Jump to content

Persistent Trojan.Gen


Recommended Posts

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 10.0.9200.16521 BrowserJavaVersion: 10.17.2

Run by 601292 at 22:22:33 on 2013-03-26

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.7338.4096 [GMT -4:00]

.

AV: Lavasoft Ad-Aware *Disabled/Outdated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}

AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Lavasoft Ad-Aware *Disabled/Outdated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}

SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}

FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files\Sandboxie\SbieSvc.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe

C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files\IDT\WDM\AESTSr64.exe

C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe

C:\Windows\system32\svchost.exe -k apphost

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Symantec\pcAnywhere\awhost32.exe

C:\Windows\system32\taskhost.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe

C:\Program Files (x86)\Symantec\pcAnywhere\AWHPROBE.EXE

C:\Program Files\Altiris\Altiris Agent\AeXAgentUIHost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\ShrewSoft\VPN Client\dtpd.exe

C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE

C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt

C:\Program Files\ShrewSoft\VPN Client\iked.exe

C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe

C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe

C:\Windows\system32\mqsvc.exe

C:\Program Files\DellTPad\Apoint.exe

C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe

C:\Program Files\Logitech\FlowScroll\KhalScroll.exe

C:\Program Files\Logitech\SetPointP\SetPoint.exe

C:\Program Files\DellTPad\ApMsgFwd.exe

C:\Program Files\DellTPad\Apntex.exe

C:\Program Files\DellTPad\HidFind.exe

C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE

C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe

C:\Users\601292\AppData\Roaming\Google\Google Talk\googletalk.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe

C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe

C:\Windows\system32\DRIVERS\o2flash.exe

C:\Users\601292\AppData\Local\Programs\Google\MusicManager\MusicManager.exe

C:\Program Files (x86)\Novation\Automap\AutomapServer.exe

C:\Program Files (x86)\InstantEyedropper\InstantEyedropper.exe

C:\Windows\SysWOW64\srvany.exe

C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Windows\sysWOW64\SDIOAssist.exe

C:\Program Files (x86)\PuTTY\pageant.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

C:\Program Files (x86)\Microsoft Lync\communicator.exe

C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe

C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe

C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe

c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe

C:\Program Files (x86)\GoZone\GoZone_iSync.exe

C:\Program Files (x86)\Citrix\ICA Client\concentr.exe

C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe

C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe

C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe

C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe

C:\Program Files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe

C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac

C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe

C:\Windows\SysWOW64\vmnat.exe

C:\Windows\system32\svchost.exe -k iissvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe

C:\Windows\SysWOW64\vmnetdhcp.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Windows\system32\svchost.exe -k HPService

C:\Program Files\Altiris\Altiris Agent\x86\AeXNSAgentHostSurrogate32.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe

C:\Program Files (x86)\Symantec\pcAnywhere\pcaEvents.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Novation\Automap\MidiAutomapClient.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe

C:\Windows\system32\wbem\WmiApSrv.exe

C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\601292\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://bluroom.luxottica.com/en/

uDefault_Page_URL = hxxp://bluroom.luxottica.com/en/

uProxyOverride = <-loopback>

mWinlogon: Userinit = userinit.exe,

BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

BHO: Microsoft Web Test Recorder 10.0 Helper: {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - c:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll

BHO: Logitech Flow Scroll: {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\FlowScroll\32-bit\LogiSmooth.dll

BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\CA\ERwin Data Modeler r9\JRE\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll

EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll

EB: Web Test Recorder 10.0: {5802D092-1784-4908-8CDB-99B6842D353D} -

uRun: [safeBootTokWatch] "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"

uRun: [googletalk] C:\Users\601292\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart

uRun: [Google Update] "C:\Users\601292\AppData\Local\Google\Update\GoogleUpdate.exe" /c

uRun: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"

uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

uRun: [iSUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler

uRun: [MusicManager] "C:\Users\601292\AppData\Local\Programs\Google\MusicManager\MusicManager.exe"

uRun: [Novation Automap Server] "C:\Program Files (x86)\Novation\Automap\AutomapServer.exe"

uRun: [instanteyedropper] "C:\Program Files (x86)\InstantEyedropper\InstantEyedropper.exe"

mRun: [iMSS] "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"

mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey

mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"

mRun: [safeBootTrayManager] "C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe"

mRun: [safeBootTokenWatcher] "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"

mRun: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin

mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

mRun: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup

mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

mRun: [ArcSoft MediaImpression Monitor] C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"

mRun: [Ad-Aware Antivirus] "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run

mRun: [sDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"

mRun: [AgentMonitor] C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe

mRun: [Hercules DJ Series] C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe /boot

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

StartupFolder: C:\Users\601292\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\GOZONE~1.LNK - C:\Program Files (x86)\GoZone\GoZone_iSync.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Pageant.lnk - C:\Program Files (x86)\PuTTY\pageant.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\VPNGUI~1.LNK - C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe

uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

uPolicies-System: NoDispScrSavPage = dword:1

uPolicies-System: SB_NoDispScrSavPage = dword:1

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-Explorer: NoActiveDesktopChanges = dword:1

mPolicies-System: ConsentPromptBehaviorAdmin = dword:0

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableLUA = dword:0

mPolicies-System: EnableUIADesktopToggle = dword:0

mPolicies-System: PromptOnSecureDesktop = dword:0

mPolicies-System: DisableCAD = dword:1

mPolicies-System: NoDispScrSavPage = dword:1

mPolicies-System: SB_NoDispScrSavPage = dword:0

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe"

IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

LSP: %SystemRoot%\system32\vsocklib.dll

.

INFO: HKCU has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

.

INFO: HKLM has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://alliances.trizetto.com/InternalSite/WhlCompMgr.cab

DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab

DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

DPF: {FCADE536-93F5-4577-80A3-E7C32FAC4C7D} - hxxp://atl-hpqsapp01.lenscrafters.com:8080/qcbin/Spider10.cab

TCP: NameServer = 192.168.1.1

TCP: Interfaces\{36D985EE-299C-4F92-B0C6-598BFA1558CA} : NameServer = 10.80.179.20,10.80.224.20

TCP: Interfaces\{DB5E60B8-ABCA-483E-B143-E903F4ED0CA3} : DHCPNameServer = 192.168.1.1

TCP: Interfaces\{DB5E60B8-ABCA-483E-B143-E903F4ED0CA3}\2457379744F66756D27657563747 : DHCPNameServer = 209.18.47.61 209.18.47.62

TCP: Interfaces\{DB5E60B8-ABCA-483E-B143-E903F4ED0CA3}\3554657455543545 : DHCPNameServer = 10.100.111.10 172.19.142.10

TCP: Interfaces\{DB5E60B8-ABCA-483E-B143-E903F4ED0CA3}\D4F62747F6E6D4F62696C656 : DHCPNameServer = 192.168.2.254

TCP: Interfaces\{DB5E60B8-ABCA-483E-B143-E903F4ED0CA3}\D4F6E676F602D416769636 : DHCPNameServer = 192.168.200.1

Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Notify: PCANotify - PCANotify.dll

Notify: SDWinLogon - SDWinLogon.dll

AppInit_DLLs= AMINIT32.DLL

SSODL: WebCheck - <orphaned>

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

IFEO: taskmgr.exe - "C:\PROGRAM FILES (X86)\SYSINTERNALS\PROCEXP.EXE"

x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll

x64-BHO: Logitech Flow Scroll: {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\FlowScroll\LogiSmooth.dll

x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

x64-Run: [sysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe

x64-Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe

x64-Run: [LogiScrollApp] C:\Program Files\Logitech\FlowScroll\KhalScroll.exe

x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming

x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

x64-Run: [TortoiseHgOverlayIconServer] C:\Program Files\TortoiseHg\TortoiseHgOverlayServer.exe

x64-Run: [igfxTray] C:\Windows\System32\igfxtray.exe

x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe

x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

x64-IE: {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files (x86)\Fiddler2\Fiddler.exe"

.

INFO: x64-HKLM has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab

x64-DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab

x64-DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab

x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab

x64-Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - <orphaned>

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Notify: igfxcui - igfxdev.dll

x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

x64-SSODL: WebCheck - <orphaned>

x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

x64-IFEO: taskmgr.exe - "C:\PROGRAM FILES (X86)\SYSINTERNALS\PROCEXP.EXE"

Hosts: 127.0.0.1 www.spywareinfo.com

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\601292\AppData\Roaming\Mozilla\Firefox\Profiles\22akjndi.default\

FF - prefs.js: browser.search.selectedEngine - Claro Search

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll

FF - plugin: C:\Users\601292\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll

FF - plugin: C:\Users\601292\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

FF - plugin: C:\Users\601292\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll

FF - plugin: C:\Users\601292\AppData\Roaming\Mozilla\plugins\npo1d.dll

FF - plugin: C:\Windows\System32\Wat\npWatWeb.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll

FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll

FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

FF - ExtSQL: !HIDDEN! 2012-03-11 10:40; smartwebprinting@hp.com; C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

.

---- FIREFOX POLICIES ----

FF - user.js: extensions.BabylonToolbar_i.id - b6293aa40000000000006480994c9ec0

FF - user.js: extensions.BabylonToolbar_i.hardId - b6293aa40000000000006480994c9ec0

FF - user.js: extensions.BabylonToolbar_i.instlDay - 15542

FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17

FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar_i.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.tlbrId - base

FF - user.js: extensions.BabylonToolbar_i.instlRef - sst

FF - user.js: extensions.BabylonToolbar.autoRvrt - false

FF - user.js: extensions.BabylonToolbar_i.newTab - false

FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://search.babylon.com/?babsrc=TB_def&mntrId=b6293aa40000000000006480994c9ec0&q=

FF - user.js: extensions.BabylonToolbar.id - b6293aa40000000000006480994c9ec0

FF - user.js: extensions.BabylonToolbar.appId - {BDB69379-802F-4eaf-B541-F8DE92DD98DB}

FF - user.js: extensions.BabylonToolbar.instlDay - 15603

FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.9.12

FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.9.12

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.9.1216:00:58

FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar.tlbrId - base

FF - user.js: extensions.BabylonToolbar.instlRef - sst

FF - user.js: extensions.BabylonToolbar.dfltLng - en

FF - user.js: extensions.BabylonToolbar.excTlbr - false

FF - user.js: extensions.BabylonToolbar.admin - false

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110195&tt=120912_nocpc_3812_2

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.claro.tlbrSrchUrl -

FF - user.js: extensions.claro.id - b6293aa40000000000006480994c9ec1

FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}

FF - user.js: extensions.claro.instlDay - 15646

FF - user.js: extensions.claro.vrsn - 1.8.3.10

FF - user.js: extensions.claro.vrsni - 1.8.3.10

FF - user.js: extensions.claro_i.vrsnTs - 1.8.3.109:52:34

FF - user.js: extensions.claro.prtnrId - claro

FF - user.js: extensions.claro.prdct - claro

FF - user.js: extensions.claro.aflt - babsst

FF - user.js: extensions.claro_i.smplGrp - none

FF - user.js: extensions.claro.tlbrId - claro

FF - user.js: extensions.claro.instlRef - sst

FF - user.js: extensions.claro.dfltLng - en

FF - user.js: extensions.claro.excTlbr - false

FF - user.js: extensions.claro.admin - false

.

============= SERVICES / DRIVERS ===============

.

R0 gfibto;gfibto;C:\Windows\System32\drivers\gfibto.sys [2012-11-26 14456]

R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-7-10 56208]

R0 SBAlg;SBAlg;C:\Windows\System32\drivers\sbalg.sys [2012-2-13 60128]

R0 SbFsLock;SbFsLock;C:\Windows\System32\drivers\sbfslock.sys [2012-2-13 15616]

R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2012-2-13 21616]

R1 ctxusbm;Citrix USB Monitor Driver;C:\Windows\System32\drivers\ctxusbm.sys [2012-5-17 93272]

R1 RsvLock;RsvLock;C:\Windows\System32\drivers\rsvlock.sys [2012-2-13 58112]

R1 SbFlop;SbFlop;C:\Windows\System32\drivers\sbflop.sys [2012-2-13 23296]

R1 SbRegFlt;SbRegFlt;C:\Windows\System32\drivers\sbregflt.sys [2012-2-13 15616]

R1 vflt;Shrew Soft Lightweight Filter;C:\Windows\System32\drivers\vfilter.sys [2010-9-2 21504]

R2 Ad-Aware Service;Ad-Aware Service;C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-11-21 1236368]

R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2012-2-7 89600]

R2 CodeMeter.exe;CodeMeter Runtime Server;C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2012-12-19 2571704]

R2 dtpd;ShrewSoft DNS Proxy Daemon;C:\Program Files\ShrewSoft\VPN Client\dtpd.exe -service --> C:\Program Files\ShrewSoft\VPN Client\dtpd.exe -service [?]

R2 HerculesDJControlMP3;Hercules DJ Control MP3;C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [2013-2-17 18944]

R2 iked;ShrewSoft IKE Daemon;C:\Program Files\ShrewSoft\VPN Client\iked.exe -service --> C:\Program Files\ShrewSoft\VPN Client\iked.exe -service [?]

R2 ipsecd;ShrewSoft IPSEC Daemon;C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe -service --> C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe -service [?]

R2 MsDepSvc;Web Deployment Agent Service;C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-4-1 67400]

R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2012-10-4 6371192]

R2 O2SDIOAssist;O2SDIOAssist;C:\Windows\SysWOW64\srvany.exe [2012-2-7 8192]

R2 SafeBootClientManager;SafeBoot Client Manager;C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe [2009-4-23 380988]

R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-12-20 1831024]

R2 uagqecsvc;Microsoft Forefront UAG Quarantine Enforcement Client;C:\Program Files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe [2012-5-17 149904]

R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-2-7 2656280]

R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-29 846448]

R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2012-2-13 27760]

R3 AeXAgentSrvHost;AeXAgentSrvHost;C:\Program Files\Altiris\Altiris Agent\x86\AeXNSAgentHostSurrogate32.exe [2012-10-12 317312]

R3 automap;Automap MIDI Driver;C:\Windows\System32\drivers\automap.sys [2012-11-23 18776]

R3 bpenum;Intel® Centrino® WiMAX Enumerator;C:\Windows\System32\drivers\bpenum.sys [2012-2-7 75264]

R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\System32\drivers\bpmp.sys [2012-2-7 173568]

R3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;C:\Windows\System32\drivers\bpusb.sys [2012-2-7 81408]

R3 cvusbdrv;Dell ControlVault;C:\Windows\System32\drivers\cvusbdrv.sys [2012-2-7 38440]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-14 138912]

R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-10-17 317440]

R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2011-9-2 76056]

R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2011-9-2 15128]

R3 O2SDJRDR;O2SDJRDR;C:\Windows\System32\drivers\o2sdjw7x64.sys [2011-3-23 83560]

R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2012-6-17 166576]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-7-9 104912]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-7-9 123856]

S2 DisplayFusionService;DisplayFusionService;C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [2013-2-12 1243024]

S2 IBMWAS80Service - L07-FPYLFS1Node01;IBM WebSphere Application Server V8.0 - L07-FPYLFS1Node01;"C:\Program Files (x86)\IBM\WebSphere\AppServer\bin\wasservice.exe" "IBMWAS80Service - L07-FPYLFS1Node01" --> C:\Program Files (x86)\IBM\WebSphere\AppServer\bin\wasservice.exe [?]

