Jump to content

I'm Infected.. Yay! ._.


Recommended Posts

I've had this virus for about a month now.. I've tried many things with the help of my tech (online), but he couldn't help (he relies solely on his wits, not anything else)..

So, here I am.

I've experienced really nothing except occasional Google Redirects, but, with viruses you can never be too sure. I figured it's time to FINALLY get rid of this thing with some PROFESSIONAL help.

Thanks in advance to whomever comes to assist me.

Note: I'm not technically intelligent whatsoever, but I'll be trying my hardest to go along with what you're recommending! :]

--

[Not sure if I'm supposed to 'attach' the two files now, or after you tell me to.. so I'll just leave them out for now.]

The thing that's said to be removed, isn't. It comes back after a restart, or just isn't deleted at all. It's just there, and won't go away with what I try. With my previous tech's help, I used a bunch of programs that I still have installed, which I'm pretty sure you'll ask me to use. Not sure if I should uninstall them or not. (examples: combofix, rkill, tdsskiller..); none of these seemed to work with my low-level technical skills. :-0

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4052

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

7/30/2011 10:48:01 AM

mbam-log-2011-07-30 (10-48-01).txt

Scan type: Quick scan

Objects scanned: 158937

Time elapsed: 4 minute(s), 12 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\.fsharproj (Trojan.Tracur) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

;

.

DDS (Ver_2011-06-23.01) - NTFSAMD64

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_23

Run by troyswi at 10:55:15 on 2011-07-30

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8151.5903 [GMT -4:00]

.

AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\Dell\DellDock\DockLogin.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\SysWOW64\svchost.exe -k Akamai

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\spool\DRIVERS\x64\3\dleaserv.exe

C:\Windows\system32\dleacoms.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\Windows\System32\rundll32.exe

C:\Windows\System32\rundll32.exe

C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe

C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe

C:\Program Files\Dell\DellDock\DellDock.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

C:\Program Files\AVAST Software\Avast\AvastUI.exe

C:\Program Files (x86)\Razer\DeathAdder\razertra.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe

C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAEM.exe

C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe

C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\iTunes\iTunes.exe

C:\Program Files (x86)\Xfire\Xfire.exe

C:\Program Files (x86)\Xfire\xfire64.exe

C:\Program Files (x86)\Xfire\xfire64.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k WerSvcGroup

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\WUDFHost.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\system32\sppsvc.exe

C:\Windows\explorer.exe

c:\program files (x86)\real\realplayer\RealPlay.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://sigma.pokemonvortex.org/your_team.php

uInternet Settings,ProxyOverride = *.local

BHO: {02baffbd-4260-4ed8-b509-e4b7401cf82a} - C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll

BHO: {05560adf-7b25-40ff-b408-3f6e6f512eb4} - C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll

BHO: Dell Toolbar: {09b71986-2ac5-482d-b6cb-42ea34f4f85b} - C:\Program Files\Dell Printable Web\toolband.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll

TB: Dell Toolbar: {09b71986-2ac5-482d-b6cb-42ea34f4f85b} - C:\Program Files\Dell Printable Web\toolband.dll

TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll

TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll

TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

EB: iMacros 7: {a310506f-6ba4-48c4-8887-1f462277aa12} - mscoree.dll

uRun: [Google Update] "C:\Users\troyswi\AppData\Local\Google\Update\GoogleUpdate.exe" /c

uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

mRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

mRun: [shwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

mRun: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r

mRun: [updReg] C:\Windows\UpdReg.EXE

mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

mRun: [Dell V310-V510 Series] "C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe" /s

mRun: [ATICustomerCare] "c:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [Anti-phishing Domain Advisor] "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe"

mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot

mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

StartupFolder: C:\Users\troyswi\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

mPolicies-system: SoftwareSASGeneration = 0 (0x0)

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - {A310506F-6BA4-48c4-8887-1F462277AA12} - mscoree.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {93C449FA-ECFB-402F-A8C7-37E4F8D60E49} - hxxp://dl.pmang.com/common/pmangctl/pmangax.cab

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

TCP: DhcpNameServer = 192.168.1.1 68.87.64.150 68.87.75.198

TCP: Interfaces\{684D61C6-AFC2-4E9E-A94E-3ECE0EB26783} : DhcpNameServer = 192.168.1.1 68.87.64.150 68.87.75.198

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll

C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll

BHO-X64: Dell Toolbar: {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

BHO-X64: Search Helper - No File

BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

BHO-X64: SkypeIEPluginBHO - No File

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll

TB-X64: Dell Toolbar: {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll

TB-X64: DAEMON Tools Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll

TB-X64: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll

TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

EB-X64: {A310506F-6BA4-48C4-8887-1F462277AA12} - No File

mRun-x64: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

mRun-x64: [shwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

mRun-x64: [startCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r

mRun-x64: [updReg] C:\Windows\UpdReg.EXE

mRun-x64: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

mRun-x64: [Dell V310-V510 Series] "C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe" /s

mRun-x64: [ATICustomerCare] "c:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun-x64: [Anti-phishing Domain Advisor] "C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe"

mRun-x64: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot

mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

Hosts: 127.0.0.1 www.spywareinfo.com

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\

FF - prefs.js: browser.search.selectedEngine - DAEMON Search

FF - prefs.js: browser.startup.homepage - hxxp://forums.ijji.com/forumdisplay.php?f=79

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 64848

FF - prefs.js: network.proxy.type - 0

FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll

FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll

FF - component: C:\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\imtcp_xpcom.dll

FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll

FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

FF - plugin: C:\Users\troyswi\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - Ext: avast! WebRep: wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF - Ext: Easy-Hide-IP Firefox Plugin: support@easy-hide-ip.com - C:\Program Files (x86)\Easy-Hide-IP\ff-extension

FF - Ext: iMacros for Firefox: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} - %profile%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}

FF - Ext: XUL Cache: {c014d80a-b4ed-42ca-ac38-a0160cb5066a} - %profile%\extensions\{c014d80a-b4ed-42ca-ac38-a0160cb5066a}

FF - Ext: XUL Cache: {4636f24c-e3f1-4390-87e2-02ba08372da5} - %profile%\extensions\{4636f24c-e3f1-4390-87e2-02ba08372da5}

FF - Ext: XUL Cache: {40271a83-fe52-42c9-875b-5aa69ffec208} - %profile%\extensions\{40271a83-fe52-42c9-875b-5aa69ffec208}

FF - Ext: XUL Cache: {4fbf8087-30c4-46f6-97e9-d56b8795e341} - %profile%\extensions\{4fbf8087-30c4-46f6-97e9-d56b8795e341}

