----a-w- C:\windows\SysWow64\sspicli.dll2012-07-12 03:09:07 95600 ----a-w- C:\windows\System32\drivers\ksecdd.sys2012-07-12 03:09:07 458704 ----a-w- C:\windows\System32\drivers\cng.sys2012-07-12 03:09:07 22016 ----a-w- C:\windows\SysWow64\secur32.dll2012-07-12 03:09:07 151920 ----a-w- C:\windows\System32\drivers\ksecpkg.sys2012-07-12 03:05:09 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb2012-07-12 03:05:09 2382848 ----a-w- C:\windows\System32\mshtml.tlb2012-07-12 03:05:09 2311680 ----a-w- C:\windows\System32\jscript9.dll2012-07-12 03:05:09 1800192 ----a-w- C:\windows\SysWow64\jscript9.dll2012-07-12 03:05:09 173056 ----a-w- C:\windows\System32\ieUnatt.exe2012-07-12 03:05:09 1494528 ----a-w- C:\windows\System32\inetcpl.cpl2012-07-12 03:05:09 142848 ----a-w- C:\windows\SysWow64\ieUnatt.exe2012-07-12 03:05:09 1427968 ----a-w- C:\windows\SysWow64\inetcpl.cpl2012-07-12 03:05:09 1392128 ----a-w- C:\windows\System32\wininet.dll2012-07-12 03:05:08 1129472 ----a-w- C:\windows\SysWow64\wininet.dll2012-06-19 04:12:46 209920 ----a-w- C:\windows\System32\profsvc.dll2012-06-17 17:23:32 9216 ----a-w- C:\windows\System32\rdrmemptylst.exe2012-06-17 17:23:32 77312 ----a-w- C:\windows\System32\rdpwsx.dll2012-06-17 17:23:32 149504 ----a-w- C:\windows\System32\rdpcorekmts.dll2012-06-17 17:18:52 5559664 ----a-w- C:\windows\System32\ntoskrnl.exe2012-06-17 17:18:52 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe2012-06-17 17:18:52 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe2012-06-17 17:18:21 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys2012-06-17 17:18:10 3216384 ----a-w- C:\windows\System32\msi.dll2012-06-17 17:18:10 2342400 ----a-w- C:\windows\SysWow64\msi.dll2012-06-17 17:17:57 184320 ----a-w- C:\windows\System32\cryptsvc.dll2012-06-17 17:17:57 1462272 ----a-w- C:\windows\System32\crypt32.dll2012-06-17 17:17:57 140288 ----a-w- C:\windows\SysWow64\cryptsvc.dll2012-06-17 17:17:57 1158656 ----a-w- C:\windows\SysWow64\crypt32.dll2012-06-17 17:17:57 103936 ----a-w- C:\windows\SysWow64\cryptnet.dll2012-06-17 17:17:56 140288 ----a-w- C:\windows\System32\cryptnet.dll2012-05-18 23:16:19 1544704 ----a-w- C:\windows\System32\DWrite.dll2012-05-18 23:16:19 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll2012-05-18 23:05:16 75120 ----a-w- C:\windows\System32\drivers\partmgr.sys2012-05-18 23:02:39 1918320 ----a-w- C:\windows\System32\drivers\tcpip.sys2012-05-07 14:41:34 50546 -c--a-w- C:\windows\SysWow64\wuwuninst.exe2009-08-14 19:31:00 1370112 -c--a-w- C:\Program Files (x86)\bsgui.dll2009-08-14 19:26:50 3101184 -c--a-w- C:\Program Files (x86)\bsapi.dll.============= FINISH: 16:08:10.16 ===============Give this a try. Link to post Share on other sites More sharing options...
Maniac Posted July 18, 2012 ID:572268 Share Posted July 18, 2012 Please perform step 2 in Normal mode, not in Safe mode. Link to post Share on other sites More sharing options...
herbchristopher Posted July 24, 2012 Author ID:575511 Share Posted July 24, 2012 Alright. Here is the Malware scan, not in safe mode:Malwarebytes Anti-Malware (Trial) 1.62.0.1300www.malwarebytes.orgDatabase version: v2012.07.22.11Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421Chris :: LENOVO [administrator]Protection: Enabled7/23/2012 9:09:51 PMmbam-log-2012-07-23 (21-09-51).txtScan type: Full scan (C:\|)Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 352577Time elapsed: 1 hour(s), 19 minute(s), 59 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)(end)The infection does not seem to be as bad as it was when I first started. I can at least use programs and function pretty normal. It still freezes when I bring the computer out of hybernation and when I log out. I still get occasional internet search redirects. Link to post Share on other sites More sharing options...