S2 MouseWithoutBordersSvc;Mouse without Borders Service;C:\Program Files (x86)\Microsoft Garage\Mouse without Borders\MouseWithoutBordersSvc.exe [2012-10-24 27872]

S2 SBAMSvc;Ad-Aware;C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-9-20 3677000]

S3 AltirisAgentProvider;AltirisAgentProvider;C:\Program Files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe [2012-10-12 408448]

S3 Bulk;HDJBulk;C:\Windows\System32\drivers\HDJBulk.sys [2012-12-10 238960]

S3 ConfigService;Altiris Deployment Solution - System Configuration;C:\Program Files\Altiris\Altiris Agent\Agents\Deployment\Agent\ConfigService.exe [2011-8-12 267368]

S3 DMService;Microsoft Forefront UAG Endpoint Component Manager;C:\Windows\DOWNLO~1\DMService.exe [2012-5-17 468368]

S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]

S3 HDJAsioK;HDJAsioK;C:\Windows\System32\drivers\HDJAsioK.sys [2012-12-10 306032]

S3 HDJMidi;Hercules DJ Console 4-Mx MIDI;C:\Windows\System32\drivers\HDJMidi.sys [2012-12-10 271216]

S3 ipMIDI;nerds.de ipMIDI - Ethernet Midi Ports SvcDesc(WDM);C:\Windows\System32\drivers\ipmidi.sys [2011-5-15 23040]

S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-11-19 80384]

S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-11-19 181248]

S3 NvnUsbAudio;Novation USB Audio Driver;C:\Windows\System32\drivers\nvnusbaudio.sys [2012-8-10 53080]

S3 O2MDFRDR;O2MDFRDR;C:\Windows\System32\drivers\o2mdfw7x64.sys [2011-1-3 72808]

S3 O2MDRRDR;O2MDRRDR;C:\Windows\System32\drivers\O2MDRw7x64.sys [2011-1-3 74984]

S3 PVIS9;Pervasive Integration Server 9;C:\Program Files (x86)\Pervasive\Cosmos9\IntegrationServer\nt-service\bin\Wrapper.exe [2010-11-5 110592]

S3 PVIS9_64;Pervasive Integration Server 9 (64-bit);C:\Program Files\Pervasive\Cosmos9 (64-bit)\IntegrationServer\nt-service\bin\Wrapper.exe [2010-11-5 110592]

S3 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-12-3 1103392]

S3 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-12-3 1369624]

S3 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-12-3 168384]

S3 SophosVirusRemovalTool;Sophos Virus Removal Tool;C:\Program Files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [2013-1-17 153080]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]

S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]

S3 teVirtualMIDI64;teVirtualMIDI - Virtual MIDI Driver x64;C:\Windows\System32\drivers\teVirtualMIDI64.sys [2011-6-26 28160]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]

S3 vnet;Shrew Soft Virtual Adapter;C:\Windows\System32\drivers\virtualnet.sys [2010-9-2 17408]

S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-1-18 68440]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-7 1255736]

S4 Artifactory;Artifactory;C:\Program Files (x86)\artifactory\bin\wrapper.exe [2012-5-6 217088]

S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]

S4 RsFx0105;RsFx0105 Driver;C:\Windows\System32\drivers\RsFx0105.sys [2011-9-22 311144]

S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-9-22 431464]

.

=============== File Associations ===============

.

FileExt: .ini: Notepad++_file="C:\Program Files (x86)\Notepad++\notepad++.exe" "%1"

FileExt: .js: jsfile="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\Dreamweaver.exe","%1"

ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\dreamweaver.exe", "%1"

.

=============== Created Last 30 ================

.

2013-03-25 17:14:23 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-03-20 17:29:24 -------- d-----w- C:\Users\601292\AppData\Local\Telerik_AD

2013-03-19 15:16:03 -------- d-----w- C:\logs

2013-03-18 15:07:46 -------- d-----w- C:\Users\601292\Lync Recordings

2013-03-18 12:56:54 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys

2013-03-18 07:07:44 -------- d-sh--w- C:\Windows\System32\%APPDATA%

2013-03-14 17:43:20 -------- d-----w- C:\Program Files (x86)\code4ward.net

2013-03-14 17:38:17 -------- d-----w- C:\Program Files (x86)\Microsoft WebMatrix

2013-03-14 17:37:16 -------- d-----w- C:\Program Files (x86)\MySQL

2013-03-14 17:00:39 -------- d-----w- C:\Program Files\Microsoft

2013-03-13 13:29:10 16486616 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2013-03-11 18:05:09 -------- d-----w- C:\Users\601292\.ApacheDirectoryStudio

2013-03-11 18:02:50 -------- d-----w- C:\Program Files\Apache Directory Studio

2013-03-07 17:58:08 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-03-05 20:35:36 -------- d-----w- C:\Program Files\Common Files\PACE Anti-Piracy

2013-03-05 19:08:57 -------- d-----w- C:\Program Files\iPod

2013-03-05 19:08:56 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-03-05 19:08:56 -------- d-----w- C:\Program Files\iTunes

2013-03-05 19:08:56 -------- d-----w- C:\Program Files (x86)\iTunes

2013-03-04 20:50:39 -------- d-----w- C:\Program Files (x86)\InstantEyedropper

2013-03-04 15:46:36 -------- d-----w- C:\Users\601292\AppData\Roaming\app.Crunch

2013-03-04 15:44:37 -------- d-----w- C:\Program Files (x86)\Crunch

2013-03-04 14:55:48 -------- d-----w- C:\ProgramData\Sophos

2013-03-04 14:55:17 73728 ----a-r- C:\Users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe

2013-03-04 14:55:17 73728 ----a-r- C:\Users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe

2013-03-04 14:55:17 73728 ----a-r- C:\Users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe

2013-03-04 14:54:42 -------- d-----w- C:\Program Files (x86)\Sophos

2013-03-01 09:53:54 50688 ------w- C:\Users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.HttpModules.dll

2013-03-01 09:51:34 13824 ------w- C:\Users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\HtmlDiff.dll

2013-03-01 09:51:34 13824 ------w- C:\Users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\HtmlDiff.dll

2013-03-01 09:51:08 74752 ------w- C:\Users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\WebFormsMvp.dll

2013-03-01 09:51:08 74752 ------w- C:\Users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\WebFormsMvp.dll

.

==================== Find3M ====================

.

2013-03-25 17:14:23 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-03-13 13:29:19 73432 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-03-13 13:29:19 693976 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-03-07 17:57:22 861088 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll

2013-03-07 17:57:22 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-02-13 19:56:22 60304 ----a-w- C:\Users\601292\g2mdlhlpx.exe

2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll

2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll

2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll

2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll

2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll

2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll

2013-01-28 17:59:24 0 ----a-w- C:\Users\601292\DesktopFiddler2Upgrade.exe

2013-01-05 05:53:43 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-01-05 05:00:15 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-01-05 05:00:11 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-01-04 05:46:09 215040 ----a-w- C:\Windows\System32\winsrv.dll

2013-01-04 04:51:16 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll

2013-01-04 03:26:48 3153408 ----a-w- C:\Windows\System32\win32k.sys

2013-01-04 02:47:35 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2013-01-04 02:47:34 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2013-01-04 02:47:34 2048 ----a-w- C:\Windows\SysWow64\user.exe

2013-01-04 02:47:33 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2013-01-03 06:00:54 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys

2013-01-03 06:00:42 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS

.

============= FINISH: 22:25:59.89 ===============

attach.zip

Link to post
Share on other sites

Hi caseyjmorton,

Welcome to Malwarebytes Forum

My name is Tomk1. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.

The fixes are specific to your problem and should only be used for the issues on this machine.

Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.

It's often worth reading through these instructions and printing them for ease of reference.

If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.

Please reply to this thread. Do not start a new topic.

Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, feel free to create a new one.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator....

AdwCleaner

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[s1].txt as well.

Link to post
Share on other sites

<p>Thanks, Here is the log.</p>

<p> </p>

<p> </p>

<div># AdwCleaner v2.115 - Logfile created 03/27/2013 at 14:59:10</div>

<div># Updated 17/03/2013 by Xplode</div>

<div># Operating system : Windows 7 Professional Service Pack 1 (64 bits)</div>

<div># User : 601292 - L07-5YNHLV1</div>

<div># Boot Mode : Normal</div>

<div># Running from : C:\Users\601292\Downloads\AdwCleaner.exe</div>

<div># Option [Delete]</div>

<div> </div>

<div> </div>

<div>***** [services] *****</div>

<div> </div>

<div> </div>

<div>***** [Files / Folders] *****</div>

<div> </div>

<div>File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml</div>

<div>File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml</div>

<div>File Deleted : C:\user.js</div>

<div>Folder Deleted : C:\Program Files (x86)\adawaretb</div>

<div>Folder Deleted : C:\ProgramData\blekko toolbars</div>

<div>Folder Deleted : C:\Users\601292\AppData\LocalLow\adawaretb</div>

<div>Folder Deleted : C:\Users\601292\AppData\LocalLow\BabylonToolbar</div>

<div>Folder Deleted : C:\Users\601292\AppData\Roaming\Mozilla\Firefox\Profiles\22akjndi.default\adawaretb</div>

<div> </div>

<div>***** [Registry] *****</div>

<div> </div>

<div>Key Deleted : HKCU\Software\BabylonToolbar</div>

<div>Key Deleted : HKCU\Software\Conduit</div>

<div>Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}</div>

<div>Key Deleted : HKCU\Software\Softonic</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\b</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}</div>

<div>Key Deleted : HKLM\Software\Conduit</div>

<div>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32</div>

<div>Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}</div>

<div>Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{16466D47-74A8-4928-B8B2-07CD79ABFC9F}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26D5CC0A-7A46-4D86-AF45-2EFA320B0C54}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D13AC8F-037E-40C5-ADA6-231BA74EA2F4}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{322EDCF5-9E7D-4021-8C67-F3FFE4961A38}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E254398-828F-4D51-A39E-3F6B6D96A12C}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{442DAF0C-7EAD-48D9-ABEA-E0036470D6D5}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{58EB187D-24F8-4423-BD6C-655CE4C416BD}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6BEB066C-A791-4A21-B934-7783533FE888}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A07612DF-B1DD-484F-A1C3-36CA4CE919D2}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A76F97B2-2C56-456A-A29E-72741595C2E8}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B19D9D96-E59C-4936-B283-8A831CDB3A53}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC8AAABA-3F8B-4866-8B3A-D9368133A478}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E15519AE-99BE-42DD-BE60-FFC3C183F443}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}</div>

<div>Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}</div>

<div>Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]</div>

<div> </div>

<div>***** [internet Browsers] *****</div>

<div> </div>

<div>-\\ Internet Explorer v10.0.9200.16521</div>

<div> </div>

<div>[OK] Registry is clean.</div>

<div> </div>

<div>-\\ Mozilla Firefox v12.0 (en-US)</div>

<div> </div>

<div>File : C:\Users\601292\AppData\Roaming\Mozilla\Firefox\Profiles\22akjndi.default\prefs.js</div>

<div> </div>

<div>C:\Users\601292\AppData\Roaming\Mozilla\Firefox\Profiles\22akjndi.default\user.js ... Deleted !</div>

<div> </div>

<div>Deleted : user_pref("browser.BabylonToolbar_i.newTab", "");</div>

<div>Deleted : user_pref("browser.BabylonToolbar_i.newTabUrl", "");</div>

<div>Deleted : user_pref("browser.babylon.HPOnNewTab", "");</div>

<div>Deleted : user_pref("browser.search.selectedEngine", "Claro Search");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.admin", false);</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.autoRvrt", "false");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.babExt", "");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=110195&tt=120912_nocpc_3812_2");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.bbDpng", "26");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.cntry", "US");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.dpk", "");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.hdrMd5", "EEE1E403CC0F75181E4F48967AD05967");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.hmpg", false);</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.id", "b6293aa40000000000006480994c9ec0");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15603");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.6.9.1216:00:58");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.newTab", false);</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.pnu_base", "{\"newVrsn\":\"68\",\"lastVrsn\":\"68\",\"vrsnLoad\[...]</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.sg", "azb");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "azb");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...]</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.6.9.12");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.6.9.1216:00:58");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.6.9.12");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110195&tt=120912_nocpc_3812_2");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "b6293aa40000000000006480994c9ec0");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.id", "b6293aa40000000000006480994c9ec0");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15542");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false);</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.claro-search.com/?affID=116690&tt=441[...]</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.9.1216:00:58");</div>

<div>Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");</div>

<div>Deleted : user_pref("extensions.claro.admin", false);</div>

<div>Deleted : user_pref("extensions.claro.aflt", "babsst");</div>

<div>Deleted : user_pref("extensions.claro.appId", "{C3110516-8EFC-49D6-8B72-69354F332062}");</div>

<div>Deleted : user_pref("extensions.claro.dfltLng", "en");</div>

<div>Deleted : user_pref("extensions.claro.excTlbr", false);</div>

<div>Deleted : user_pref("extensions.claro.id", "b6293aa40000000000006480994c9ec1");</div>

<div>Deleted : user_pref("extensions.claro.instlDay", "15646");</div>

<div>Deleted : user_pref("extensions.claro.instlRef", "sst");</div>

<div>Deleted : user_pref("extensions.claro.prdct", "claro");</div>

<div>Deleted : user_pref("extensions.claro.prtnrId", "claro");</div>

<div>Deleted : user_pref("extensions.claro.tlbrId", "claro");</div>

<div>Deleted : user_pref("extensions.claro.tlbrSrchUrl", "");</div>

<div>Deleted : user_pref("extensions.claro.vrsn", "1.8.3.10");</div>

<div>Deleted : user_pref("extensions.claro.vrsni", "1.8.3.10");</div>

<div>Deleted : user_pref("extensions.claro_i.smplGrp", "none");</div>

<div>Deleted : user_pref("extensions.claro_i.vrsnTs", "1.8.3.109:52:34");</div>

<div> </div>

<div>-\\ Google Chrome v25.0.1364.172</div>

<div> </div>

<div>File : C:\Users\601292\AppData\Local\Google\Chrome\User Data\Default\Preferences</div>

<div> </div>

<div>Deleted [l.4192] : urls_to_restore_on_startup = [ "hxxps://www.luxotticaretail.com/", "hxxp://search.babylon.com[...]</div>

<div> </div>

<div>*************************</div>

<div> </div>

<div>AdwCleaner[R1].txt - [13298 octets] - [27/03/2013 14:57:55]</div>

<div>AdwCleaner[s1].txt - [13317 octets] - [27/03/2013 14:59:10]</div>

<div> </div>

<div>########## EOF - C:\AdwCleaner[s1].txt - [13378 octets] ##########</div>

<div> </div>

Link to post
Share on other sites

caseyjmorton,

I am so sorry.

I lost track of your thread.

Hopefully you are still with me.

Download ComboFix from here: http://download.blee...Bs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link --> http://forums.whatth...ams_t96260.html
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Link to post
Share on other sites

No worries. Here is the log. Also for what its worth, I am still getting the following virus notifications about once every 10 seconds:

Scan type: Auto-Protect Scan

Event: Risk Found!

Security risk detected: Trojan.Gen

File: C:\Users\601292\AppData\Local\Temp\DWH1BC0.tmp

Location: C:\Users\601292\AppData\Local\Temp

Computer: L07-5YNHLV1

User: 601292

Action taken: Pending Side Effects Analysis : Access denied

Date found: Friday, March 29, 2013 9:45:50 PM

Here is the log:

ComboFix 13-03-28.01 - 601292 03/29/2013 21:04:57.1.4 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.7338.4357 [GMT -4:00]

Running from: c:\users\601292\Desktop\ComboFix.exe

AV: Lavasoft Ad-Aware *Disabled/Outdated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}

AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}

FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}

SP: Lavasoft Ad-Aware *Disabled/Outdated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}

SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\program files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk

c:\users\601292\AppData\Local\assembly\tmp

c:\users\601292\AppData\Local\Temp\DWHD12A.tmp

c:\users\601292\DesktopFiddler2Upgrade.exe

c:\users\601292\g2mdlhlpx.exe

.

.

((((((((((((((((((((((((( Files Created from 2013-02-28 to 2013-03-30 )))))))))))))))))))))))))))))))

.

.