FF - Ext: XUL Cache: {1dda916b-a2f7-4c9f-a773-dfe5adb23c88} - %profile%\extensions\{1dda916b-a2f7-4c9f-a773-dfe5adb23c88}

FF - Ext: XUL Cache: {a7148e08-9dcc-430c-a305-e8f7b8c0ded5} - %profile%\extensions\{a7148e08-9dcc-430c-a305-e8f7b8c0ded5}

FF - Ext: XUL Cache: {0772bda2-530f-42b7-9717-fb7bd7d5026b} - %profile%\extensions\{0772bda2-530f-42b7-9717-fb7bd7d5026b}

FF - Ext: XUL Cache: {4f55d6e9-4cf3-403b-8a77-20413087e102} - %profile%\extensions\{4f55d6e9-4cf3-403b-8a77-20413087e102}

FF - Ext: XUL Cache: {e6b52706-93b9-473f-90fd-3cfb0e53dd4e} - %profile%\extensions\{e6b52706-93b9-473f-90fd-3cfb0e53dd4e}

FF - Ext: XUL Cache: {7c926b72-a3c2-4747-a0e3-04b82b926203} - %profile%\extensions\{7c926b72-a3c2-4747-a0e3-04b82b926203}

FF - Ext: XUL Cache: {747fd0e4-ec3c-4356-9960-10e2f4a63739} - %profile%\extensions\{747fd0e4-ec3c-4356-9960-10e2f4a63739}

FF - Ext: XUL Cache: {df28687c-9a39-4e15-854f-af3247fc7fd8} - %profile%\extensions\{df28687c-9a39-4e15-854f-af3247fc7fd8}

FF - Ext: XUL Cache: {907f6615-ca17-4a2e-b168-874b3da349f9} - %profile%\extensions\{907f6615-ca17-4a2e-b168-874b3da349f9}

FF - Ext: XUL Cache: {b4d6a01a-4879-4c28-8a4a-4e244fe73384} - %profile%\extensions\{b4d6a01a-4879-4c28-8a4a-4e244fe73384}

FF - Ext: XUL Cache: {facca4a5-2dc8-4aad-8f8f-5d9ee93d66b9} - %profile%\extensions\{facca4a5-2dc8-4aad-8f8f-5d9ee93d66b9}

FF - Ext: XUL Cache: {6b36e3c7-6f23-4017-b302-04187ec1b696} - %profile%\extensions\{6b36e3c7-6f23-4017-b302-04187ec1b696}

FF - Ext: XUL Cache: {77c2c07a-9d90-481d-92ea-84c4f59e4841} - %profile%\extensions\{77c2c07a-9d90-481d-92ea-84c4f59e4841}

FF - Ext: XUL Cache: {aaed32ad-1e47-4745-8b74-773216ecc790} - %profile%\extensions\{aaed32ad-1e47-4745-8b74-773216ecc790}

FF - Ext: XUL Cache: {0823b41f-9676-431a-b2e7-4d360a7b743d} - %profile%\extensions\{0823b41f-9676-431a-b2e7-4d360a7b743d}

FF - Ext: XUL Cache: {1ab7b2f2-034e-4cfd-aba2-4f5f2878f831} - %profile%\extensions\{1ab7b2f2-034e-4cfd-aba2-4f5f2878f831}

.

---- FIREFOX POLICIES ----

FF - user.js: network.protocol-handler.warn-external.dnupdate - false

============= SERVICES / DRIVERS ===============

.

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]

R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]

R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]

R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]

R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]

R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-7-25 42184]

R2 BPAAgent8;AutoMate BPA Server 8 Agent;C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe [2011-2-11 11323392]

R2 dlea_device;dlea_device;C:\Windows\system32\dleacoms.exe -service --> C:\Windows\system32\dleacoms.exe -service [?]

R2 dleaCATSCustConnectService;dleaCATSCustConnectService;C:\Windows\System32\spool\DRIVERS\x64\3\dleaserv.exe [2010-9-18 33448]

R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-8-30 13336]

R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-8-30 689472]

R2 TeamViewer5;TeamViewer 5;C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-9-16 1956136]

R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-6-1 2337144]

R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]

R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]

R3 danewFltr;NewDeathAdder Mouse;C:\Windows\system32\drivers\danew.sys --> C:\Windows\system32\drivers\danew.sys [?]

R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]

R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]

R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]

S2 BPA_Execution;AutoMate BPA Server 8 Execution Server;C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_EXEC.exe [2011-2-11 376832]

S2 BPA_Management;AutoMate BPA Server 8 Management Server;C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_MAN.exe [2011-2-11 376832]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 EFS32;Encrypting File System (EFS) ;C:\Windows\system32\OnLineIDCpl32.exe --> C:\Windows\system32\OnLineIDCpl32.exe [?]

S2 FLEXnet Licensing Service32;FLEXnet Licensing Service ;C:\Windows\system32\catsrv32.exe --> C:\Windows\system32\catsrv32.exe [?]

S2 SessionLauncher;SessionLauncher;c:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe --> c:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [?]

S2 wcncsvc32;Windows Connect Now - Config Registrar ;c:\windows\system32\capiprovider32.exe --> c:\windows\system32\capiprovider32.exe [?]

S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2011-5-12 25072]

S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe [2009-6-26 1124848]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

.

=============== Created Last 30 ================

.

2011-07-22 17:19:15 542720 ----a-w- C:\Windows\SysWow64\yA

2011-07-20 14:18:20 -------- d-sh--w- C:\Windows\System32\%APPDATA%

2011-07-13 12:15:59 25600 ----a-w- C:\Windows\SysWow64\setup16.exe

2011-07-13 12:15:59 243200 ----a-w- C:\Windows\System32\wow64.dll

2011-07-13 12:15:59 16384 ----a-w- C:\Windows\System32\ntvdm64.dll

2011-07-13 12:15:59 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll

2011-07-13 12:15:59 13312 ----a-w- C:\Windows\System32\wow64cpu.dll

2011-07-13 12:15:57 7680 ----a-w- C:\Windows\SysWow64\instnm.exe

2011-07-13 12:15:57 5120 ----a-w- C:\Windows\SysWow64\wow32.dll

2011-07-13 12:15:52 2048 ----a-w- C:\Windows\SysWow64\user.exe

2011-07-08 18:01:17 -------- d-----w- C:\Program Files\iPod

2011-07-08 17:59:52 -------- d-----w- C:\Program Files\Bonjour

2011-07-08 17:59:52 -------- d-----w- C:\Program Files (x86)\Bonjour

2011-07-03 20:02:53 64856 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys

2011-07-03 20:02:53 600920 ----a-w- C:\Windows\System32\drivers\aswSnx.sys

2011-07-03 20:02:50 40112 ----a-w- C:\Windows\avastSS.scr

2011-07-03 20:02:45 -------- d-----w- C:\ProgramData\AVAST Software

2011-07-03 20:02:45 -------- d-----w- C:\Program Files\AVAST Software

2011-07-03 20:00:14 98816 ----a-w- C:\Windows\sed.exe

2011-07-03 20:00:14 518144 ----a-w- C:\Windows\SWREG.exe

2011-07-03 20:00:14 256000 ----a-w- C:\Windows\PEV.exe

2011-07-03 20:00:14 208896 ----a-w- C:\Windows\MBR.exe

2011-07-03 20:00:12 -------- d-s---w- C:\comfix.exe

2011-07-03 01:30:35 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com

2011-06-30 21:16:01 349184 ----a-w- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll

.