Maniac Posted July 24, 2012 ID:575582 Share Posted July 24, 2012 Your database version is out-of-date. Did you follow my instructions?Database version: v2012.07.22.11Also, your scan type was not Quick, as I ask. Please be more careful. Link to post Share on other sites More sharing options...
herbchristopher Posted July 28, 2012 Author ID:577685 Share Posted July 28, 2012 Sorry. I have a lot on my plate right now, and when I get weighed down I tend to overlook things. I updated it right before I ran the quick scan. Here is my log.Malwarebytes Anti-Malware (Trial) 1.62.0.1300www.malwarebytes.orgDatabase version: v2012.07.21.12Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421Chris :: LENOVO [administrator]Protection: Enabled7/21/2012 5:54:43 PMmbam-log-2012-07-21 (17-54-43).txtScan type: Full scan (C:\|)Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 335947Time elapsed: 1 hour(s), 11 minute(s), 15 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 1C:\Users\Chris\Documents\Vuze Downloads\DeGun - MS OFFICE 2007-2010 AIO crack+Serial Pack CLEAN\Microsoft Office - 2007 Entreprise Keygen\Keygen Microsoft Office Entreprise 2007.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.(end) Link to post Share on other sites More sharing options...
herbchristopher Posted July 29, 2012 Author ID:578146 Share Posted July 29, 2012 I see what I was doing wrong. Malwarebytes Anti-Malware 1.62.0.1300www.malwarebytes.orgDatabase version: v2012.07.28.01Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421Chris :: LENOVO [administrator]Protection: Enabled7/27/2012 10:16:16 PMmbam-log-2012-07-27 (22-16-16).txtScan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 212137Time elapsed: 3 minute(s), 50 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 1C:\Program Files (x86)\Vid-Saver\Vid-Saver.dll (PUP.GamePlayLab) -> Delete on reboot.Registry Keys Detected: 16HKCR\CLSID\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCR\TypeLib\{44444444-4444-4444-4444-440044344491} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCR\Interface\{55555555-5555-5555-5555-550055345591} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCR\CrossriderApp0003491.BHO.1 (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCR\CrossriderApp0003491.BHO (PUP.GamePlayLab) -> Quarantined and deleted successfully.HKCR\CrossriderApp0003491.FBApi (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.HKCR\CrossriderApp0003491.FBApi.1 (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.HKCR\CrossriderApp0003491.Sandbox (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.HKCR\CrossriderApp0003491.Sandbox.1 (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.HKCU\Software\Cr_Installer\3491 (Adware.GamePlayLab) -> Quarantined and deleted successfully.HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> Quarantined and deleted successfully.Registry Values Detected: 1HKCU\Software\InstalledBrowserExtensions\215 Apps|3491 (PUP.CrossFire.SA) -> Data: Vid-Saver -> Quarantined and deleted successfully.Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 2C:\Program Files (x86)\Vid-Saver\Vid-Saver.dll (PUP.GamePlayLab) -> Delete on reboot.C:\Users\Chris\Local Settings\Temporary Internet Files\Content.IE5\GVRBFWU1\vfd-ob[1].exe (Adware.Dropper) -> Quarantined and deleted successfully.(end) Link to post Share on other sites More sharing options...
Maniac Posted July 30, 2012 ID:578422 Share Posted July 30, 2012 Good! Please visit this webpage for download links, and instructions for running the tool: http://www.bleepingcomputer.com/combofix/how-to-use-combofix* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Please post the C:\ComboFix.txt in your next reply for further review.Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted July 31, 2012 Root Admin ID:578802 Share Posted July 31, 2012 This topic is closed due to PiracyC:\Users\Chris\Documents\Vuze Downloads\DeGun - MS OFFICE 2007-2010 AIO crack+Serial Pack CLEAN\Microsoft Office - 2007 Entreprise Keygen\Keygen Microsoft Office Entreprise 2007.exe Link to post Share on other sites More sharing options...
Recommended Posts