2013-03-30 01:36 . 2013-03-30 01:36 -------- d-----w- c:\users\HydraApplicationPool\AppData\Local\temp

2013-03-30 01:36 . 2013-03-30 01:36 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp

2013-03-27 19:18 . 2013-03-27 19:18 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS

2013-03-27 19:18 . 2013-03-27 19:18 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS

2013-03-27 19:18 . 2013-03-27 19:18 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS

2013-03-27 19:18 . 2013-03-27 19:18 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS

2013-03-27 19:18 . 2013-03-27 19:18 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS

2013-03-27 19:18 . 2013-03-27 19:18 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS

2013-03-27 19:18 . 2013-03-27 19:18 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS

2013-03-27 19:18 . 2013-03-27 19:18 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS

2013-03-27 19:18 . 2013-03-27 19:18 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS

2013-03-27 19:17 . 2013-03-27 19:17 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS

2013-03-27 19:17 . 2013-03-27 19:17 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS

2013-03-27 19:17 . 2013-03-27 19:17 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS

2013-03-27 19:16 . 2013-03-27 19:16 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS

2013-03-27 19:16 . 2013-03-27 19:16 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS

2013-03-27 19:16 . 2013-03-27 19:16 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS

2013-03-27 19:16 . 2013-03-27 19:16 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS

2013-03-27 19:16 . 2013-03-27 19:16 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS

2013-03-27 16:53 . 2013-03-27 16:53 -------- d-----w- c:\users\ASP.NET v4.0\AppData\Local\CrashDumps

2013-03-25 18:20 . 2013-03-25 18:20 -------- d-----w- c:\users\601292\AppData\Roaming\HPAppData

2013-03-25 17:21 . 2013-02-17 05:40 28672 ----a-w- c:\windows\system32\IEUDINIT.EXE

2013-03-25 17:14 . 2013-03-25 17:14 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-03-20 17:29 . 2013-03-20 17:29 -------- d-----w- c:\users\601292\AppData\Local\Telerik_AD

2013-03-19 15:16 . 2013-03-28 19:51 -------- d-----w- C:\logs

2013-03-18 15:07 . 2013-03-18 15:07 -------- d-----w- c:\users\601292\Lync Recordings

2013-03-18 12:56 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys

2013-03-18 07:07 . 2013-03-18 07:07 -------- d-sh--w- c:\windows\system32\%APPDATA%

2013-03-14 17:43 . 2013-03-14 17:43 -------- d-----w- c:\program files (x86)\code4ward.net

2013-03-14 17:38 . 2013-03-14 17:38 -------- d-----w- c:\program files (x86)\Microsoft WebMatrix

2013-03-14 17:37 . 2013-03-14 17:37 -------- d-----w- c:\program files (x86)\MySQL

2013-03-14 17:00 . 2013-03-14 17:00 -------- d-----w- c:\program files\Microsoft

2013-03-13 13:29 . 2013-03-13 13:29 16486616 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2013-03-11 18:05 . 2013-03-11 18:05 -------- d-----w- c:\users\601292\.ApacheDirectoryStudio

2013-03-11 18:02 . 2013-03-12 13:39 -------- d-----w- c:\program files\Apache Directory Studio

2013-03-07 17:58 . 2013-03-07 17:57 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-03-05 20:35 . 2013-03-05 20:35 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy

2013-03-05 19:08 . 2013-03-05 19:08 -------- d-----w- c:\program files\iPod

2013-03-05 19:08 . 2013-03-05 19:09 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-03-05 19:08 . 2013-03-05 19:09 -------- d-----w- c:\program files\iTunes

2013-03-05 19:08 . 2013-03-05 19:09 -------- d-----w- c:\program files (x86)\iTunes

2013-03-04 20:50 . 2013-03-04 20:50 -------- d-----w- c:\program files (x86)\InstantEyedropper

2013-03-04 15:46 . 2013-03-04 15:46 -------- d-----w- c:\users\601292\AppData\Roaming\app.Crunch

2013-03-04 15:44 . 2013-03-04 15:45 -------- d-----w- c:\program files (x86)\Crunch

2013-03-04 14:55 . 2013-03-04 14:55 -------- d-----w- c:\programdata\Sophos

2013-03-04 14:55 . 2013-03-04 14:55 73728 ----a-r- c:\users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe

2013-03-04 14:55 . 2013-03-04 14:55 73728 ----a-r- c:\users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe

2013-03-04 14:55 . 2013-03-04 14:55 73728 ----a-r- c:\users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe

2013-03-04 14:54 . 2013-03-04 14:54 -------- d-----w- c:\program files (x86)\Sophos

2013-03-01 09:53 . 2013-03-01 09:53 50688 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.HttpModules.dll

2013-03-01 09:52 . 2013-03-01 09:52 9913 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\Resources\TabStrip\scripts\tabstrip.js

2013-03-01 09:51 . 2013-03-01 09:51 26565 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\DesktopModules\Admin\Extensions\scripts\Gallery.js

2013-03-01 09:50 . 2013-03-01 09:50 11517952 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Telerik.Web.UI.Skins.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-03-27 19:14 . 2012-03-31 02:41 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin

2013-03-18 08:05 . 2012-02-07 17:45 72013344 ----a-w- c:\windows\system32\MRT.exe

2013-03-18 07:58 . 2013-01-09 18:33 3091488 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll

2013-03-18 07:38 . 2012-06-11 12:29 603552 ----a-w- c:\programdata\Microsoft\VWDExpress\10.0\1033\ResourceCache.dll

2013-03-13 13:29 . 2012-05-16 14:22 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-03-13 13:29 . 2012-05-16 14:22 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-03-07 17:57 . 2012-05-17 20:16 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

2013-03-07 17:57 . 2012-02-21 20:25 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-03-01 09:54 . 2013-03-01 09:54 65024 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.Professional.Authentication.ActiveDirectory.dll

2013-03-01 09:54 . 2013-03-01 09:54 26112 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.Providers.FiftyOneClientCapabilityProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 5632 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.Sitemap.BigSitemapProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 28160 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.SolpartMenuNavigationProvider.dll

2013-03-01 09:50 . 2013-03-01 09:50 229376 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\SolpartWebControls.dll

2013-02-12 05:45 . 2013-03-16 14:25 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-02-12 05:45 . 2013-03-16 14:25 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-02-12 05:45 . 2013-03-16 14:25 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-02-12 05:45 . 2013-03-16 14:25 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-02-12 04:48 . 2013-03-16 14:25 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-02-12 04:48 . 2013-03-16 14:25 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-02-08 03:20 . 2013-02-01 04:57 1133088 ----a-w- c:\programdata\Microsoft\VWDExpress\11.0\1033\ResourceCache.dll

2013-01-05 05:53 . 2013-02-13 01:52 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-01-05 05:00 . 2013-02-13 01:52 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-01-05 05:00 . 2013-02-13 01:52 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-01-04 05:46 . 2013-02-13 01:51 215040 ----a-w- c:\windows\system32\winsrv.dll

2013-01-04 04:51 . 2013-02-13 01:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll

2013-01-04 04:43 . 2013-02-13 01:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2013-01-04 03:26 . 2013-02-13 01:52 3153408 ----a-w- c:\windows\system32\win32k.sys

2013-01-04 02:47 . 2013-02-13 01:51 25600 ----a-w- c:\windows\SysWow64\setup16.exe

2013-01-04 02:47 . 2013-02-13 01:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe

2013-01-04 02:47 . 2013-02-13 01:51 2048 ----a-w- c:\windows\SysWow64\user.exe

2013-01-04 02:47 . 2013-02-13 01:51 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

2013-01-03 06:00 . 2013-02-13 01:51 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys

2013-01-03 06:00 . 2013-02-13 01:51 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]

@="{C5994560-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]

@="{C5994561-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]

@="{C5994562-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]

@="{C5994563-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]

@="{C5994564-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]

@="{C5994565-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]

@="{C5994566-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]

@="{C5994567-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]

@="{C5994568-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"googletalk"="c:\users\601292\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"DisplayFusion"="c:\program files (x86)\DisplayFusion\DisplayFusion.exe" [2013-02-11 7203712]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]

"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]

"MusicManager"="c:\users\601292\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-10-22 7356928]

"Novation Automap Server"="c:\program files (x86)\Novation\Automap\AutomapServer.exe" [2012-11-15 3129344]

"instanteyedropper"="c:\program files (x86)\InstantEyedropper\InstantEyedropper.exe" [2007-10-17 352256]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]

"IMSS"="c:\program files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe" [2011-01-17 112152]

"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"Communicator"="c:\program files (x86)\Microsoft Lync\communicator.exe" [2012-09-29 12105344]

"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-12-20 115560]

"SafeBootTrayManager"="c:\program files (x86)\SafeBoot Tray Manager\SbTrayManager.exe" [2012-09-11 69632]

"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2011-10-30 571392]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2012-05-23 371896]

"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]

"ArcSoft MediaImpression Monitor"="c:\program files (x86)\Kodak\MediaImpression\ArcMonitor.exe" [2010-11-12 73728]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2012-11-16 542104]

"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]

"AgentMonitor"="c:\program files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [2012-11-05 377800]

"Hercules DJ Series"="c:\program files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe" [2012-11-26 3413912]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]

.

c:\users\601292\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

GoZone iSync.lnk - c:\program files (x86)\GoZone\GoZone_iSync.exe [2012-8-28 436848]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]

Pageant.lnk - c:\program files (x86)\PuTTY\pageant.exe [2012-2-14 139264]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"EnableLinkedConnections"= 1 (0x1)

"DisableCAD"= 1 (0x1)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"SB_NoDispScrSavPage"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]

2012-04-02 11:49 18824 ----a-w- c:\windows\System32\PCANotify.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"midi1"=myokent.dll

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1340456155-3394922107-2961774907-286358\Scripts\Logon\0\0]

"Script"=login.bat

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]

@="Ad-Aware Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SophosVirusRemovalTool]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-09 123856]

R2 DisplayFusionService;DisplayFusionService;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe [2013-02-11 1243024]

R2 IBMWAS80Service - L07-FPYLFS1Node01;IBM WebSphere Application Server V8.0 - L07-FPYLFS1Node01;c:\program files (x86)\IBM\WebSphere\AppServer\bin\wasservice.exe IBMWAS80Service - L07-FPYLFS1Node01 [x]

R2 MouseWithoutBordersSvc;Mouse without Borders Service;c:\program files (x86)\Microsoft Garage\Mouse without Borders\MouseWithoutBordersSvc.exe [2012-10-24 27872]

R2 O2SDIOAssist;O2SDIOAssist;c:\windows\SysWOW64\srvany.exe [2003-04-18 8192]

R3 AltirisAgentProvider;AltirisAgentProvider;c:\program files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe [2012-10-01 408448]

R3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys [2012-10-30 238960]

R3 ConfigService;Altiris Deployment Solution - System Configuration;c:\program files\Altiris\Altiris Agent\Agents\Deployment\Agent\ConfigService.exe [2011-08-13 267368]

R3 DMService;Microsoft Forefront UAG Endpoint Component Manager;c:\windows\DOWNLO~1\DMService.exe [2012-05-17 468368]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]

R3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys [2012-10-30 306032]

R3 HDJMidi;Hercules DJ Console 4-Mx MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys [2012-10-30 271216]

R3 ipMIDI;nerds.de ipMIDI - Ethernet Midi Ports SvcDesc(WDM);c:\windows\system32\drivers\ipmidi.sys [2011-05-15 23040]

R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2010-11-19 80384]

R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2010-11-19 181248]

R3 NvnUsbAudio;Novation USB Audio Driver;c:\windows\system32\DRIVERS\nvnusbaudio.sys [2011-10-05 53080]

R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\O2MDFw7x64.sys [2011-01-03 72808]

R3 O2MDRRDR;O2MDRRDR;c:\windows\system32\drivers\O2MDRw7x64.sys [2011-01-03 74984]

R3 PVIS9;Pervasive Integration Server 9;c:\program files (x86)\Pervasive\Cosmos9\IntegrationServer\nt-service\bin\Wrapper.exe [2010-11-06 110592]

R3 PVIS9_64;Pervasive Integration Server 9 (64-bit);c:\program files\Pervasive\Cosmos9 (64-bit)\IntegrationServer\nt-service\bin\Wrapper.exe [2010-11-06 110592]

R3 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-11-13 1103392]

R3 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-11-13 1369624]

R3 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-11-13 168384]

R3 SophosVirusRemovalTool;Sophos Virus Removal Tool;c:\program files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [2013-01-17 153080]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 teVirtualMIDI64;teVirtualMIDI - Virtual MIDI Driver x64;c:\windows\system32\DRIVERS\teVirtualMIDI64.sys [2011-06-27 28160]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760]

R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 17408]

R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-07 1255736]

R4 Artifactory;Artifactory;c:\program files (x86)\artifactory\bin\wrapper.exe [2012-05-08 217088]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]

R4 RsFx0105;RsFx0105 Driver;c:\windows\system32\DRIVERS\RsFx0105.sys [2011-09-23 311144]

R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-23 431464]

S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2012-11-26 14456]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]

S0 SafeBoot;SafeBoot; [x]

S0 SBAlg;SBAlg; [x]

S0 SbFsLock;SbFsLock; [x]

S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]

S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]

S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2012-05-17 93272]

S1 RsvLock;RsvLock; [x]

S1 SbFlop;SbFlop; [x]

S1 SbRegFlt;SbRegFlt; [x]

S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 21504]

S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-11-22 1236368]

S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]

S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2012-12-03 2571704]

S2 dtpd;ShrewSoft DNS Proxy Daemon;c:\program files\ShrewSoft\VPN Client\dtpd.exe [2010-10-08 56592]

S2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [2012-09-06 18944]

S2 iked;ShrewSoft IKE Daemon;c:\program files\ShrewSoft\VPN Client\iked.exe [2010-10-08 957712]

S2 ipsecd;ShrewSoft IPSEC Daemon;c:\program files\ShrewSoft\VPN Client\ipsecd.exe [2010-10-08 697616]

S2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2012-10-04 6371192]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]

S2 SafeBootClientManager;SafeBoot Client Manager;c:\program files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe [2009-04-23 380988]

S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-09-20 3677000]

S2 uagqecsvc;Microsoft Forefront UAG Quarantine Enforcement Client;c:\program files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe [2010-04-09 149904]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]

S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448]

S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]

S3 AeXAgentSrvHost;AeXAgentSrvHost;c:\program files\Altiris\Altiris Agent\x86\AeXNSAgentHostSurrogate32.exe [2012-10-01 317312]

S3 automap;Automap MIDI Driver;c:\windows\system32\DRIVERS\automap.sys [2012-04-19 18776]

S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2011-07-08 75264]

S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2011-07-08 173568]

S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [2011-07-08 81408]

S3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys [2011-07-08 38440]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 138912]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]

S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]

S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]

S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7x64.sys [2011-03-23 83560]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

Contents of the 'Scheduled Tasks' folder

.

2013-03-30 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 13:29]

.

2013-03-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1340456155-3394922107-2961774907-286358Core.job

- c:\users\601292\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 15:57]

.

2013-03-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1340456155-3394922107-2961774907-286358UA.job

- c:\users\601292\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 15:57]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]

@="{C5994560-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]

@="{C5994561-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]

@="{C5994562-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]

@="{C5994563-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]

@="{C5994564-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]

@="{C5994565-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]

@="{C5994566-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]

@="{C5994567-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]

@="{C5994568-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-07-20 611192]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-25 525312]

"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]

"LogiScrollApp"="c:\program files\Logitech\FlowScroll\KhalScroll.exe" [2012-02-08 166680]

"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]

"TortoiseHgOverlayIconServer"="c:\program files\TortoiseHg\TortoiseHgOverlayServer.exe" [2012-06-09 47616]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-28 167704]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-28 392472]

"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-28 416024]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://bluroom.luxottica.com/en/

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = <-loopback>

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

LSP: %SystemRoot%\system32\vsocklib.dll

Trusted Zone: dell.com

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{36D985EE-299C-4F92-B0C6-598BFA1558CA}: NameServer = 10.80.179.20,10.80.224.20

DPF: {FCADE536-93F5-4577-80A3-E7C32FAC4C7D} - hxxp://atl-hpqsapp01.lenscrafters.com:8080/qcbin/Spider10.cab

FF - ProfilePath - c:\users\601292\AppData\Roaming\Mozilla\Firefox\Profiles\22akjndi.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - ExtSQL: !HIDDEN! 2012-03-11 10:40; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

.

- - - - ORPHANS REMOVED - - - -

.