==================== Find3M ====================

.

2011-07-07 15:51:49 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2011-06-11 02:56:44 3134464 ----a-w- C:\Windows\System32\win32k.sys

2011-06-02 06:45:22 362496 ----a-w- C:\Windows\System32\wow64win.dll

2011-06-02 06:44:54 214528 ----a-w- C:\Windows\System32\winsrv.dll

2011-06-02 06:39:54 422400 ----a-w- C:\Windows\System32\KernelBase.dll

2011-06-02 06:35:56 338944 ----a-w- C:\Windows\System32\conhost.exe

2011-06-02 05:56:28 44032 ----a-w- C:\Windows\apppatch\acwow64.dll

2011-06-02 05:54:50 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll

2011-06-02 03:45:49 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

2011-06-02 03:45:49 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

2011-06-02 03:45:49 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

2011-06-02 03:45:49 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

2011-05-29 21:17:10 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll

2011-05-29 21:17:10 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll

2011-05-28 03:25:16 1638912 ----a-w- C:\Windows\System32\mshtml.tlb

2011-05-28 03:00:02 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2011-05-24 23:14:10 270720 ------w- C:\Windows\System32\MpSigStub.exe

2011-05-24 11:21:59 404992 ----a-w- C:\Windows\System32\umpnpmgr.dll

2011-05-24 10:34:20 64512 ----a-w- C:\Windows\SysWow64\devobj.dll

2011-05-24 10:34:20 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll

2011-05-24 10:34:00 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll

2011-05-24 10:32:46 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe

2011-05-10 12:06:08 51712 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys

2011-05-10 12:06:08 4517664 ----a-w- C:\Windows\System32\usbaaplrc.dll

2011-05-08 14:59:19 380008 ----a-w- C:\Windows\SysWow64\PMangAX0.dll

2011-05-04 05:30:38 2326016 ----a-w- C:\Windows\System32\tquery.dll

2011-05-04 05:28:07 779264 ----a-w- C:\Windows\System32\mssvp.dll

2011-05-04 05:28:07 2228224 ----a-w- C:\Windows\System32\mssrch.dll

2011-05-04 05:28:06 75264 ----a-w- C:\Windows\System32\msscntrs.dll

2011-05-04 05:28:06 491520 ----a-w- C:\Windows\System32\mssph.dll

2011-05-04 05:28:06 288256 ----a-w- C:\Windows\System32\mssphtb.dll

2011-05-04 05:24:09 593408 ----a-w- C:\Windows\System32\SearchIndexer.exe

2011-05-04 05:24:09 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe

2011-05-04 05:24:09 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe

2011-05-04 04:53:10 1553920 ----a-w- C:\Windows\SysWow64\tquery.dll

2011-05-04 04:52:59 666624 ----a-w- C:\Windows\SysWow64\mssvp.dll

2011-05-04 04:52:59 59392 ----a-w- C:\Windows\SysWow64\msscntrs.dll

2011-05-04 04:52:59 337408 ----a-w- C:\Windows\SysWow64\mssph.dll

2011-05-04 04:52:59 197120 ----a-w- C:\Windows\SysWow64\mssphtb.dll

2011-05-04 04:52:59 1401856 ----a-w- C:\Windows\SysWow64\mssrch.dll

2011-05-04 04:52:12 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe

2011-05-04 04:52:12 428032 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe

2011-05-04 04:52:12 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe

2011-05-04 02:51:08 287744 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys

2011-05-04 02:51:08 157696 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys

2011-05-04 02:51:05 126464 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys

2011-05-03 05:21:22 976896 ----a-w- C:\Windows\System32\inetcomm.dll

2011-05-03 04:50:29 740864 ----a-w- C:\Windows\SysWow64\inetcomm.dll

.

============= FINISH: 10:57:46.61 ===============

Link to post
Share on other sites

Hello Charade and welcome to Malwarebytes! :welcome:

I am D-FRED-BROWN and I will be helping you. :)

Please print or save this topic: it will make it easier for you to follow the instructions and complete all of the necessary steps.

-------------

Please download to your Desktop:

  • TDSSKiller.zip from here and extract it (right click on it => "Extract here").

>>> TDSSKiller: Double-click on TDSSKiller.exe to run the application.

  • Click on the Start Scan button and wait for the scan and disinfection process to be over.
  • If an infected file is detected, the default action will be Cure, click on Continue tdsskiller2.png
  • If a suspicious file is detected, the default action will be Skip, click on Continue tdsskiller3.png
  • If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.
  • If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.

In your next reply, please include the following (you may need to use two posts to get it all in):

  • TDSSKiller_log.txt
how the PC is running now?
-------------
Please download ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
***IMPORTANT: save ComboFix to your Desktop***
* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Please go here to see a list of programs that should be disabled.
**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall**
Please include the C:\ComboFix.txt in your next reply for further review.
Also, please let me know if any problems still remain.
-------------
Please download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

-------------

In your next reply, please include:

  • C:\ComboFix.txt
  • TDSSKiller log
  • Security Check checkup.txt

How is your computer running now?

Link to post
Share on other sites

Hmm. Everything appears to be better; unsure though.

[The Malwarebytes log I posted was from an out-of-date version of Malwarebytes; when I scanned with it, before your post, it received more "infections."]

Posting this log just in case it's important.