Wow6432Node-HKCU-Run-SafeBootTokWatch - c:\program files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe

Wow6432Node-HKLM-Run-SafeBootTokenWatcher - c:\program files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe

Notify-SDWinLogon - SDWinLogon.dll

SafeBoot-Symantec Antvirus

AddRemove-AltirisAgent - c:\program files (x86)\Altiris\Altiris Agent\aexnsagent.exe

AddRemove-{92F2A534-C3E4-4B18-BEBD-329F5E848C8B} - c:\program files (x86)\Altiris\Altiris Agent\aexnsagent.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsDepSvc]

"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\Altiris Agent]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\Communications]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\eXpress\NS Client]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]

"Version"=hex:6b,91,29,0e,8a,96,47,2c,b3,aa,10,a5,bf,a9,3e,3d,77,b4,0e,bb,07,

f0,33,66,56,0e,43,54,6e,ed,1c,13,56,a8,fb,59,4e,10,54,01,84,4d,73,53,30,a2,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-03-29 21:43:39

ComboFix-quarantined-files.txt 2013-03-30 01:43

.

Pre-Run: 19,645,554,688 bytes free

Post-Run: 19,327,090,688 bytes free

.

- - End Of File - - 8795E9A2182068F794CAEB591712A3BE

Link to post
Share on other sites

That error should have stopped now. Be sure and let me know if it didn't.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Link to post
Share on other sites

<p> </p>

<div>Malwarebytes Anti-Malware 1.70.0.1100</div>

<div>www.malwarebytes.org</div>

<div> </div>

<div>Database version: v2013.03.27.02</div>

<div> </div>

<div>Windows 7 Service Pack 1 x64 NTFS</div>

<div>Internet Explorer 10.0.9200.16521</div>

<div>601292 :: L07-5YNHLV1 [administrator]</div>

<div> </div>

<div>4/1/2013 9:18:18 AM</div>

<div>mbam-log-2013-04-01 (09-18-18).txt</div>

<div> </div>

<div>Scan type: Quick scan</div>

<div>Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM</div>

<div>Scan options disabled: P2P</div>

<div>Objects scanned: 369169</div>

<div>Time elapsed: 9 minute(s), </div>

<div> </div>

<div>Memory Processes Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Memory Modules Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Registry Keys Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Registry Values Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Registry Data Items Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Folders Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Files Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>(end)</div>

<div> </div>

Link to post
Share on other sites

<p> </p>

<div>Sorry for the terrible formatting on the last couple posts, Heres a better copy:</div>

<div> </div>

<div>Malwarebytes Anti-Malware 1.70.0.1100</div>

<div>www.malwarebytes.org</div>

<div> </div>

<div>Database version: v2013.03.27.02</div>

<div> </div>

<div>Windows 7 Service Pack 1 x64 NTFS</div>

<div>Internet Explorer 10.0.9200.16521</div>

<div>601292 :: L07-5YNHLV1 [administrator]</div>

<div> </div>

<div>4/1/2013 9:18:18 AM</div>

<div>mbam-log-2013-04-01 (09-18-18).txt</div>

<div> </div>

<div>Scan type: Quick scan</div>

<div>Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM</div>

<div>Scan options disabled: P2P</div>

<div>Objects scanned: 369169</div>

<div>Time elapsed: 9 minute(s), </div>

<div> </div>

<div>Memory Processes Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Memory Modules Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Registry Keys Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Registry Values Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Registry Data Items Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Folders Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>Files Detected: 0</div>

<div>(No malicious items detected)</div>

<div> </div>

<div>(end)</div>

<div> </div>

Link to post
Share on other sites

<p>And still getting the risk notifications from SEP:</p>

<p> </p>

<p> </p>

<div>Scan type: Auto-Protect Scan</div>

<div>Event: Risk Found!</div>

<div>Security risk detected: Trojan.Gen</div>

<div>File: C:\Users\601292\AppData\Local\Temp\DWH63AB.tmp</div>

<div>Location: C:\Users\601292\AppData\Local\Temp</div>

<div>Computer: L07-5YNHLV1</div>

<div>User: 601292</div>

<div>Action taken: Pending Side Effects Analysis : Access denied</div>

<div>Date found: Monday, April 01, 2013  9:46:17 AM</div>

Link to post
Share on other sites

Ok... it's rebuilding under a modified name.

  • Download RogueKiller and save it to your desktop.
  • Quit all other programs
  • Start RogueKiller.exe
  • Wait until the Prescan has finished ...
  • Click on Scan
    RGKRScan.png
  • Wait for the end of the scan
  • A report will be created on your desktop.
  • Click on the Delete button
    RGKRDelete.png
  • Next click on the ShortcutsFix
    RGKRShortcutsFix.png
  • another report will be created on your desktop.

Please post: All RKreport.txt text files located on your desktop.

Link to post
Share on other sites

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    ClearJavaCache::


  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
    CFScriptB-4.gif
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Link to post
Share on other sites

ComboFix 13-04-02.01 - 601292 04/03/2013 11:11:17.2.4 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.7338.4486 [GMT -4:00]

Running from: c:\users\601292\Desktop\ComboFix.exe

Command switches used :: c:\users\601292\Desktop\CFScript.txt

AV: Lavasoft Ad-Aware *Disabled/Outdated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}

AV: Symantec Endpoint Protection *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}

FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}

SP: Lavasoft Ad-Aware *Disabled/Outdated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}

SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

SP: Symantec Endpoint Protection *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((( Files Created from 2013-03-03 to 2013-04-03 )))))))))))))))))))))))))))))))

.

.

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\TEMP\AppData\Local\temp

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\HydraApplicationPool\AppData\Local\temp

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\ASP.NET v4.0\AppData\Local\temp

2013-04-03 15:19 . 2013-04-03 15:19 -------- d-----w- c:\users\Administrator\AppData\Local\temp

2013-04-02 18:15 . 2013-04-02 18:15 -------- d-----w- C:\SyncMyRide

2013-04-02 02:18 . 2013-04-02 02:18 -------- d-----w- c:\windows\LastGood

2013-04-02 02:00 . 2013-04-02 02:00 -------- d-----w- c:\users\601292\AppData\Roaming\com.adobe.DC3Module.AdobeADC

2013-04-01 18:02 . 2013-04-01 18:02 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS

2013-04-01 18:02 . 2013-04-01 18:02 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS

2013-04-01 18:02 . 2013-04-01 18:02 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS

2013-04-01 18:02 . 2013-04-01 18:02 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS

2013-04-01 18:02 . 2013-04-01 18:02 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS

2013-04-01 18:02 . 2013-04-01 18:02 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS

2013-04-01 18:02 . 2013-04-01 18:02 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS

2013-04-01 18:02 . 2013-04-01 18:02 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS

2013-04-01 18:02 . 2013-04-01 18:02 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS

2013-04-01 18:02 . 2013-04-01 18:02 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS

2013-04-01 18:02 . 2013-04-01 18:02 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS

2013-04-01 18:02 . 2013-04-01 18:02 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS

2013-04-01 18:01 . 2013-04-01 18:01 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS

2013-04-01 18:01 . 2013-04-01 18:01 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS

2013-04-01 18:01 . 2013-04-01 18:01 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS

2013-04-01 18:01 . 2013-04-01 18:01 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS

2013-04-01 18:01 . 2013-04-01 18:01 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS

2013-03-27 16:53 . 2013-03-27 16:53 -------- d-----w- c:\users\ASP.NET v4.0\AppData\Local\CrashDumps

2013-03-25 18:20 . 2013-03-25 18:20 -------- d-----w- c:\users\601292\AppData\Roaming\HPAppData

2013-03-25 17:21 . 2013-02-17 05:40 28672 ----a-w- c:\windows\system32\IEUDINIT.EXE

2013-03-25 17:14 . 2013-03-25 17:14 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-03-20 17:29 . 2013-03-20 17:29 -------- d-----w- c:\users\601292\AppData\Local\Telerik_AD

2013-03-19 15:16 . 2013-04-01 18:58 -------- d-----w- C:\logs

2013-03-18 15:07 . 2013-03-18 15:07 -------- d-----w- c:\users\601292\Lync Recordings

2013-03-18 12:56 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys

2013-03-18 07:07 . 2013-03-18 07:07 -------- d-sh--w- c:\windows\system32\%APPDATA%

2013-03-14 17:43 . 2013-03-14 17:43 -------- d-----w- c:\program files (x86)\code4ward.net

2013-03-14 17:38 . 2013-03-14 17:38 -------- d-----w- c:\program files (x86)\Microsoft WebMatrix

2013-03-14 17:37 . 2013-03-14 17:37 -------- d-----w- c:\program files (x86)\MySQL

2013-03-14 17:00 . 2013-03-14 17:00 -------- d-----w- c:\program files\Microsoft

2013-03-13 13:29 . 2013-03-13 13:29 16486616 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe

2013-03-11 18:05 . 2013-03-11 18:05 -------- d-----w- c:\users\601292\.ApacheDirectoryStudio

2013-03-11 18:02 . 2013-03-12 13:39 -------- d-----w- c:\program files\Apache Directory Studio

2013-03-07 17:58 . 2013-03-07 17:57 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-03-05 20:35 . 2013-03-05 20:35 -------- d-----w- c:\program files\Common Files\PACE Anti-Piracy

2013-03-05 19:08 . 2013-03-05 19:08 -------- d-----w- c:\program files\iPod

2013-03-05 19:08 . 2013-03-05 19:09 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69

2013-03-05 19:08 . 2013-03-05 19:09 -------- d-----w- c:\program files\iTunes

2013-03-05 19:08 . 2013-03-05 19:09 -------- d-----w- c:\program files (x86)\iTunes

2013-03-04 20:50 . 2013-03-04 20:50 -------- d-----w- c:\program files (x86)\InstantEyedropper

2013-03-04 15:46 . 2013-03-04 15:46 -------- d-----w- c:\users\601292\AppData\Roaming\app.Crunch

2013-03-04 15:44 . 2013-03-04 15:45 -------- d-----w- c:\program files (x86)\Crunch

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-04-02 01:57 . 2012-05-16 14:22 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-04-02 01:57 . 2012-05-16 14:22 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-04-01 18:00 . 2012-03-31 02:41 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin

2013-03-18 08:05 . 2012-02-07 17:45 72013344 ----a-w- c:\windows\system32\MRT.exe

2013-03-18 07:58 . 2013-01-09 18:33 3091488 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll

2013-03-18 07:38 . 2012-06-11 12:29 603552 ----a-w- c:\programdata\Microsoft\VWDExpress\10.0\1033\ResourceCache.dll

2013-03-07 17:57 . 2012-05-17 20:16 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

2013-03-07 17:57 . 2012-02-21 20:25 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-03-04 14:55 . 2013-03-04 14:55 73728 ----a-r- c:\users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe

2013-03-04 14:55 . 2013-03-04 14:55 73728 ----a-r- c:\users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe

2013-03-04 14:55 . 2013-03-04 14:55 73728 ----a-r- c:\users\601292\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe

2013-03-01 09:54 . 2013-03-01 09:54 65024 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.Professional.Authentication.ActiveDirectory.dll

2013-03-01 09:54 . 2013-03-01 09:54 65024 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.Professional.Authentication.ActiveDirectory.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Authentication.Twitter.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Authentication.LiveConnect.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Authentication.Google.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Authentication.Facebook.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Authentication.Twitter.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Authentication.LiveConnect.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Authentication.Google.dll

2013-03-01 09:54 . 2013-03-01 09:54 8192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Authentication.Facebook.dll

2013-03-01 09:54 . 2013-03-01 09:54 26112 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.Providers.FiftyOneClientCapabilityProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 26112 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.Providers.FiftyOneClientCapabilityProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 95232 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.RadEditorProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 95232 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.RadEditorProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 99840 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Web.DDRMenu.dll

2013-03-01 09:54 . 2013-03-01 09:54 99840 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Web.DDRMenu.dll

2013-03-01 09:54 . 2013-03-01 09:54 12288 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Web.Razor.dll

2013-03-01 09:54 . 2013-03-01 09:54 12288 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Web.Razor.dll

2013-03-01 09:54 . 2013-03-01 09:54 5632 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.Sitemap.BigSitemapProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 5632 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.Sitemap.BigSitemapProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 28160 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.SolpartMenuNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 28160 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.SolpartMenuNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 14848 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.ASP2MenuNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 14848 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.ASP2MenuNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 7168 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.DNNDropDownNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 7168 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.DNNDropDownNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 20992 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.DNNMenuNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 20992 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.DNNMenuNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 12800 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\DotNetNuke.DNNTreeNavigationProvider.dll

2013-03-01 09:54 . 2013-03-01 09:54 12800 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\DotNetNuke.DNNTreeNavigationProvider.dll

2013-03-01 09:53 . 2013-03-01 09:53 50688 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.HttpModules.dll

2013-03-01 09:53 . 2013-03-01 09:53 50688 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.HttpModules.dll

2013-03-01 09:53 . 2013-03-01 09:53 264192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Web.dll

2013-03-01 09:53 . 2013-03-01 09:53 264192 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Web.dll

2013-03-01 09:53 . 2013-03-01 09:53 2168832 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.dll

2013-03-01 09:53 . 2013-03-01 09:53 2168832 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.dll

2013-03-01 09:53 . 2013-03-01 09:53 35328 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Services.Syndication.dll

2013-03-01 09:53 . 2013-03-01 09:53 35328 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Services.Syndication.dll

2013-03-01 09:53 . 2013-03-01 09:53 30208 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Web.Client.dll

2013-03-01 09:53 . 2013-03-01 09:53 30208 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Web.Client.dll

2013-03-01 09:53 . 2013-03-01 09:53 23040 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\CountryListBox.dll

2013-03-01 09:53 . 2013-03-01 09:53 23040 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\CountryListBox.dll

2013-03-01 09:53 . 2013-03-01 09:53 16384 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Instrumentation.dll

2013-03-01 09:53 . 2013-03-01 09:53 16384 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Instrumentation.dll

2013-03-01 09:53 . 2013-03-01 09:53 102912 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\ClientDependency.Core.dll

2013-03-01 09:53 . 2013-03-01 09:53 102912 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\ClientDependency.Core.dll

2013-03-01 09:51 . 2013-03-01 09:51 13824 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\HtmlDiff.dll

2013-03-01 09:51 . 2013-03-01 09:51 13824 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\HtmlDiff.dll

2013-03-01 09:51 . 2013-03-01 09:51 74752 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\WebFormsMvp.dll

2013-03-01 09:51 . 2013-03-01 09:51 74752 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\WebFormsMvp.dll

2013-03-01 09:50 . 2013-03-01 09:50 11517952 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Telerik.Web.UI.Skins.dll

2013-03-01 09:50 . 2013-03-01 09:50 11517952 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Telerik.Web.UI.Skins.dll

2013-03-01 09:50 . 2013-03-01 09:50 17659392 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Telerik.Web.UI.dll

2013-03-01 09:50 . 2013-03-01 09:50 17659392 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Telerik.Web.UI.dll

2013-03-01 09:50 . 2013-03-01 09:50 73592 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\WebMatrix.WebData.dll

2013-03-01 09:50 . 2013-03-01 09:50 73592 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\WebMatrix.WebData.dll

2013-03-01 09:50 . 2013-03-01 09:50 73312 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Web.Http.WebHost.dll

2013-03-01 09:50 . 2013-03-01 09:50 73312 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Web.Http.WebHost.dll

2013-03-01 09:50 . 2013-03-01 09:50 66560 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\PetaPoco.dll

2013-03-01 09:50 . 2013-03-01 09:50 66560 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\PetaPoco.dll

2013-03-01 09:50 . 2013-03-01 09:50 495616 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.WebUtility.dll

2013-03-01 09:50 . 2013-03-01 09:50 495616 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.WebUtility.dll

2013-03-01 09:50 . 2013-03-01 09:50 45416 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Microsoft.Web.Infrastructure.dll

2013-03-01 09:50 . 2013-03-01 09:50 45416 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Microsoft.Web.Infrastructure.dll

2013-03-01 09:50 . 2013-03-01 09:50 41048 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Web.WebPages.Deployment.dll

2013-03-01 09:50 . 2013-03-01 09:50 41048 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Web.WebPages.Deployment.dll

2013-03-01 09:50 . 2013-03-01 09:50 39800 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Web.WebPages.Razor.dll

2013-03-01 09:50 . 2013-03-01 09:50 39800 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Web.WebPages.Razor.dll

2013-03-01 09:50 . 2013-03-01 09:50 38264 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\WebMatrix.Data.dll

2013-03-01 09:50 . 2013-03-01 09:50 38264 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\WebMatrix.Data.dll

2013-03-01 09:50 . 2013-03-01 09:50 374784 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Newtonsoft.Json.dll

2013-03-01 09:50 . 2013-03-01 09:50 374784 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Newtonsoft.Json.dll

2013-03-01 09:50 . 2013-03-01 09:50 323168 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Web.Http.dll

2013-03-01 09:50 . 2013-03-01 09:50 323168 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Web.Http.dll

2013-03-01 09:50 . 2013-03-01 09:50 283648 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.WebControls.dll

2013-03-01 09:50 . 2013-03-01 09:50 283648 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.WebControls.dll

2013-03-01 09:50 . 2013-03-01 09:50 276344 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Web.Razor.dll

2013-03-01 09:50 . 2013-03-01 09:50 276344 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Web.Razor.dll

2013-03-01 09:50 . 2013-03-01 09:50 24064 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Microsoft.ApplicationBlocks.Data.dll

2013-03-01 09:50 . 2013-03-01 09:50 24064 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Microsoft.ApplicationBlocks.Data.dll

2013-03-01 09:50 . 2013-03-01 09:50 238592 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\DotNetNuke.Log4Net.dll

2013-03-01 09:50 . 2013-03-01 09:50 238592 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\DotNetNuke.Log4Net.dll

2013-03-01 09:50 . 2013-03-01 09:50 229376 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\Providers\SolpartWebControls.dll

2013-03-01 09:50 . 2013-03-01 09:50 229376 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\Providers\SolpartWebControls.dll

2013-03-01 09:50 . 2013-03-01 09:50 204400 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Web.WebPages.dll

2013-03-01 09:50 . 2013-03-01 09:50 204400 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Web.WebPages.dll

2013-03-01 09:50 . 2013-03-01 09:50 180832 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Net.Http.dll

2013-03-01 09:50 . 2013-03-01 09:50 180832 ------w- c:\users\601292\AppData\Roaming\Microsoft\VisualStudio\10.0\ProjectTemplatesCache\Visual Web Developer\CSharp\DotNetNuke.zip\bin\System.Net.Http.dll

2013-03-01 09:50 . 2013-03-01 09:50 168544 ------w- c:\users\601292\AppData\Roaming\Microsoft\VWDExpress\11.0\ProjectTemplatesCache\Visual Web Developer\DotNetNuke.zip\bin\System.Net.Http.Formatting.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]

@="{C5994560-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]

@="{C5994561-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]

@="{C5994562-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]

@="{C5994563-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]

@="{C5994564-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]

@="{C5994565-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]

@="{C5994566-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]

@="{C5994567-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]

@="{C5994568-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"googletalk"="c:\users\601292\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]

"DisplayFusion"="c:\program files (x86)\DisplayFusion\DisplayFusion.exe" [2013-02-11 7203712]

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]

"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]

"Novation Automap Server"="c:\program files (x86)\Novation\Automap\AutomapServer.exe" [2012-11-15 3129344]

"instanteyedropper"="c:\program files (x86)\InstantEyedropper\InstantEyedropper.exe" [2007-10-17 352256]

"SafeBootTokWatch"="c:\program files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe" [2013-04-01 172092]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]

"IMSS"="c:\program files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe" [2011-01-17 112152]

"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]

"Communicator"="c:\program files (x86)\Microsoft Lync\communicator.exe" [2012-09-29 12105344]

"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-12-20 115560]

"SafeBootTrayManager"="c:\program files (x86)\SafeBoot Tray Manager\SbTrayManager.exe" [2012-09-11 69632]

"Nikon Message Center 2"="c:\program files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe" [2011-10-30 571392]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2012-05-23 371896]

"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]

"ArcSoft MediaImpression Monitor"="c:\program files (x86)\Kodak\MediaImpression\ArcMonitor.exe" [2010-11-12 73728]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]

"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2012-11-16 542104]

"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]

"AgentMonitor"="c:\program files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [2012-11-05 377800]

"Hercules DJ Series"="c:\program files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe" [2012-11-26 3413912]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]

.

c:\users\601292\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

GoZone iSync.lnk - c:\program files (x86)\GoZone\GoZone_iSync.exe [2012-8-28 436848]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]

Pageant.lnk - c:\program files (x86)\PuTTY\pageant.exe [2012-2-14 139264]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"EnableLinkedConnections"= 1 (0x1)

"DisableCAD"= 1 (0x1)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"SB_NoDispScrSavPage"= 1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]

2012-04-02 11:49 18824 ----a-w- c:\windows\System32\PCANotify.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"midi1"=myokent.dll

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1340456155-3394922107-2961774907-286358\Scripts\Logon\0\0]

"Script"=login.bat

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]

@="Ad-Aware Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SophosVirusRemovalTool]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

@="Service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-09 123856]

R2 DisplayFusionService;DisplayFusionService;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe [2013-02-11 1243024]

R2 IBMWAS80Service - L07-FPYLFS1Node01;IBM WebSphere Application Server V8.0 - L07-FPYLFS1Node01;c:\program files (x86)\IBM\WebSphere\AppServer\bin\wasservice.exe IBMWAS80Service - L07-FPYLFS1Node01 [x]

R2 MouseWithoutBordersSvc;Mouse without Borders Service;c:\program files (x86)\Microsoft Garage\Mouse without Borders\MouseWithoutBordersSvc.exe [2012-10-24 27872]

R2 O2SDIOAssist;O2SDIOAssist;c:\windows\SysWOW64\srvany.exe [2003-04-18 8192]

R2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [2012-09-20 3677000]

R3 AltirisAgentProvider;AltirisAgentProvider;c:\program files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe [2012-10-01 408448]

R3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys [2012-10-30 238960]

R3 ConfigService;Altiris Deployment Solution - System Configuration;c:\program files\Altiris\Altiris Agent\Agents\Deployment\Agent\ConfigService.exe [2011-08-13 267368]

R3 DMService;Microsoft Forefront UAG Endpoint Component Manager;c:\windows\DOWNLO~1\DMService.exe [2012-05-17 468368]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]

R3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys [2012-10-30 306032]

R3 HDJMidi;Hercules DJ Console 4-Mx MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys [2012-10-30 271216]

R3 ipMIDI;nerds.de ipMIDI - Ethernet Midi Ports SvcDesc(WDM);c:\windows\system32\drivers\ipmidi.sys [2011-05-15 23040]

R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2010-11-19 80384]

R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2010-11-19 181248]

R3 NvnUsbAudio;Novation USB Audio Driver;c:\windows\system32\DRIVERS\nvnusbaudio.sys [2011-10-05 53080]

R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\O2MDFw7x64.sys [2011-01-03 72808]

R3 O2MDRRDR;O2MDRRDR;c:\windows\system32\drivers\O2MDRw7x64.sys [2011-01-03 74984]

R3 PVIS9;Pervasive Integration Server 9;c:\program files (x86)\Pervasive\Cosmos9\IntegrationServer\nt-service\bin\Wrapper.exe [2010-11-06 110592]

R3 PVIS9_64;Pervasive Integration Server 9 (64-bit);c:\program files\Pervasive\Cosmos9 (64-bit)\IntegrationServer\nt-service\bin\Wrapper.exe [2010-11-06 110592]

R3 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2012-11-13 1103392]

R3 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2012-11-13 1369624]

R3 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2012-11-13 168384]

R3 SophosVirusRemovalTool;Sophos Virus Removal Tool;c:\program files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [2013-01-17 153080]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 teVirtualMIDI64;teVirtualMIDI - Virtual MIDI Driver x64;c:\windows\system32\DRIVERS\teVirtualMIDI64.sys [2011-06-27 28160]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760]

R3 vnet;Shrew Soft Virtual Adapter;c:\windows\system32\DRIVERS\virtualnet.sys [2010-09-02 17408]

R3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-07 1255736]

R4 Artifactory;Artifactory;c:\program files (x86)\artifactory\bin\wrapper.exe [2012-05-08 217088]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]

R4 RsFx0105;RsFx0105 Driver;c:\windows\system32\DRIVERS\RsFx0105.sys [2011-09-23 311144]

R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-23 431464]

S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys [2012-11-26 14456]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]

S0 SafeBoot;SafeBoot; [x]

S0 SBAlg;SBAlg; [x]

S0 SbFsLock;SbFsLock; [x]

S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616]

S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [2011-08-08 116336]

S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys [2012-05-17 93272]

S1 RsvLock;RsvLock; [x]

S1 SbFlop;SbFlop; [x]

S1 SbRegFlt;SbRegFlt; [x]

S1 vflt;Shrew Soft Lightweight Filter;c:\windows\system32\DRIVERS\vfilter.sys [2010-09-02 21504]

S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [2012-11-22 1236368]

S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]

S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2012-12-03 2571704]

S2 dtpd;ShrewSoft DNS Proxy Daemon;c:\program files\ShrewSoft\VPN Client\dtpd.exe [2010-10-08 56592]

S2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE [2012-09-06 18944]

S2 iked;ShrewSoft IKE Daemon;c:\program files\ShrewSoft\VPN Client\iked.exe [2010-10-08 957712]

S2 ipsecd;ShrewSoft IPSEC Daemon;c:\program files\ShrewSoft\VPN Client\ipsecd.exe [2010-10-08 697616]

S2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2012-10-04 6371192]

S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]

S2 SafeBootClientManager;SafeBoot Client Manager;c:\program files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe [2009-04-23 380988]

S2 uagqecsvc;Microsoft Forefront UAG Quarantine Enforcement Client;c:\program files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe [2010-04-09 149904]

S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]

S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-30 846448]

S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760]

S3 AeXAgentSrvHost;AeXAgentSrvHost;c:\program files\Altiris\Altiris Agent\x86\AeXNSAgentHostSurrogate32.exe [2012-10-01 317312]

S3 automap;Automap MIDI Driver;c:\windows\system32\DRIVERS\automap.sys [2012-04-19 18776]

S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2011-07-08 75264]

S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2011-07-08 173568]

S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [2011-07-08 81408]

S3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys [2011-07-08 38440]

S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 138912]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]

S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys [2011-09-02 76056]

S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys [2011-09-02 15128]

S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7x64.sys [2011-03-23 83560]

.

.

--- Other Services/Drivers In Memory ---

.

*Deregistered* - PROCEXP152

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

.

Contents of the 'Scheduled Tasks' folder

.

2013-04-03 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 01:57]

.

2013-04-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1340456155-3394922107-2961774907-286358Core.job

- c:\users\601292\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 15:57]

.

2013-04-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1340456155-3394922107-2961774907-286358UA.job

- c:\users\601292\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-14 15:57]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]

@="{C5994560-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]

@="{C5994561-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]

@="{C5994562-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]

@="{C5994563-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]

@="{C5994564-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]

@="{C5994565-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]

@="{C5994566-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]

@="{C5994567-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]

@="{C5994568-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]

2011-06-13 14:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Apoint"="c:\program files\DellTPad\Apoint.exe" [2011-07-20 611192]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-25 525312]

"FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704]

"LogiScrollApp"="c:\program files\Logitech\FlowScroll\KhalScroll.exe" [2012-02-08 166680]

"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]

"TortoiseHgOverlayIconServer"="c:\program files\TortoiseHg\TortoiseHgOverlayServer.exe" [2012-06-09 47616]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-28 167704]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-28 392472]

"Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-28 416024]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://bluroom.luxottica.com/en/

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = <-loopback>

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

LSP: %SystemRoot%\system32\vsocklib.dll

Trusted Zone: dell.com

TCP: DhcpNameServer = 8.8.8.8 8.8.4.4

TCP: Interfaces\{36D985EE-299C-4F92-B0C6-598BFA1558CA}: NameServer = 10.80.179.20,10.80.224.20

DPF: {FCADE536-93F5-4577-80A3-E7C32FAC4C7D} - hxxp://atl-hpqsapp01.lenscrafters.com:8080/qcbin/Spider10.cab

FF - ProfilePath - c:\users\601292\AppData\Roaming\Mozilla\Firefox\Profiles\22akjndi.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - ExtSQL: !HIDDEN! 2012-03-11 10:40; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

.

- - - - ORPHANS REMOVED - - - -

.

Notify-SDWinLogon - SDWinLogon.dll

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsDepSvc]

"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\Altiris Agent]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\Communications]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Altiris\eXpress\NS Client]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]

"Version"=hex:6b,91,29,0e,8a,96,47,2c,b3,aa,10,a5,bf,a9,3e,3d,77,b4,0e,bb,07,

f0,33,66,56,0e,43,54,6e,ed,1c,13,56,a8,fb,59,4e,10,54,01,84,4d,73,53,30,a2,\

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-04-03 11:22:41

ComboFix-quarantined-files.txt 2013-04-03 15:22

ComboFix2.txt 2013-03-30 01:43

.

Pre-Run: 19,698,847,744 bytes free

Post-Run: 19,478,224,896 bytes free

.

- - End Of File - - 5FF91F00E2CD7148156984733C8498B2

Link to post
Share on other sites

Just got another warning from SEP:

Scan type: Auto-Protect Scan

Event: Risk Found!

Security risk detected: Trojan.Gen

File: C:\Users\601292\AppData\Local\Temp\DWH4AF3.tmp

Location: Quarantine

Computer: L07-5YNHLV1

User: 601292

Action taken: Quarantine succeeded : Access denied

Date found: Wednesday, April 03, 2013 11:48:23 AM

Link to post
Share on other sites

I'm just not seeing what is creating that file.

Let's get a different look:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
      Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Link to post
Share on other sites

You didn't get extras.txt because you only get that the first time you run the program... and according to your log, this is the second time your ran it.

There is no sign of that .tmp file in the log... but let's tidy up a little.

Double click on OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :

:Processes
explorer.exe

:OTL
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
@Alternate Data Stream - 938 bytes -> C:\Program Files\Common Files\Microsoft Shared:KuXqYF4Uag77Y6KoDuGnC
@Alternate Data Stream - 1175 bytes -> C:\ProgramData\Microsoft:l5MQOA5kG4YzEO6IXFyc5ZLE
@Alternate Data Stream - 1174 bytes -> C:\ProgramData\Microsoft:IbWrSWGFjmGPJw62lzQalndYK
@Alternate Data Stream - 1149 bytes -> C:\Users\601292\AppData\Local\Temp:tfVERGOcJypckHsVZI2NG514wX
@Alternate Data Stream - 1135 bytes -> C:\ProgramData\Microsoft:4rKdxOg2NySmYPUdTqRQUi
@Alternate Data Stream - 1115 bytes -> C:\ProgramData\Microsoft:oazP7W6IJzTcTQJWW9d0OtC7
@Alternate Data Stream - 1093 bytes -> C:\ProgramData\Microsoft:UAAJf2aqUdUR2XYgnsA
@Alternate Data Stream - 1053 bytes -> C:\Users\601292\AppData\Local\Temp:oAMTI1Eflloki8LViKYr
@Alternate Data Stream - 1026 bytes -> C:\Users\601292\AppData\Local\A9tyxEPMW8H8:bi92T0tem4PfxpPFwwLuOT
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top

  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer

Please post the OTL log.