Malwarebytes' Anti-Malware 1.51.1.1800

www.malwarebytes.org

Database version: 7338

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

7/31/2011 10:37:10 AM

mbam-log-2011-07-31 (10-37-10).txt

Scan type: Quick scan

Objects scanned: 233735

Time elapsed: 5 minute(s), 34 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 5

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 6

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{02BAFFBD-4260-4ED8-B509-E4B7401CF82a} (Trojan.Tracur.PGen) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02BAFFBD-4260-4ED8-B509-E4B7401CF82A} (Trojan.Tracur.PGen) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{02BAFFBD-4260-4ED8-B509-E4B7401CF82A} (Trojan.Tracur.PGen) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BAFFBD-4260-4ED8-B509-E4B7401CF82A} (Trojan.Tracur.PGen) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-032.dll (Trojan.Tracur.PGen) -> Quarantined and deleted successfully.

c:\Windows\System32\api-ms-win-core-memory-l1-1-032.dll (Trojan.Tracur.PGen) -> Quarantined and deleted successfully.

c:\Windows\System32\yA (Trojan.Agent) -> Quarantined and deleted successfully.

c:\Windows\SysWOW64\yA (Trojan.Agent) -> Quarantined and deleted successfully.

c:\Users\troyswi\AppData\Local\Temp\tmph1598299929656929788.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

c:\Users\troyswi\AppData\Local\Temp\tmph4585799952771104555.tmp (Trojan.Tracur.SGen) -> Quarantined and deleted successfully.

--

Onto the ones you requested.

2011/07/31 10:48:07.0638 1548 TDSS rootkit removing tool 2.5.13.0 Jul 29 2011 17:24:11

2011/07/31 10:48:07.0960 1548 ================================================================================

2011/07/31 10:48:07.0960 1548 SystemInfo:

2011/07/31 10:48:07.0960 1548

2011/07/31 10:48:07.0960 1548 OS Version: 6.1.7600 ServicePack: 0.0

2011/07/31 10:48:07.0960 1548 Product type: Workstation

2011/07/31 10:48:07.0960 1548 ComputerName: STEVESWI-PC

2011/07/31 10:48:07.0960 1548 UserName: troyswi

2011/07/31 10:48:07.0960 1548 Windows directory: C:\Windows

2011/07/31 10:48:07.0960 1548 System windows directory: C:\Windows

2011/07/31 10:48:07.0960 1548 Running under WOW64

2011/07/31 10:48:07.0960 1548 Processor architecture: Intel x64

2011/07/31 10:48:07.0960 1548 Number of processors: 8

2011/07/31 10:48:07.0960 1548 Page size: 0x1000

2011/07/31 10:48:07.0960 1548 Boot type: Normal boot

2011/07/31 10:48:07.0960 1548 ================================================================================

2011/07/31 10:48:09.0348 1548 Initialize success

2011/07/31 10:48:15.0012 3728 ================================================================================

2011/07/31 10:48:15.0012 3728 Scan started

2011/07/31 10:48:15.0012 3728 Mode: Manual;

2011/07/31 10:48:15.0012 3728 ================================================================================

2011/07/31 10:48:16.0916 3728 1394ohci (69aa89a20dee08bfa650aab6ce37bd10) C:\Windows\system32\DRIVERS\1394ohci.sys

2011/07/31 10:48:16.0963 3728 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys

2011/07/31 10:48:16.0983 3728 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys

2011/07/31 10:48:17.0041 3728 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys

2011/07/31 10:48:17.0099 3728 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys

2011/07/31 10:48:17.0119 3728 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys

2011/07/31 10:48:17.0185 3728 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys

2011/07/31 10:48:17.0200 3728 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys

2011/07/31 10:48:17.0246 3728 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys

2011/07/31 10:48:17.0297 3728 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys

2011/07/31 10:48:17.0310 3728 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys

2011/07/31 10:48:17.0449 3728 amdkmdag (bbab5b28253fe0fc7255d8775ba05c1d) C:\Windows\system32\DRIVERS\atikmdag.sys

2011/07/31 10:48:17.0580 3728 amdkmdap (cba35ff4092b91e105d93ed11a0250b6) C:\Windows\system32\DRIVERS\atikmpag.sys

2011/07/31 10:48:17.0603 3728 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys

2011/07/31 10:48:17.0643 3728 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys

2011/07/31 10:48:17.0677 3728 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys

2011/07/31 10:48:17.0700 3728 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys

2011/07/31 10:48:17.0757 3728 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys

2011/07/31 10:48:17.0893 3728 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys

2011/07/31 10:48:17.0927 3728 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys

2011/07/31 10:48:18.0023 3728 aswFsBlk (55353cd0da287b2c3782485740965b54) C:\Windows\system32\drivers\aswFsBlk.sys

2011/07/31 10:48:18.0161 3728 aswMonFlt (b38061cdefb71361e0c7547ac60527e8) C:\Windows\system32\drivers\aswMonFlt.sys

2011/07/31 10:48:18.0190 3728 aswRdr (91e7aca95933633b2557f47cdfdb74c3) C:\Windows\system32\drivers\aswRdr.sys

2011/07/31 10:48:18.0274 3728 aswSnx (2b15499f68fad60ce69264a327e9b0f0) C:\Windows\system32\drivers\aswSnx.sys

2011/07/31 10:48:18.0311 3728 aswSP (4d939ecb19dc930056593390d1c87c43) C:\Windows\system32\drivers\aswSP.sys

2011/07/31 10:48:18.0328 3728 aswTdi (d633426c5a207ce21767569aa4946891) C:\Windows\system32\drivers\aswTdi.sys

2011/07/31 10:48:18.0374 3728 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys

2011/07/31 10:48:18.0412 3728 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys

2011/07/31 10:48:18.0457 3728 AtiHdmiService (77c149e6d702737b2e372dee166faef8) C:\Windows\system32\drivers\AtiHdmi.sys

2011/07/31 10:48:18.0516 3728 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys

2011/07/31 10:48:18.0545 3728 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys

2011/07/31 10:48:18.0574 3728 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys

2011/07/31 10:48:18.0610 3728 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys

2011/07/31 10:48:18.0673 3728 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys

2011/07/31 10:48:18.0723 3728 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys

2011/07/31 10:48:18.0735 3728 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys

2011/07/31 10:48:18.0781 3728 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys

2011/07/31 10:48:18.0806 3728 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys

2011/07/31 10:48:18.0824 3728 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys

2011/07/31 10:48:18.0835 3728 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys

2011/07/31 10:48:18.0889 3728 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys

2011/07/31 10:48:18.0952 3728 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys

2011/07/31 10:48:18.0972 3728 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys

2011/07/31 10:48:18.0993 3728 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys

2011/07/31 10:48:19.0026 3728 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys

2011/07/31 10:48:19.0073 3728 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys

2011/07/31 10:48:19.0090 3728 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys

2011/07/31 10:48:19.0117 3728 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys

2011/07/31 10:48:19.0141 3728 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys

2011/07/31 10:48:19.0167 3728 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys

2011/07/31 10:48:19.0208 3728 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys

2011/07/31 10:48:19.0247 3728 danewFltr (003626f7ca17c204f16cd5047af0703a) C:\Windows\system32\drivers\danew.sys

2011/07/31 10:48:19.0300 3728 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys

2011/07/31 10:48:19.0327 3728 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys

2011/07/31 10:48:19.0361 3728 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys

2011/07/31 10:48:19.0418 3728 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys

2011/07/31 10:48:19.0587 3728 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys

2011/07/31 10:48:19.0968 3728 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys

2011/07/31 10:48:20.0111 3728 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys

2011/07/31 10:48:20.0134 3728 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys

2011/07/31 10:48:20.0186 3728 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys

2011/07/31 10:48:20.0208 3728 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys

2011/07/31 10:48:20.0231 3728 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys

2011/07/31 10:48:20.0288 3728 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys

2011/07/31 10:48:20.0306 3728 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys

2011/07/31 10:48:20.0339 3728 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys

2011/07/31 10:48:20.0365 3728 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys

2011/07/31 10:48:20.0391 3728 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys

2011/07/31 10:48:20.0430 3728 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys

2011/07/31 10:48:20.0471 3728 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys

2011/07/31 10:48:20.0497 3728 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys

2011/07/31 10:48:20.0535 3728 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys

2011/07/31 10:48:20.0565 3728 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys

2011/07/31 10:48:20.0593 3728 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys

2011/07/31 10:48:20.0622 3728 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys

2011/07/31 10:48:20.0641 3728 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys

2011/07/31 10:48:20.0660 3728 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys

2011/07/31 10:48:20.0677 3728 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys

2011/07/31 10:48:20.0712 3728 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys

2011/07/31 10:48:20.0749 3728 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys

2011/07/31 10:48:20.0783 3728 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys

2011/07/31 10:48:20.0804 3728 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys

2011/07/31 10:48:20.0826 3728 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys

2011/07/31 10:48:20.0855 3728 iaStor (631fa8935163b01fc0c02966cb3adb92) C:\Windows\system32\DRIVERS\iaStor.sys

2011/07/31 10:48:20.0900 3728 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys

2011/07/31 10:48:20.0925 3728 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys

2011/07/31 10:48:20.0978 3728 IntcAzAudAddService (ee64207f2f5c20bfe5f73db2566c4601) C:\Windows\system32\drivers\RTKVHD64.sys

2011/07/31 10:48:21.0018 3728 IntcDAud (49072edbc5c2f964917d1b585c90ed0a) C:\Windows\system32\DRIVERS\IntcDAud.sys

2011/07/31 10:48:21.0043 3728 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys

2011/07/31 10:48:21.0071 3728 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys

2011/07/31 10:48:21.0100 3728 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys

2011/07/31 10:48:21.0135 3728 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys

2011/07/31 10:48:21.0148 3728 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys

2011/07/31 10:48:21.0188 3728 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys

2011/07/31 10:48:21.0212 3728 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys

2011/07/31 10:48:21.0236 3728 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys

2011/07/31 10:48:21.0284 3728 k57nd60a (9d7ea8c7215d8d4ae7be110eee61085d) C:\Windows\system32\DRIVERS\k57nd60a.sys

2011/07/31 10:48:21.0303 3728 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys

2011/07/31 10:48:21.0339 3728 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys

2011/07/31 10:48:21.0359 3728 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys

2011/07/31 10:48:21.0385 3728 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys

2011/07/31 10:48:21.0400 3728 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys

2011/07/31 10:48:21.0443 3728 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys

2011/07/31 10:48:21.0506 3728 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys

2011/07/31 10:48:21.0524 3728 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys

2011/07/31 10:48:21.0541 3728 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys

2011/07/31 10:48:21.0560 3728 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys

2011/07/31 10:48:21.0580 3728 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys

2011/07/31 10:48:21.0602 3728 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys

2011/07/31 10:48:21.0625 3728 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys

2011/07/31 10:48:21.0654 3728 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys

2011/07/31 10:48:21.0672 3728 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys

2011/07/31 10:48:21.0686 3728 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys

2011/07/31 10:48:21.0699 3728 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys

2011/07/31 10:48:21.0715 3728 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys

2011/07/31 10:48:21.0729 3728 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys

2011/07/31 10:48:21.0744 3728 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys

2011/07/31 10:48:21.0789 3728 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys

2011/07/31 10:48:21.0827 3728 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys

2011/07/31 10:48:21.0866 3728 mrxsmb10 (a8c2d7673c8a010569390c826a0efaf4) C:\Windows\system32\DRIVERS\mrxsmb10.sys

2011/07/31 10:48:21.0908 3728 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys

2011/07/31 10:48:21.0964 3728 msahci (bccf16d5fb1109162380e3e28dc9e4e5) C:\Windows\system32\DRIVERS\msahci.sys

2011/07/31 10:48:21.0982 3728 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys

2011/07/31 10:48:22.0019 3728 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys

2011/07/31 10:48:22.0037 3728 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys

2011/07/31 10:48:22.0062 3728 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys

2011/07/31 10:48:22.0093 3728 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys

2011/07/31 10:48:22.0109 3728 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys

2011/07/31 10:48:22.0130 3728 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys

2011/07/31 10:48:22.0161 3728 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys

2011/07/31 10:48:22.0182 3728 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys

2011/07/31 10:48:22.0202 3728 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys

2011/07/31 10:48:22.0220 3728 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys

2011/07/31 10:48:22.0239 3728 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys

2011/07/31 10:48:22.0277 3728 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys

2011/07/31 10:48:22.0330 3728 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys

2011/07/31 10:48:22.0360 3728 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys

2011/07/31 10:48:22.0380 3728 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys

2011/07/31 10:48:22.0402 3728 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys

2011/07/31 10:48:22.0425 3728 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys

2011/07/31 10:48:22.0443 3728 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys

2011/07/31 10:48:22.0465 3728 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys

2011/07/31 10:48:22.0483 3728 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys

2011/07/31 10:48:22.0541 3728 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys

2011/07/31 10:48:22.0590 3728 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys

2011/07/31 10:48:22.0642 3728 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys

2011/07/31 10:48:22.0703 3728 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys

2011/07/31 10:48:22.0739 3728 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys

2011/07/31 10:48:22.0814 3728 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys

2011/07/31 10:48:22.0839 3728 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys

2011/07/31 10:48:22.0872 3728 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys

2011/07/31 10:48:22.0906 3728 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys

2011/07/31 10:48:22.0985 3728 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys

2011/07/31 10:48:23.0008 3728 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys

2011/07/31 10:48:23.0130 3728 PCDSRVC{1E208CE0-FB7451FF-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\dell support center\pcdsrvc_x64.pkms

2011/07/31 10:48:23.0209 3728 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys

2011/07/31 10:48:23.0241 3728 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys

2011/07/31 10:48:23.0259 3728 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys

2011/07/31 10:48:23.0286 3728 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys

2011/07/31 10:48:23.0324 3728 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys

2011/07/31 10:48:23.0413 3728 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys

2011/07/31 10:48:23.0433 3728 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys

2011/07/31 10:48:23.0472 3728 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys

2011/07/31 10:48:23.0510 3728 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys

2011/07/31 10:48:23.0557 3728 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys

2011/07/31 10:48:23.0597 3728 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys

2011/07/31 10:48:23.0654 3728 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys

2011/07/31 10:48:23.0684 3728 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys

2011/07/31 10:48:23.0714 3728 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys

2011/07/31 10:48:23.0738 3728 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys

2011/07/31 10:48:23.0770 3728 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys

2011/07/31 10:48:23.0792 3728 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys

2011/07/31 10:48:23.0816 3728 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys

2011/07/31 10:48:23.0837 3728 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys

2011/07/31 10:48:23.0859 3728 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys

2011/07/31 10:48:23.0882 3728 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys

2011/07/31 10:48:23.0906 3728 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys

2011/07/31 10:48:23.0926 3728 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys

2011/07/31 10:48:23.0966 3728 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys

2011/07/31 10:48:24.0020 3728 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys

2011/07/31 10:48:24.0084 3728 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys

2011/07/31 10:48:24.0129 3728 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys

2011/07/31 10:48:24.0165 3728 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys

2011/07/31 10:48:24.0196 3728 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys

2011/07/31 10:48:24.0214 3728 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys

2011/07/31 10:48:24.0242 3728 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys

2011/07/31 10:48:24.0279 3728 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys

2011/07/31 10:48:24.0301 3728 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys

2011/07/31 10:48:24.0317 3728 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys

2011/07/31 10:48:24.0336 3728 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys

2011/07/31 10:48:24.0398 3728 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys

2011/07/31 10:48:24.0412 3728 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys

2011/07/31 10:48:24.0425 3728 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys

2011/07/31 10:48:24.0463 3728 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys

2011/07/31 10:48:24.0510 3728 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys

2011/07/31 10:48:24.0538 3728 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys

2011/07/31 10:48:24.0576 3728 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys

2011/07/31 10:48:24.0617 3728 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys

2011/07/31 10:48:24.0661 3728 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys

2011/07/31 10:48:24.0721 3728 taphss (f33fdc72298df4bf9813a55d21f4eb31) C:\Windows\system32\DRIVERS\taphss.sys

2011/07/31 10:48:24.0796 3728 Tcpip (61dc720bb065d607d5823f13d2a64321) C:\Windows\system32\drivers\tcpip.sys

2011/07/31 10:48:24.0862 3728 TCPIP6 (61dc720bb065d607d5823f13d2a64321) C:\Windows\system32\DRIVERS\tcpip.sys

2011/07/31 10:48:24.0898 3728 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys

2011/07/31 10:48:24.0924 3728 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys

2011/07/31 10:48:24.0936 3728 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys

2011/07/31 10:48:24.0989 3728 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys

2011/07/31 10:48:25.0016 3728 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys

2011/07/31 10:48:25.0058 3728 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys

2011/07/31 10:48:25.0073 3728 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys

2011/07/31 10:48:25.0097 3728 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys

2011/07/31 10:48:25.0127 3728 udfs (31ba4a33afab6a69ea092b18017f737f) C:\Windows\system32\DRIVERS\udfs.sys

2011/07/31 10:48:25.0195 3728 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys

2011/07/31 10:48:25.0215 3728 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys

2011/07/31 10:48:25.0253 3728 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys

2011/07/31 10:48:25.0294 3728 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys

2011/07/31 10:48:25.0333 3728 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys

2011/07/31 10:48:25.0369 3728 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\Windows\system32\DRIVERS\usbccgp.sys

2011/07/31 10:48:25.0391 3728 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys

2011/07/31 10:48:25.0411 3728 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\Windows\system32\drivers\usbehci.sys

2011/07/31 10:48:25.0435 3728 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\Windows\system32\DRIVERS\usbhub.sys

2011/07/31 10:48:25.0479 3728 usbio (5c4219c10b5887dff85e1d2779aed55b) C:\Windows\system32\Drivers\dsiarhwprog_x64.sys

2011/07/31 10:48:25.0509 3728 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\Windows\system32\drivers\usbohci.sys

2011/07/31 10:48:25.0528 3728 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys

2011/07/31 10:48:25.0568 3728 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys

2011/07/31 10:48:25.0615 3728 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\drivers\USBSTOR.SYS

2011/07/31 10:48:25.0668 3728 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\Windows\system32\drivers\usbuhci.sys

2011/07/31 10:48:25.0714 3728 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys

2011/07/31 10:48:25.0747 3728 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys

2011/07/31 10:48:25.0771 3728 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys

2011/07/31 10:48:25.0794 3728 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys

2011/07/31 10:48:25.0840 3728 vhidmini (1161acff728d97f75d74d2f1465f8a46) C:\Windows\system32\DRIVERS\vHidDev.sys

2011/07/31 10:48:25.0867 3728 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys

2011/07/31 10:48:25.0888 3728 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys

2011/07/31 10:48:25.0908 3728 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys

2011/07/31 10:48:25.0934 3728 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys

2011/07/31 10:48:25.0967 3728 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys

2011/07/31 10:48:25.0997 3728 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys

2011/07/31 10:48:26.0027 3728 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys

2011/07/31 10:48:26.0054 3728 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys

2011/07/31 10:48:26.0068 3728 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys

2011/07/31 10:48:26.0156 3728 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys

2011/07/31 10:48:26.0184 3728 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys

2011/07/31 10:48:26.0254 3728 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys

2011/07/31 10:48:26.0295 3728 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys

2011/07/31 10:48:26.0319 3728 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys

2011/07/31 10:48:26.0420 3728 WinUsb (4d52c872018af7e18d078978dcc3f6f2) C:\Windows\system32\DRIVERS\WinUsb.sys