Link to post
Share on other sites

<p> </p>

<div>When it rebooted there was a bunch of SEP alerts but then it went quiet.  I'm guessing it was from the rootkit (or whatever this is) regenerating.</div>

<div> </div>

<div>All processes killed</div>

<div>========== PROCESSES ==========</div>

<div>No active process named explorer.exe was found!</div>

<div>========== OTL ==========</div>

<div>Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@java.com/JavaPlugin\ not found.</div>

<div>Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.</div>

<div>Starting removal of ActiveX control {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}</div>

<div>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\ deleted successfully.</div>

<div>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\ deleted successfully.</div>

<div>Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\ deleted successfully.</div>

<div>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\ not found.</div>

<div>Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}\ not found.</div>

<div>ADS C:\Program Files\Common Files\Microsoft Shared:KuXqYF4Uag77Y6KoDuGnC deleted successfully.</div>

<div>ADS C:\ProgramData\Microsoft:l5MQOA5kG4YzEO6IXFyc5ZLE deleted successfully.</div>

<div>ADS C:\ProgramData\Microsoft:IbWrSWGFjmGPJw62lzQalndYK deleted successfully.</div>

<div>ADS C:\Users\601292\AppData\Local\Temp:tfVERGOcJypckHsVZI2NG514wX deleted successfully.</div>

<div>ADS C:\ProgramData\Microsoft:4rKdxOg2NySmYPUdTqRQUi deleted successfully.</div>

<div>ADS C:\ProgramData\Microsoft:oazP7W6IJzTcTQJWW9d0OtC7 deleted successfully.</div>

<div>ADS C:\ProgramData\Microsoft:UAAJf2aqUdUR2XYgnsA deleted successfully.</div>

<div>ADS C:\Users\601292\AppData\Local\Temp:oAMTI1Eflloki8LViKYr deleted successfully.</div>

<div>ADS C:\Users\601292\AppData\Local\A9tyxEPMW8H8:bi92T0tem4PfxpPFwwLuOT deleted successfully.</div>

<div>========== COMMANDS ==========</div>

<div> </div>

<div>[EMPTYTEMP]</div>

<div> </div>

<div>User: 601292</div>

<div>->Temp folder emptied: 23603117 bytes</div>

<div>->Temporary Internet Files folder emptied: 749138 bytes</div>

<div>->Java cache emptied: 0 bytes</div>

<div>->FireFox cache emptied: 24224034 bytes</div>

<div>->Google Chrome cache emptied: 273942944 bytes</div>

<div>->Flash cache emptied: 660 bytes</div>

<div> </div>

<div>User: Administrator</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 0 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: All Users</div>

<div> </div>

<div>User: ASP.NET v4.0</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 0 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: Classic .NET AppPool</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 0 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: Default</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 67 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: Default User</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 0 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: DefaultAppPool</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 0 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: HydraApplicationPool</div>

<div>->Temp folder emptied: 0 bytes</div>

<div>->Temporary Internet Files folder emptied: 0 bytes</div>

<div>->Flash cache emptied: 0 bytes</div>

<div> </div>

<div>User: Public</div>

<div>->Temp folder emptied: 0 bytes</div>

<div> </div>

<div>User: TEMP</div>

<div>->Temp folder emptied: 0 bytes</div>

<div> </div>

<div>%systemdrive% .tmp files removed: 0 bytes</div>

<div>%systemroot% .tmp files removed: 0 bytes</div>

<div>%systemroot%\System32 .tmp files removed: 0 bytes</div>

<div>%systemroot%\System32 (64bit) .tmp files removed: 0 bytes</div>

<div>%systemroot%\System32\drivers .tmp files removed: 0 bytes</div>

<div>Windows Temp folder emptied: 166668 bytes</div>

<div>%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 90674 bytes</div>

<div>RecycleBin emptied: 7185989 bytes</div>

<div> </div>

<div>Total Files Cleaned = 315.00 mb</div>

<div> </div>

<div> </div>

<div>OTL by OldTimer - Version 3.2.69.0 log created on 04052013_095244</div>

<div> </div>

<div>Files\Folders moved on Reboot...</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH1605.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH172F.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH17D9.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH430F.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH4917.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH50F3.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH5132.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH68C8.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH6963.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH6A4D.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH6ACB.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH8435.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH89B0.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH94C7.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWH9D7F.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHA9A0.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHC411.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHCBFD.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHDBC6.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHE7D7.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHE803.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHF762.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHFB20.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHFE6E.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHFF99.tmp not found!</div>

<div>File\Folder C:\Users\601292\AppData\Local\Temp\DWHFFDB.tmp not found!</div>

<div>C:\Users\601292\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.</div>

<div>C:\Users\601292\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.</div>

<div>File move failed. C:\Windows\temp\vmware-SYSTEM\vmauthd.log scheduled to be moved on reboot.</div>

<div>C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-3640.log moved successfully.</div>

<div>File\Folder C:\Windows\temp\etilqs_chNUf7D9vJNBCWGOiUOi not found!</div>

<div>File\Folder C:\Windows\temp\etilqs_chNUf7D9vJNBCWGOiUOi-journal not found!</div>

<div>File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.</div>

<div> </div>

<div>PendingFileRenameOperations files...</div>

<div> </div>

<div>Registry entries deleted on Reboot...</div>

<div> </div>

Link to post
Share on other sites

My (very) uneducated guess is that it has inserted itself into the MBR, so that it loads (and hides) itself at a very low level. I have done a couple of MBR scans in on my own a couple weeks ago and i do see reports of "Umknown MBR code" when running aswMBR, but i havent taken any action on it for 2 reasons:

1. My drive is encrypted and the encryption loads very early in the boot sequence (pretty much right after the bios, as best i can tell). My guess is that the Unknown MBR code may be where the decryption driver loads.

2. I'm petrified to touch the MBR as I have been burned by that in the past. I'm particularly wary of it as even if the code that it is reporting is indeed the rootkit code, i am leary to take any action as it may kill anything that the encryption may have added along with it.

Not sure if this makes any sense to you or is totally off base. OS and hardware are not my wheelhouse, I'm more of a webapp and database kinda guy.

Casey

Link to post
Share on other sites

Dell mbr's are non standard so can be "good" and still get that flag.

Can you please post the log from your aswMBR scan?

You will also notice another file was created on the desktop named MBR.dat when you ran that scan. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

Link to post
Share on other sites

I actually just ran it again a few minutes preemptively :)

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software

Run date: 2013-04-05 10:10:33

-----------------------------

10:10:33.016 OS Version: Windows x64 6.1.7601 Service Pack 1

10:10:33.016 Number of processors: 4 586 0x2A07

10:10:33.017 ComputerName: L07-5YNHLV1 UserName: 601292

10:10:37.269 Initialize success

10:27:14.085 AVAST engine defs: 13040500

10:40:40.167 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0

10:40:40.173 Disk 0 Vendor: WDC_WD2500BEKT-75PVMT1 01.01A01 Size: 238475MB BusType: 11

10:40:40.197 Disk 0 MBR read successfully

10:40:40.202 Disk 0 MBR scan

10:40:40.238 Disk 0 unknown MBR code

10:40:40.241 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63

10:40:40.255 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 81920

10:40:40.267 Disk 0 Partition 3 00 07 HPFS/NTFS 238334 MB offset 286720

10:40:40.276 Disk 0 scanning C:\Windows\system32\drivers

10:40:40.280 Service scanning

10:41:29.713 Modules scanning

10:41:29.730 Disk 0 trace - called modules:

10:41:29.746 ntoskrnl.exe CLASSPNP.SYS disk.sys stdcfltn.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys

10:41:29.753 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007222060]

10:41:29.759 3 CLASSPNP.SYS[fffff8800100143f] -> nt!IofCallDriver -> [0xfffffa8006ea79c0]

10:41:29.765 5 stdcfltn.sys[fffff880017e1c52] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8006b5b060]

10:41:31.182 AVAST engine scan C:\Windows

10:41:31.221 AVAST engine scan C:\Windows\system32

10:41:31.233 AVAST engine scan C:\Windows\system32\drivers

10:41:31.243 AVAST engine scan C:\Users\601292

10:41:31.254 AVAST engine scan C:\ProgramData

10:41:31.263 Scan finished successfully

10:49:51.532 Disk 0 MBR has been saved successfully to "C:\Users\601292\Desktop\MBR.dat"

10:49:51.538 The log file has been saved successfully to "C:\Users\601292\Desktop\aswMBR.txt"

Link to post
Share on other sites

Your MBR appears to be fine.

Let's run another tool. I'm not expecting it to find anything... but let's give it a shot.

Download the latest version of TDSSKiller from here and save it to your Desktop.

  1. Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    tdss_1.jpg
  2. Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
    tdss_2.jpg
  3. Click the Start Scan button.
    tdss_3.jpg
  4. If a suspicious object is detected, the default action will be Skip, click on Continue.
    tdss_4.jpg
  5. If malicious objects are found, they will show in the Scan results and offer three (3) options.
  6. Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    tdss_5.jpg
  7. Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.

Link to post
Share on other sites

<p>Nope, nothing found.</p>

<p> </p>

<p> </p>

<div>13:22:22.0990 7032  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42</div>

<div>13:22:23.0252 7032  ============================================================</div>

<div>13:22:23.0252 7032  Current date / time: 2013/04/05 13:22:23.0252</div>

<div>13:22:23.0252 7032  SystemInfo:</div>

<div>13:22:23.0252 7032  </div>

<div>13:22:23.0253 7032  OS Version: 6.1.7601 ServicePack: 1.0</div>

<div>13:22:23.0253 7032  Product type: Workstation</div>

<div>13:22:23.0253 7032  ComputerName: L07-5YNHLV1</div>

<div>13:22:23.0261 7032  UserName: 601292</div>

<div>13:22:23.0261 7032  Windows directory: C:\Windows</div>

<div>13:22:23.0261 7032  System windows directory: C:\Windows</div>

<div>13:22:23.0261 7032  Running under WOW64</div>

<div>13:22:23.0261 7032  Processor architecture: Intel x64</div>

<div>13:22:23.0261 7032  Number of processors: 4</div>

<div>13:22:23.0261 7032  Page size: 0x1000</div>

<div>13:22:23.0262 7032  Boot type: Normal boot</div>

<div>13:22:23.0262 7032  ============================================================</div>

<div>13:22:24.0630 7032  Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040</div>

<div>13:22:24.0639 7032  ============================================================</div>

<div>13:22:24.0639 7032  \Device\Harddisk0\DR0:</div>

<div>13:22:24.0640 7032  MBR partitions:</div>

<div>13:22:24.0640 7032  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x32000</div>

<div>13:22:24.0640 7032  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x46000, BlocksNum 0x1D17F170</div>

<div>13:22:24.0640 7032  ============================================================</div>

<div>13:22:24.0651 7032  Initialize success</div>

<div>13:22:24.0651 7032  ============================================================</div>

<div>13:23:08.0561 6428  ============================================================</div>

<div>13:23:08.0561 6428  Scan started</div>

<div>13:23:08.0561 6428  Mode: Manual; SigCheck; TDLFS; </div>

<div>13:23:08.0561 6428  ============================================================</div>

<div>13:23:08.0627 6428  ================ Scan system memory ========================</div>

<div>13:23:08.0627 6428  System memory - ok</div>

<div>13:23:08.0629 6428  ================ Scan services =============================</div>

<div>13:23:08.0678 6428  1394ohci - ok</div>

<div>13:23:08.0698 6428  Acceler - ok</div>

<div>13:23:08.0707 6428  ACDaemon - ok</div>

<div>13:23:08.0715 6428  ACPI - ok</div>

<div>13:23:08.0720 6428  AcpiPmi - ok</div>

<div>13:23:08.0730 6428  Ad-Aware Service - ok</div>

<div>13:23:08.0741 6428  AdobeARMservice - ok</div>

<div>13:23:08.0753 6428  AdobeFlashPlayerUpdateSvc - ok</div>

<div>13:23:08.0764 6428  adp94xx - ok</div>

<div>13:23:08.0769 6428  adpahci - ok</div>

<div>13:23:08.0775 6428  adpu320 - ok</div>

<div>13:23:08.0783 6428  AeLookupSvc - ok</div>

<div>13:23:08.0788 6428  AESTFilters - ok</div>

<div>13:23:08.0793 6428  AeXAgentSrvHost - ok</div>

<div>13:23:08.0803 6428  AeXNSClient - ok</div>

<div>13:23:08.0807 6428  Afc - ok</div>

<div>13:23:08.0813 6428  AFD - ok</div>

<div>13:23:08.0817 6428  agp440 - ok</div>

<div>13:23:08.0828 6428  ALG - ok</div>

<div>13:23:08.0831 6428  aliide - ok</div>

<div>13:23:08.0833 6428  AltirisAgentProvider - ok</div>

<div>13:23:08.0836 6428  amdide - ok</div>

<div>13:23:08.0839 6428  AmdK8 - ok</div>

<div>13:23:08.0841 6428  AmdPPM - ok</div>

<div>13:23:08.0854 6428  amdsata - ok</div>

<div>13:23:08.0862 6428  amdsbs - ok</div>

<div>13:23:08.0865 6428  amdxata - ok</div>

<div>13:23:08.0875 6428  ApfiltrService - ok</div>

<div>13:23:08.0889 6428  AppHostSvc - ok</div>

<div>13:23:08.0893 6428  AppID - ok</div>

<div>13:23:08.0895 6428  AppIDSvc - ok</div>

<div>13:23:08.0897 6428  Appinfo - ok</div>

<div>13:23:08.0902 6428  Apple Mobile Device - ok</div>

<div>13:23:08.0918 6428  AppMgmt - ok</div>

<div>13:23:08.0922 6428  arc - ok</div>

<div>13:23:08.0925 6428  arcsas - ok</div>

<div>13:23:08.0941 6428  Artifactory - ok</div>

<div>13:23:08.0955 6428  aspnet_state - ok</div>

<div>13:23:08.0958 6428  AsyncMac - ok</div>

<div>13:23:08.0961 6428  atapi - ok</div>

<div>13:23:08.0964 6428  AudioEndpointBuilder - ok</div>

<div>13:23:08.0967 6428  AudioSrv - ok</div>

<div>13:23:08.0978 6428  automap - ok</div>

<div>13:23:08.0988 6428  awecho - ok</div>

<div>13:23:08.0997 6428  awhost32 - ok</div>

<div>13:23:09.0000 6428  AW_HOST - ok</div>

<div>13:23:09.0003 6428  AxInstSV - ok</div>

<div>13:23:09.0005 6428  b06bdrv - ok</div>

<div>13:23:09.0018 6428  b57nd60a - ok</div>

<div>13:23:09.0025 6428  BDESVC - ok</div>

<div>13:23:09.0029 6428  Beep - ok</div>

<div>13:23:09.0044 6428  BFE - ok</div>

<div>13:23:09.0047 6428  BITS - ok</div>

<div>13:23:09.0063 6428  blbdrive - ok</div>

<div>13:23:09.0070 6428  Bonjour Service - ok</div>

<div>13:23:09.0074 6428  bowser - ok</div>

<div>13:23:09.0080 6428  bpenum - ok</div>

<div>13:23:09.0083 6428  bpmp - ok</div>

<div>13:23:09.0088 6428  bpusb - ok</div>

<div>13:23:09.0090 6428  BrFiltLo - ok</div>

<div>13:23:09.0093 6428  BrFiltUp - ok</div>

<div>13:23:09.0101 6428  BridgeMP - ok</div>

<div>13:23:09.0104 6428  Browser - ok</div>

<div>13:23:09.0107 6428  Brserid - ok</div>

<div>13:23:09.0110 6428  BrSerWdm - ok</div>

<div>13:23:09.0113 6428  BrUsbMdm - ok</div>

<div>13:23:09.0115 6428  BrUsbSer - ok</div>

<div>13:23:09.0118 6428  BTHMODEM - ok</div>

<div>13:23:09.0122 6428  bthserv - ok</div>

<div>13:23:09.0133 6428  Bulk - ok</div>

<div>13:23:09.0137 6428  catchme - ok</div>

<div>13:23:09.0139 6428  ccEvtMgr - ok</div>

<div>13:23:09.0142 6428  ccSetMgr - ok</div>

<div>13:23:09.0146 6428  cdfs - ok</div>

<div>13:23:09.0152 6428  cdrom - ok</div>

<div>13:23:09.0158 6428  CertPropSvc - ok</div>

<div>13:23:09.0161 6428  circlass - ok</div>

<div>13:23:09.0165 6428  CLFS - ok</div>

<div>13:23:09.0167 6428  clr_optimization_v2.0.50727_32 - ok</div>

<div>13:23:09.0170 6428  clr_optimization_v2.0.50727_64 - ok</div>

<div>13:23:09.0174 6428  clr_optimization_v4.0.30319_32 - ok</div>

<div>13:23:09.0183 6428  clr_optimization_v4.0.30319_64 - ok</div>

<div>13:23:09.0185 6428  CmBatt - ok</div>

<div>13:23:09.0188 6428  cmdide - ok</div>

<div>13:23:09.0190 6428  CNG - ok</div>

<div>13:23:09.0211 6428  CodeMeter.exe - ok</div>

<div>13:23:09.0214 6428  Compbatt - ok</div>

<div>13:23:09.0217 6428  CompositeBus - ok</div>

<div>13:23:09.0220 6428  COMSysApp - ok</div>

<div>13:23:09.0235 6428  ConfigService - ok</div>

<div>13:23:09.0238 6428  crcdisk - ok</div>

<div>13:23:09.0247 6428  CryptSvc - ok</div>

<div>13:23:09.0250 6428  CSC - ok</div>

<div>13:23:09.0253 6428  CscService - ok</div>

<div>13:23:09.0261 6428  ctxusbm - ok</div>

<div>13:23:09.0264 6428  CVirtA - ok</div>

<div>13:23:09.0267 6428  CVPND - ok</div>

<div>13:23:09.0270 6428  CVPNDRVA - ok</div>

<div>13:23:09.0273 6428  cvusbdrv - ok</div>

<div>13:23:09.0277 6428  DcomLaunch - ok</div>

<div>13:23:09.0281 6428  defragsvc - ok</div>

<div>13:23:09.0284 6428  DfsC - ok</div>

<div>13:23:09.0286 6428  Dhcp - ok</div>

<div>13:23:09.0289 6428  discache - ok</div>

<div>13:23:09.0292 6428  Disk - ok</div>

<div>13:23:09.0295 6428  DisplayFusionService - ok</div>

<div>13:23:09.0298 6428  DMService - ok</div>

<div>13:23:09.0300 6428  dmvsc - ok</div>

<div>13:23:09.0303 6428  DNE - ok</div>

<div>13:23:09.0332 6428  Dnscache - ok</div>

<div>13:23:09.0335 6428  dot3svc - ok</div>

<div>13:23:09.0337 6428  DPS - ok</div>

<div>13:23:09.0340 6428  drmkaud - ok</div>

<div>13:23:09.0352 6428  dtpd - ok</div>

<div>13:23:09.0355 6428  DXGKrnl - ok</div>

<div>13:23:09.0395 6428  e1cexpress - ok</div>

<div>13:23:09.0397 6428  EapHost - ok</div>

<div>13:23:09.0400 6428  ebdrv - ok</div>

<div>13:23:09.0403 6428  eeCtrl - ok</div>

<div>13:23:09.0406 6428  EFS - ok</div>

<div>13:23:09.0408 6428  ehRecvr - ok</div>

<div>13:23:09.0411 6428  ehSched - ok</div>

<div>13:23:09.0414 6428  elxstor - ok</div>

<div>13:23:09.0417 6428  EraserUtilRebootDrv - ok</div>

<div>13:23:09.0421 6428  ErrDev - ok</div>

<div>13:23:09.0433 6428  EventSystem - ok</div>

<div>13:23:09.0435 6428  exfat - ok</div>

<div>13:23:09.0438 6428  fastfat - ok</div>

<div>13:23:09.0441 6428  Fax - ok</div>

<div>13:23:09.0443 6428  fdc - ok</div>

<div>13:23:09.0447 6428  fdPHost - ok</div>

<div>13:23:09.0450 6428  FDResPub - ok</div>

<div>13:23:09.0452 6428  FileInfo - ok</div>

<div>13:23:09.0455 6428  Filetrace - ok</div>

<div>13:23:09.0458 6428  flpydisk - ok</div>

<div>13:23:09.0460 6428  FltMgr - ok</div>

<div>13:23:09.0464 6428  FontCache - ok</div>

<div>13:23:09.0466 6428  FontCache3.0.0.0 - ok</div>

<div>13:23:09.0469 6428  FsDepends - ok</div>

<div>13:23:09.0472 6428  Fs_Rec - ok</div>

<div>13:23:09.0475 6428  fvevol - ok</div>

<div>13:23:09.0478 6428  gagp30kx - ok</div>

<div>13:23:09.0481 6428  GEARAspiWDM - ok</div>

<div>13:23:09.0488 6428  gfibto - ok</div>

<div>13:23:09.0491 6428  gpsvc - ok</div>

<div>13:23:09.0494 6428  hcmon - ok</div>

<div>13:23:09.0497 6428  hcw85cir - ok</div>

<div>13:23:09.0508 6428  HdAudAddService - ok</div>

<div>13:23:09.0519 6428  HDAudBus - ok</div>

<div>13:23:09.0522 6428  HDJAsioK - ok</div>

<div>13:23:09.0528 6428  HDJMidi - ok</div>

<div>13:23:09.0559 6428  HerculesDJControlMP3 - ok</div>

<div>13:23:09.0561 6428  HidBatt - ok</div>

<div>13:23:09.0564 6428  HidBth - ok</div>

<div>13:23:09.0567 6428  HidIr - ok</div>

<div>13:23:09.0570 6428  hidserv - ok</div>

<div>13:23:09.0573 6428  HidUsb - ok</div>

<div>13:23:09.0577 6428  hkmsvc - ok</div>

<div>13:23:09.0580 6428  HomeGroupListener - ok</div>

<div>13:23:09.0582 6428  HomeGroupProvider - ok</div>

<div>13:23:09.0596 6428  hpqcxs08 - ok</div>

<div>13:23:09.0605 6428  hpqddsvc - ok</div>

<div>13:23:09.0606 6428  HpSAMD - ok</div>

<div>13:23:09.0609 6428  HPSLPSVC - ok</div>

<div>13:23:09.0612 6428  HTTP - ok</div>

<div>13:23:09.0615 6428  hwpolicy - ok</div>

<div>13:23:09.0618 6428  i8042prt - ok</div>

<div>13:23:09.0636 6428  iaStorV - ok</div>

<div>13:23:09.0647 6428  IBMWAS80Service - L07-FPYLFS1Node01 - ok</div>

<div>13:23:09.0651 6428  IDriverT - ok</div>

<div>13:23:09.0654 6428  idsvc - ok</div>

<div>13:23:09.0662 6428  igfx - ok</div>

<div>13:23:09.0665 6428  iirsp - ok</div>

<div>13:23:09.0677 6428  iked - ok</div>

<div>13:23:09.0681 6428  IKEEXT - ok</div>

<div>13:23:09.0694 6428  IntcDAud - ok</div>

<div>13:23:09.0699 6428  intelide - ok</div>

<div>13:23:09.0701 6428  intelppm - ok</div>

<div>13:23:09.0704 6428  IPBusEnum - ok</div>

<div>13:23:09.0708 6428  IpFilterDriver - ok</div>

<div>13:23:09.0711 6428  iphlpsvc - ok</div>

<div>13:23:09.0715 6428  ipMIDI - ok</div>

<div>13:23:09.0718 6428  IPMIDRV - ok</div>

<div>13:23:09.0721 6428  IPNAT - ok</div>

<div>13:23:09.0741 6428  iPod Service - ok</div>

<div>13:23:09.0751 6428  ipsecd - ok</div>

<div>13:23:09.0754 6428  IRENUM - ok</div>

<div>13:23:09.0757 6428  isapnp - ok</div>

<div>13:23:09.0759 6428  iScsiPrt - ok</div>

<div>13:23:09.0763 6428  kbdclass - ok</div>

<div>13:23:09.0765 6428  kbdhid - ok</div>

<div>13:23:09.0768 6428  KeyIso - ok</div>

<div>13:23:09.0770 6428  KSecDD - ok</div>

<div>13:23:09.0773 6428  KSecPkg - ok</div>

<div>13:23:09.0776 6428  ksthunk - ok</div>

<div>13:23:09.0779 6428  KtmRm - ok</div>

<div>13:23:09.0786 6428  LanmanServer - ok</div>

<div>13:23:09.0790 6428  LanmanWorkstation - ok</div>

<div>13:23:09.0793 6428  LBTServ - ok</div>

<div>13:23:09.0798 6428  LEqdUsb - ok</div>

<div>13:23:09.0800 6428  LHidEqd - ok</div>

<div>13:23:09.0803 6428  LHidFilt - ok</div>

<div>13:23:09.0807 6428  LiveUpdate - ok</div>

<div>13:23:09.0809 6428  lltdio - ok</div>

<div>13:23:09.0812 6428  lltdsvc - ok</div>

<div>13:23:09.0815 6428  lmhosts - ok</div>

<div>13:23:09.0818 6428  LMouFilt - ok</div>

<div>13:23:09.0828 6428  LMS - ok</div>

<div>13:23:09.0831 6428  LoopBeMidi1 - ok</div>

<div>13:23:09.0843 6428  LSI_FC - ok</div>

<div>13:23:09.0846 6428  LSI_SAS - ok</div>

<div>13:23:09.0849 6428  LSI_SAS2 - ok</div>

<div>13:23:09.0852 6428  LSI_SCSI - ok</div>

<div>13:23:09.0854 6428  luafv - ok</div>

<div>13:23:09.0857 6428  LUsbFilt - ok</div>

<div>13:23:09.0861 6428  Mcx2Svc - ok</div>

<div>13:23:09.0864 6428  megasas - ok</div>

<div>13:23:09.0867 6428  MegaSR - ok</div>

<div>13:23:09.0877 6428  MEIx64 - ok</div>

<div>13:23:09.0891 6428  Microsoft SharePoint Workspace Audit Service - ok</div>

<div>13:23:09.0894 6428  MMCSS - ok</div>

<div>13:23:09.0898 6428  Modem - ok</div>

<div>13:23:09.0901 6428  monitor - ok</div>

<div>13:23:09.0903 6428  mouclass - ok</div>

<div>13:23:09.0906 6428  mouhid - ok</div>

<div>13:23:09.0909 6428  mountmgr - ok</div>

<div>13:23:09.0917 6428  MouseWithoutBordersSvc - ok</div>

<div>13:23:09.0920 6428  MozillaMaintenance - ok</div>

<div>13:23:09.0923 6428  mpio - ok</div>

<div>13:23:09.0926 6428  mpsdrv - ok</div>

<div>13:23:09.0929 6428  MpsSvc - ok</div>

<div>13:23:09.0931 6428  MQAC - ok</div>

<div>13:23:09.0934 6428  MRxDAV - ok</div>

<div>13:23:09.0937 6428  mrxsmb - ok</div>

<div>13:23:09.0939 6428  mrxsmb10 - ok</div>

<div>13:23:09.0942 6428  mrxsmb20 - ok</div>

<div>13:23:09.0945 6428  msahci - ok</div>

<div>13:23:09.0948 6428  MsDepSvc - ok</div>

<div>13:23:09.0950 6428  msdsm - ok</div>

<div>13:23:09.0953 6428  MSDTC - ok</div>

<div>13:23:09.0958 6428  Msfs - ok</div>

<div>13:23:09.0960 6428  mshidkmdf - ok</div>

<div>13:23:09.0964 6428  msisadrv - ok</div>

<div>13:23:09.0975 6428  MSiSCSI - ok</div>

<div>13:23:09.0977 6428  msiserver - ok</div>

<div>13:23:09.0981 6428  MSKSSRV - ok</div>

<div>13:23:09.0983 6428  MSMQ - ok</div>

<div>13:23:09.0987 6428  MSPCLOCK - ok</div>

<div>13:23:09.0990 6428  MSPQM - ok</div>

<div>13:23:09.0993 6428  MsRPC - ok</div>

<div>13:23:09.0997 6428  mssmbios - ok</div>

<div>13:23:10.0000 6428  MSSQL$SQLEXPRESS - ok</div>

<div>13:23:10.0003 6428  MSSQLServerADHelper100 - ok</div>

<div>13:23:10.0006 6428  MSTEE - ok</div>

<div>13:23:10.0009 6428  MTConfig - ok</div>

<div>13:23:10.0011 6428  Mup - ok</div>

<div>13:23:10.0014 6428  napagent - ok</div>

<div>13:23:10.0017 6428  NativeWifiP - ok</div>

<div>13:23:10.0029 6428  NAVENG - ok</div>

<div>13:23:10.0033 6428  NAVEX15 - ok</div>

<div>13:23:10.0035 6428  NDIS - ok</div>

<div>13:23:10.0038 6428  NdisCap - ok</div>

<div>13:23:10.0041 6428  NdisTapi - ok</div>

<div>13:23:10.0044 6428  Ndisuio - ok</div>

<div>13:23:10.0047 6428  NdisWan - ok</div>

<div>13:23:10.0058 6428  NDProxy - ok</div>

<div>13:23:10.0061 6428  Net Driver HPZ12 - ok</div>

<div>13:23:10.0065 6428  NetBIOS - ok</div>

<div>13:23:10.0067 6428  NetBT - ok</div>

<div>13:23:10.0070 6428  Netlogon - ok</div>

<div>13:23:10.0083 6428  Netman - ok</div>

<div>13:23:10.0092 6428  NetMsmqActivator - ok</div>

<div>13:23:10.0100 6428  NetPipeActivator - ok</div>

<div>13:23:10.0102 6428  netprofm - ok</div>

<div>13:23:10.0108 6428  NetTcpActivator - ok</div>

<div>13:23:10.0111 6428  NetTcpPortSharing - ok</div>

<div>13:23:10.0121 6428  NETwNs64 - ok</div>

<div>13:23:10.0124 6428  nfrd960 - ok</div>

<div>13:23:10.0127 6428  NIHardwareService - ok</div>

<div>13:23:10.0131 6428  NlaSvc - ok</div>

<div>13:23:10.0133 6428  NPF - ok</div>

<div>13:23:10.0136 6428  Npfs - ok</div>

<div>13:23:10.0138 6428  nsi - ok</div>

<div>13:23:10.0141 6428  nsiproxy - ok</div>

<div>13:23:10.0145 6428  Ntfs - ok</div>

<div>13:23:10.0149 6428  Null - ok</div>

<div>13:23:10.0151 6428  nusb3hub - ok</div>

<div>13:23:10.0154 6428  nusb3xhc - ok</div>