2011/07/31 10:48:26.0436 3728 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys

2011/07/31 10:48:26.0485 3728 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys

2011/07/31 10:48:26.0530 3728 WudfPf (c63907207b837a5c05cf6d1606aa0008) C:\Windows\system32\drivers\WudfPf.sys

2011/07/31 10:48:26.0572 3728 WUDFRd (d885a873d733020f8b9b9ff4b1666158) C:\Windows\system32\DRIVERS\WUDFRd.sys

2011/07/31 10:48:26.0721 3728 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0

2011/07/31 10:48:26.0741 3728 Boot (0x1200) (bc9a11633259728740939cf0e71a0b4a) \Device\Harddisk0\DR0\Partition0

2011/07/31 10:48:26.0752 3728 Boot (0x1200) (49a3865dff989b9ba35ece3357abcccc) \Device\Harddisk0\DR0\Partition1

2011/07/31 10:48:26.0755 3728 ================================================================================

2011/07/31 10:48:26.0755 3728 Scan finished

2011/07/31 10:48:26.0755 3728 ================================================================================

2011/07/31 10:48:26.0764 2732 Detected object count: 0

2011/07/31 10:48:26.0764 2732 Actual detected object count: 0

Link to post
Share on other sites

I couldn't fit the ComboFix log in one post, so I attached it to this one. o_o

CheckUp..

Results of screen317's Security Check version 0.99.18

Windows 7 (UAC is disabled!)

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

avast! Free Antivirus

WMI entry may not exist for antivirus; attempting automatic update.

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

CCleaner

Java 6 Update 23

Out of date Java installed!

Adobe Flash Player 10.3.181.26

Mozilla Firefox (3.6.18) Firefox Out of Date!

````````````````````````````````

Process Check:

objlist.exe by Laurent

Malwarebytes' Anti-Malware mbam.exe

AVAST Software Avast AvastSvc.exe

AVAST Software Avast AvastUI.exe

``````````End of Log````````````

combofix.txt

Link to post
Share on other sites

That ComboFix log was a doozy :lol:!

Let's run a few more scans:

Please print out these instructions or copy them to a Notepad file for an easier reading and download MBRCheck by a_d_13 to your Desktop from one of these locations:

http://ad13.geekstogo.com/MBRCheck.exe

http://download.bleepingcomputer.com/rootrepeal/MBRCheck.exe

http://www.kernelmode.info/MBRCheck.exe

Close all opened programs/ windows and double-click on MBRCheck.exe.

It will produce a log file saved automatically on your Desktop as "MBRCheck_[Date]_[Time].txt".

Press the "Enter" key to close the MBRCheck window and post the contents of the log file.

--------

Please do the following:

  • Please download aswMBR.exe from here and save it to your Desktop.
  • Double click aswMBR.exe to start the tool. (Vista - Win 7 Rt click to run as Administrator)
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your Desktop, and post that log in your next reply. Do NOT attempt any Fix at this time!
  • This will also create a file on your Desktop named MBR.dat. Right click that file and select Send To->Compressed (zipped) folder. Attach that zipped folder in your next reply as well.

--------

Please include the MBRCheck log, the aswMBR report, and the MBR.dat zip file in your next reply ;)

Link to post
Share on other sites

MBRCheck

--

MBRCheck, version 1.2.3

© 2010, AD

Command-line:

Windows Version: Windows 7 Home Premium Edition

Windows Information: (build 7600), 64-bit

Base Board Manufacturer: Dell Inc.

BIOS Manufacturer: Dell Inc.

System Manufacturer: Dell Inc.

System Product Name: Studio XPS 8100

Logical Drives Mask: 0x000003fc

Kernel Drivers (total 188):