<div>13:23:10.0166 6428  NvnUsbAudio - ok</div>

<div>13:23:10.0176 6428  nvraid - ok</div>

<div>13:23:10.0179 6428  nvstor - ok</div>

<div>13:23:10.0190 6428  nv_agp - ok</div>

<div>13:23:10.0202 6428  O2FLASH - ok</div>

<div>13:23:10.0205 6428  O2MDFRDR - ok</div>

<div>13:23:10.0207 6428  O2MDRRDR - ok</div>

<div>13:23:10.0210 6428  O2SDIOAssist - ok</div>

<div>13:23:10.0222 6428  O2SDJRDR - ok</div>

<div>13:23:10.0225 6428  ohci1394 - ok</div>

<div>13:23:10.0240 6428  ose - ok</div>

<div>13:23:10.0243 6428  osppsvc - ok</div>

<div>13:23:10.0248 6428  p2pimsvc - ok</div>

<div>13:23:10.0250 6428  p2psvc - ok</div>

<div>13:23:10.0262 6428  Parport - ok</div>

<div>13:23:10.0266 6428  partmgr - ok</div>

<div>13:23:10.0269 6428  PcaSvc - ok</div>

<div>13:23:10.0271 6428  pci - ok</div>

<div>13:23:10.0274 6428  pciide - ok</div>

<div>13:23:10.0276 6428  pcmcia - ok</div>

<div>13:23:10.0280 6428  pcw - ok</div>

<div>13:23:10.0282 6428  PEAUTH - ok</div>

<div>13:23:10.0285 6428  PeerDistSvc - ok</div>

<div>13:23:10.0289 6428  PerfHost - ok</div>

<div>13:23:10.0295 6428  pla - ok</div>

<div>13:23:10.0304 6428  PlugPlay - ok</div>

<div>13:23:10.0308 6428  Pml Driver HPZ12 - ok</div>

<div>13:23:10.0310 6428  PNRPAutoReg - ok</div>

<div>13:23:10.0314 6428  PNRPsvc - ok</div>

<div>13:23:10.0316 6428  PolicyAgent - ok</div>

<div>13:23:10.0320 6428  Power - ok</div>

<div>13:23:10.0323 6428  PptpMiniport - ok</div>

<div>13:23:10.0326 6428  Processor - ok</div>

<div>13:23:10.0330 6428  ProfSvc - ok</div>

<div>13:23:10.0332 6428  ProtectedStorage - ok</div>

<div>13:23:10.0335 6428  Psched - ok</div>

<div>13:23:10.0338 6428  PVIS9 - ok</div>

<div>13:23:10.0343 6428  PVIS9_64 - ok</div>

<div>13:23:10.0356 6428  PxHlpa64 - ok</div>

<div>13:23:10.0359 6428  ql2300 - ok</div>

<div>13:23:10.0362 6428  ql40xx - ok</div>

<div>13:23:10.0366 6428  QWAVE - ok</div>

<div>13:23:10.0368 6428  QWAVEdrv - ok</div>

<div>13:23:10.0371 6428  RasAcd - ok</div>

<div>13:23:10.0374 6428  RasAgileVpn - ok</div>

<div>13:23:10.0377 6428  RasAuto - ok</div>

<div>13:23:10.0380 6428  Rasl2tp - ok</div>

<div>13:23:10.0384 6428  RasMan - ok</div>

<div>13:23:10.0386 6428  RasPppoe - ok</div>

<div>13:23:10.0389 6428  RasSstp - ok</div>

<div>13:23:10.0392 6428  rdbss - ok</div>

<div>13:23:10.0395 6428  rdpbus - ok</div>

<div>13:23:10.0398 6428  RDPCDD - ok</div>

<div>13:23:10.0402 6428  RDPDR - ok</div>

<div>13:23:10.0409 6428  RDPENCDD - ok</div>

<div>13:23:10.0413 6428  RDPREFMP - ok</div>

<div>13:23:10.0416 6428  RDPWD - ok</div>

<div>13:23:10.0419 6428  rdyboost - ok</div>

<div>13:23:10.0421 6428  RemoteAccess - ok</div>

<div>13:23:10.0424 6428  RemoteRegistry - ok</div>

<div>13:23:10.0427 6428  rpcapd - ok</div>

<div>13:23:10.0430 6428  RpcEptMapper - ok</div>

<div>13:23:10.0433 6428  RpcLocator - ok</div>

<div>13:23:10.0435 6428  RpcSs - ok</div>

<div>13:23:10.0438 6428  RsFx0105 - ok</div>

<div>13:23:10.0441 6428  rspndr - ok</div>

<div>13:23:10.0450 6428  RsvLock - ok</div>

<div>13:23:10.0453 6428  s3cap - ok</div>

<div>13:23:10.0466 6428  SafeBoot - ok</div>

<div>13:23:10.0469 6428  SafeBootClientManager - ok</div>

<div>13:23:10.0472 6428  SamSs - ok</div>

<div>13:23:10.0474 6428  SBAlg - ok</div>

<div>13:23:10.0477 6428  SBAMSvc - ok</div>

<div>13:23:10.0481 6428  SbFlop - ok</div>

<div>13:23:10.0483 6428  SbFsLock - ok</div>

<div>13:23:10.0488 6428  SbieDrv - ok</div>

<div>13:23:10.0501 6428  SbieSvc - ok</div>

<div>13:23:10.0504 6428  sbp2port - ok</div>

<div>13:23:10.0507 6428  SbRegFlt - ok</div>

<div>13:23:10.0510 6428  SCardSvr - ok</div>

<div>13:23:10.0514 6428  scfilter - ok</div>

<div>13:23:10.0517 6428  Schedule - ok</div>

<div>13:23:10.0520 6428  SCPolicySvc - ok</div>

<div>13:23:10.0522 6428  sdbus - ok</div>

<div>13:23:10.0525 6428  SDRSVC - ok</div>

<div>13:23:10.0529 6428  SDScannerService - ok</div>

<div>13:23:10.0546 6428  SDUpdateService - ok</div>

<div>13:23:10.0549 6428  SDWSCService - ok</div>

<div>13:23:10.0552 6428  secdrv - ok</div>

<div>13:23:10.0555 6428  seclogon - ok</div>

<div>13:23:10.0558 6428  SENS - ok</div>

<div>13:23:10.0560 6428  SensrSvc - ok</div>

<div>13:23:10.0564 6428  Serenum - ok</div>

<div>13:23:10.0567 6428  Serial - ok</div>

<div>13:23:10.0569 6428  sermouse - ok</div>

<div>13:23:10.0576 6428  SessionEnv - ok</div>

<div>13:23:10.0579 6428  sffdisk - ok</div>

<div>13:23:10.0582 6428  sffp_mmc - ok</div>

<div>13:23:10.0585 6428  sffp_sd - ok</div>

<div>13:23:10.0587 6428  sfloppy - ok</div>

<div>13:23:10.0590 6428  SharedAccess - ok</div>

<div>13:23:10.0593 6428  ShellHWDetection - ok</div>

<div>13:23:10.0595 6428  SiSRaid2 - ok</div>

<div>13:23:10.0598 6428  SiSRaid4 - ok</div>

<div>13:23:10.0604 6428  Smb - ok</div>

<div>13:23:10.0607 6428  SmcService - ok</div>

<div>13:23:10.0613 6428  SNAC - ok</div>

<div>13:23:10.0618 6428  SNMPTRAP - ok</div>

<div>13:23:10.0631 6428  SophosVirusRemovalTool - ok</div>

<div>13:23:10.0634 6428  spldr - ok</div>

<div>13:23:10.0636 6428  Spooler - ok</div>

<div>13:23:10.0639 6428  sppsvc - ok</div>

<div>13:23:10.0641 6428  sppuinotify - ok</div>

<div>13:23:10.0661 6428  SQLAgent$SQLEXPRESS - ok</div>

<div>13:23:10.0664 6428  SQLBrowser - ok</div>

<div>13:23:10.0685 6428  SQLWriter - ok</div>

<div>13:23:10.0699 6428  SRTSP - ok</div>

<div>13:23:10.0715 6428  SRTSPL - ok</div>

<div>13:23:10.0736 6428  SRTSPX - ok</div>

<div>13:23:10.0740 6428  srv - ok</div>

<div>13:23:10.0745 6428  srv2 - ok</div>

<div>13:23:10.0749 6428  srvnet - ok</div>

<div>13:23:10.0753 6428  SSDPSRV - ok</div>

<div>13:23:10.0756 6428  SstpSvc - ok</div>

<div>13:23:10.0760 6428  STacSV - ok</div>

<div>13:23:10.0789 6428  stdcfltn - ok</div>

<div>13:23:10.0797 6428  stexstor - ok</div>

<div>13:23:10.0801 6428  STHDA - ok</div>

<div>13:23:10.0812 6428  StillCam - ok</div>

<div>13:23:10.0816 6428  stisvc - ok</div>

<div>13:23:10.0820 6428  storflt - ok</div>

<div>13:23:10.0823 6428  StorSvc - ok</div>

<div>13:23:10.0827 6428  storvsc - ok</div>

<div>13:23:10.0831 6428  swenum - ok</div>

<div>13:23:10.0835 6428  SwitchBoard - ok</div>

<div>13:23:10.0839 6428  swprv - ok</div>

<div>13:23:10.0844 6428  Symantec AntiVirus - ok</div>

<div>13:23:10.0848 6428  SymEvent - ok</div>

<div>13:23:10.0852 6428  SysMain - ok</div>

<div>13:23:10.0854 6428  TabletInputService - ok</div>

<div>13:23:10.0857 6428  TapiSrv - ok</div>

<div>13:23:10.0860 6428  TBS - ok</div>

<div>13:23:10.0863 6428  Tcpip - ok</div>

<div>13:23:10.0867 6428  TCPIP6 - ok</div>

<div>13:23:10.0871 6428  tcpipreg - ok</div>

<div>13:23:10.0874 6428  TDPIPE - ok</div>

<div>13:23:10.0877 6428  TDTCP - ok</div>

<div>13:23:10.0888 6428  tdx - ok</div>

<div>13:23:10.0891 6428  TermDD - ok</div>

<div>13:23:10.0894 6428  TermService - ok</div>

<div>13:23:10.0902 6428  teVirtualMIDI64 - ok</div>

<div>13:23:10.0905 6428  Themes - ok</div>

<div>13:23:10.0908 6428  THREADORDER - ok</div>

<div>13:23:10.0927 6428  Tpkd - ok</div>

<div>13:23:10.0930 6428  TrkWks - ok</div>

<div>13:23:10.0933 6428  TrustedInstaller - ok</div>

<div>13:23:10.0937 6428  tssecsrv - ok</div>

<div>13:23:10.0940 6428  TsUsbFlt - ok</div>

<div>13:23:10.0942 6428  TsUsbGD - ok</div>

<div>13:23:10.0946 6428  tunnel - ok</div>

<div>13:23:10.0948 6428  uagp35 - ok</div>

<div>13:23:10.0951 6428  uagqecsvc - ok</div>

<div>13:23:10.0954 6428  udfs - ok</div>

<div>13:23:10.0958 6428  UI0Detect - ok</div>

<div>13:23:10.0961 6428  uliagpkx - ok</div>

<div>13:23:10.0964 6428  umbus - ok</div>

<div>13:23:10.0967 6428  UmPass - ok</div>

<div>13:23:10.0970 6428  UmRdpService - ok</div>

<div>13:23:10.0973 6428  UNS - ok</div>

<div>13:23:10.0975 6428  upnphost - ok</div>

<div>13:23:10.0979 6428  USBAAPL64 - ok</div>

<div>13:23:10.0981 6428  usbaudio - ok</div>

<div>13:23:10.0984 6428  usbccgp - ok</div>

<div>13:23:10.0987 6428  usbcir - ok</div>

<div>13:23:10.0990 6428  usbehci - ok</div>

<div>13:23:10.0993 6428  usbhub - ok</div>

<div>13:23:10.0996 6428  usbohci - ok</div>

<div>13:23:11.0003 6428  usbprint - ok</div>

<div>13:23:11.0006 6428  usbscan - ok</div>

<div>13:23:11.0008 6428  USBSTOR - ok</div>

<div>13:23:11.0011 6428  usbuhci - ok</div>

<div>13:23:11.0014 6428  usbvideo - ok</div>

<div>13:23:11.0017 6428  UxSms - ok</div>

<div>13:23:11.0020 6428  VaultSvc - ok</div>

<div>13:23:11.0023 6428  vdrvroot - ok</div>

<div>13:23:11.0025 6428  vds - ok</div>

<div>13:23:11.0051 6428  vflt - ok</div>

<div>13:23:11.0054 6428  vga - ok</div>

<div>13:23:11.0057 6428  VgaSave - ok</div>

<div>13:23:11.0059 6428  vhdmp - ok</div>

<div>13:23:11.0062 6428  viaide - ok</div>

<div>13:23:11.0066 6428  VMAuthdService - ok</div>

<div>13:23:11.0070 6428  vmbus - ok</div>

<div>13:23:11.0073 6428  VMBusHID - ok</div>

<div>13:23:11.0078 6428  vmci - ok</div>

<div>13:23:11.0094 6428  vmkbd - ok</div>

<div>13:23:11.0098 6428  VMnetAdapter - ok</div>

<div>13:23:11.0101 6428  VMnetBridge - ok</div>

<div>13:23:11.0105 6428  VMnetDHCP - ok</div>

<div>13:23:11.0108 6428  VMnetuserif - ok</div>

<div>13:23:11.0116 6428  VMparport - ok</div>

<div>13:23:11.0120 6428  vmusb - ok</div>

<div>13:23:11.0124 6428  VMUSBArbService - ok</div>

<div>13:23:11.0130 6428  VMware NAT Service - ok</div>

<div>13:23:11.0137 6428  vmx86 - ok</div>

<div>13:23:11.0141 6428  vnet - ok</div>

<div>13:23:11.0145 6428  volmgr - ok</div>

<div>13:23:11.0149 6428  volmgrx - ok</div>

<div>13:23:11.0153 6428  volsnap - ok</div>

<div>13:23:11.0163 6428  vpnva - ok</div>

<div>13:23:11.0167 6428  vsmraid - ok</div>

<div>13:23:11.0170 6428  VSPerfDrv100 - ok</div>

<div>13:23:11.0175 6428  VSS - ok</div>

<div>13:23:11.0179 6428  vwifibus - ok</div>

<div>13:23:11.0182 6428  vwififlt - ok</div>

<div>13:23:11.0194 6428  vwifimp - ok</div>

<div>13:23:11.0198 6428  W32Time - ok</div>

<div>13:23:11.0203 6428  W3SVC - ok</div>

<div>13:23:11.0206 6428  WacomPen - ok</div>

<div>13:23:11.0273 6428  WANARP - ok</div>

<div>13:23:11.0341 6428  Wanarpv6 - ok</div>

<div>13:23:11.0365 6428  WAS - ok</div>

<div>13:23:11.0375 6428  WatAdminSvc - ok</div>

<div>13:23:11.0385 6428  wbengine - ok</div>

<div>13:23:11.0394 6428  WbioSrvc - ok</div>

<div>13:23:11.0405 6428  wcncsvc - ok</div>

<div>13:23:11.0415 6428  WcsPlugInService - ok</div>

<div>13:23:11.0422 6428  Wd - ok</div>

<div>13:23:11.0429 6428  Wdf01000 - ok</div>

<div>13:23:11.0436 6428  WdiServiceHost - ok</div>

<div>13:23:11.0442 6428  WdiSystemHost - ok</div>

<div>13:23:11.0449 6428  WebClient - ok</div>

<div>13:23:11.0452 6428  Wecsvc - ok</div>

<div>13:23:11.0455 6428  wercplsupport - ok</div>

<div>13:23:11.0459 6428  WerSvc - ok</div>

<div>13:23:11.0463 6428  WfpLwf - ok</div>

<div>13:23:11.0466 6428  WIMMount - ok</div>

<div>13:23:11.0470 6428  WinDefend - ok</div>

<div>13:23:11.0476 6428  WinHttpAutoProxySvc - ok</div>

<div>13:23:11.0479 6428  Winmgmt - ok</div>

<div>13:23:11.0483 6428  WinRM - ok</div>

<div>13:23:11.0488 6428  WinUsb - ok</div>

<div>13:23:11.0491 6428  Wlansvc - ok</div>

<div>13:23:11.0494 6428  wlidsvc - ok</div>

<div>13:23:11.0497 6428  WmiAcpi - ok</div>

<div>13:23:11.0502 6428  wmiApSrv - ok</div>

<div>13:23:11.0504 6428  WMPNetworkSvc - ok</div>

<div>13:23:11.0507 6428  WPCSvc - ok</div>

<div>13:23:11.0510 6428  WPDBusEnum - ok</div>

<div>13:23:11.0513 6428  ws2ifsl - ok</div>

<div>13:23:11.0527 6428  wscsvc - ok</div>

<div>13:23:11.0530 6428  WSDPrintDevice - ok</div>

<div>13:23:11.0533 6428  WSearch - ok</div>

<div>13:23:11.0538 6428  wuauserv - ok</div>

<div>13:23:11.0541 6428  WudfPf - ok</div>

<div>13:23:11.0543 6428  WUDFRd - ok</div>

<div>13:23:11.0547 6428  wudfsvc - ok</div>

<div>13:23:11.0549 6428  WwanSvc - ok</div>

<div>13:23:11.0608 6428  ================ Scan global ===============================</div>

<div>13:23:11.0612 6428  [Global] - ok</div>

<div>13:23:11.0617 6428  ================ Scan MBR ==================================</div>

<div>13:23:11.0630 6428  [ 5C73746B987022A51FD1D12550C35637 ] \Device\Harddisk0\DR0</div>

<div>13:23:12.0327 6428  \Device\Harddisk0\DR0 - ok</div>

<div>13:23:12.0328 6428  ================ Scan VBR ==================================</div>

<div>13:23:12.0332 6428  [ F67FF8E229FE901B35208CBB11286AC1 ] \Device\Harddisk0\DR0\Partition1</div>

<div>13:23:12.0335 6428  \Device\Harddisk0\DR0\Partition1 - ok</div>

<div>13:23:12.0367 6428  [ 4BAFAF1D3E4B4B1B52448F66BF3BB4D4 ] \Device\Harddisk0\DR0\Partition2</div>

<div>13:23:12.0368 6428  \Device\Harddisk0\DR0\Partition2 - ok</div>

<div>13:23:12.0369 6428  ============================================================</div>

<div>13:23:12.0369 6428  Scan finished</div>

<div>13:23:12.0369 6428  ============================================================</div>

<div>13:23:12.0384 6748  Detected object count: 0</div>

<div>13:23:12.0384 6748  Actual detected object count: 0</div>

<div> </div>

Link to post
Share on other sites

Ok...

Let's run another tool. It doesn't go after big nasties... but it might find some adware embedded in your browsers.

Please download Junkware Removal Tool by clicking here and save it to your desktop.

  • Shutdown your antivirus to avoid any conflicts.
  • Double click JRT.exe to run the tool.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.