0x02C52000 \SystemRoot\system32\ntoskrnl.exe

0x02C09000 \SystemRoot\system32\hal.dll

0x00BAB000 \SystemRoot\system32\kdcom.dll

0x00CA2000 \SystemRoot\system32\mcupdate_GenuineIntel.dll

0x00CE6000 \SystemRoot\system32\PSHED.dll

0x00CFA000 \SystemRoot\system32\CLFS.SYS

0x00EB7000 \SystemRoot\system32\CI.dll

0x00E00000 \SystemRoot\system32\drivers\Wdf01000.sys

0x00EA4000 \SystemRoot\system32\drivers\WDFLDR.SYS

0x00F77000 \SystemRoot\system32\DRIVERS\ACPI.sys

0x00FCE000 \SystemRoot\system32\DRIVERS\WMILIB.SYS

0x00FD7000 \SystemRoot\system32\DRIVERS\msisadrv.sys

0x00FE1000 \SystemRoot\system32\DRIVERS\vdrvroot.sys

0x00D58000 \SystemRoot\system32\DRIVERS\pci.sys

0x00D8B000 \SystemRoot\System32\drivers\partmgr.sys

0x00DA0000 \SystemRoot\system32\DRIVERS\volmgr.sys

0x00C00000 \SystemRoot\System32\drivers\volmgrx.sys

0x00C5C000 \SystemRoot\System32\drivers\mountmgr.sys

0x010EB000 \SystemRoot\system32\DRIVERS\iaStor.sys

0x012F3000 \SystemRoot\system32\drivers\amdxata.sys

0x012FE000 \SystemRoot\system32\drivers\fltmgr.sys

0x0134A000 \SystemRoot\system32\drivers\fileinfo.sys

0x0135E000 \SystemRoot\System32\Drivers\PxHlpa64.sys

0x01428000 \SystemRoot\System32\Drivers\Ntfs.sys

0x0136A000 \SystemRoot\System32\Drivers\msrpc.sys

0x015CA000 \SystemRoot\System32\Drivers\ksecdd.sys

0x01000000 \SystemRoot\System32\Drivers\cng.sys

0x015E4000 \SystemRoot\System32\drivers\pcw.sys

0x015F5000 \SystemRoot\System32\Drivers\Fs_Rec.sys

0x016E2000 \SystemRoot\system32\drivers\ndis.sys

0x01600000 \SystemRoot\system32\drivers\NETIO.SYS

0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys

0x01803000 \SystemRoot\System32\drivers\tcpip.sys

0x0168B000 \SystemRoot\System32\drivers\fwpkclnt.sys

0x01073000 \SystemRoot\system32\DRIVERS\volsnap.sys

0x016D5000 \SystemRoot\System32\Drivers\spldr.sys

0x00DB5000 \SystemRoot\System32\drivers\rdyboost.sys

0x017D4000 \SystemRoot\System32\Drivers\mup.sys

0x017E6000 \SystemRoot\System32\drivers\hwpolicy.sys

0x01A0D000 \SystemRoot\System32\DRIVERS\fvevol.sys

0x01A47000 \SystemRoot\system32\DRIVERS\disk.sys

0x01A5D000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS

0x044D9000 \SystemRoot\system32\DRIVERS\cdrom.sys

0x04503000 \SystemRoot\System32\Drivers\aswSnx.SYS

0x0459B000 \SystemRoot\System32\Drivers\Null.SYS

0x045A4000 \SystemRoot\System32\Drivers\Beep.SYS

0x045AB000 \SystemRoot\System32\drivers\vga.sys

0x045B9000 \SystemRoot\System32\drivers\VIDEOPRT.SYS

0x045DE000 \SystemRoot\System32\drivers\watchdog.sys

0x045EE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys

0x045F7000 \SystemRoot\system32\drivers\rdpencdd.sys

0x04200000 \SystemRoot\system32\drivers\rdprefmp.sys

0x04209000 \SystemRoot\System32\Drivers\Msfs.SYS

0x04214000 \SystemRoot\System32\Drivers\Npfs.SYS

0x04225000 \SystemRoot\system32\DRIVERS\tdx.sys

0x04243000 \SystemRoot\system32\DRIVERS\TDI.SYS

0x04250000 \SystemRoot\System32\Drivers\aswTdi.SYS

0x0425E000 \SystemRoot\System32\DRIVERS\netbt.sys

0x01A9B000 \SystemRoot\system32\drivers\afd.sys

0x042A3000 \SystemRoot\System32\Drivers\aswRdr.SYS

0x042AD000 \SystemRoot\system32\DRIVERS\wfplwf.sys

0x01B24000 \SystemRoot\system32\DRIVERS\pacer.sys

0x01B4A000 \SystemRoot\system32\DRIVERS\netbios.sys

0x01B59000 \SystemRoot\system32\DRIVERS\wanarp.sys

0x01B74000 \SystemRoot\system32\DRIVERS\termdd.sys

0x01B88000 \SystemRoot\system32\DRIVERS\rdbss.sys

0x01BD9000 \SystemRoot\system32\drivers\nsiproxy.sys

0x01BE5000 \SystemRoot\system32\DRIVERS\mssmbios.sys

0x01BF0000 \SystemRoot\System32\drivers\discache.sys

0x01400000 \SystemRoot\System32\Drivers\dfsc.sys

0x017EF000 \SystemRoot\system32\DRIVERS\blbdrive.sys

0x02E83000 \SystemRoot\System32\Drivers\aswSP.SYS

0x02ED0000 \SystemRoot\system32\DRIVERS\tunnel.sys

0x02EF6000 \SystemRoot\system32\DRIVERS\intelppm.sys

0x02F0C000 \SystemRoot\system32\DRIVERS\atikmpag.sys

0x04A07000 \SystemRoot\system32\DRIVERS\atikmdag.sys

0x0469A000 \SystemRoot\System32\drivers\dxgkrnl.sys

0x0478E000 \SystemRoot\System32\drivers\dxgmms1.sys

0x047D4000 \SystemRoot\system32\DRIVERS\HDAudBus.sys

0x04600000 \SystemRoot\system32\DRIVERS\HECIx64.sys

0x04611000 \SystemRoot\system32\drivers\usbehci.sys

0x04622000 \SystemRoot\system32\drivers\USBPORT.SYS

0x02F57000 \SystemRoot\system32\DRIVERS\1394ohci.sys

0x02F95000 \SystemRoot\system32\DRIVERS\k57nd60a.sys

0x04678000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys

0x04685000 \SystemRoot\system32\DRIVERS\CompositeBus.sys

0x051DD000 \SystemRoot\system32\DRIVERS\AgileVpn.sys

0x02E00000 \SystemRoot\system32\DRIVERS\rasl2tp.sys

0x051F3000 \SystemRoot\system32\DRIVERS\ndistapi.sys

0x02E24000 \SystemRoot\system32\DRIVERS\ndiswan.sys

0x02E53000 \SystemRoot\system32\DRIVERS\raspppoe.sys

0x010BF000 \SystemRoot\system32\DRIVERS\raspptp.sys

0x02FE6000 \SystemRoot\system32\DRIVERS\rassstp.sys

0x04695000 \SystemRoot\system32\DRIVERS\vHidDev.sys

0x013C8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS

0x02E6E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS

0x013E1000 \SystemRoot\system32\DRIVERS\kbdclass.sys

0x013F0000 \SystemRoot\system32\DRIVERS\mouclass.sys

0x04697000 \SystemRoot\system32\DRIVERS\swenum.sys

0x05496000 \SystemRoot\system32\DRIVERS\ks.sys

0x054D9000 \SystemRoot\system32\DRIVERS\umbus.sys

0x054EB000 \SystemRoot\system32\DRIVERS\usbhub.sys

0x05545000 \SystemRoot\System32\Drivers\NDProxy.SYS

0x0555A000 \SystemRoot\system32\DRIVERS\mouhid.sys

0x05567000 \SystemRoot\system32\DRIVERS\kbdhid.sys

0x05575000 \SystemRoot\system32\drivers\AtiHdmi.sys

0x05597000 \SystemRoot\system32\drivers\portcls.sys

0x055D4000 \SystemRoot\system32\drivers\drmk.sys

0x055F6000 \SystemRoot\system32\drivers\ksthunk.sys

0x05E04000 \SystemRoot\system32\drivers\RTKVHD64.sys

0x05400000 \SystemRoot\system32\DRIVERS\IntcDAud.sys

0x05FED000 \SystemRoot\system32\drivers\danew.sys

0x05FF0000 \SystemRoot\system32\DRIVERS\hidusb.sys

0x05FFE000 \SystemRoot\system32\DRIVERS\USBD.SYS

0x00080000 \SystemRoot\System32\win32k.sys

0x0543E000 \SystemRoot\System32\drivers\Dxapi.sys

0x0544A000 \SystemRoot\system32\DRIVERS\usbccgp.sys

0x05467000 \SystemRoot\System32\Drivers\crashdmp.sys

0x042B6000 \SystemRoot\System32\Drivers\dump_iaStor.sys

0x05475000 \SystemRoot\System32\Drivers\dump_dumpfve.sys

0x044BE000 \SystemRoot\system32\drivers\USBSTOR.SYS

0x05488000 \SystemRoot\system32\DRIVERS\monitor.sys

0x00400000 \SystemRoot\System32\TSDDD.dll

0x006C0000 \SystemRoot\System32\cdd.dll

0x00C76000 \SystemRoot\system32\drivers\luafv.sys

0x02CF7000 \??\C:\Windows\system32\drivers\aswMonFlt.sys

0x02D31000 \SystemRoot\System32\Drivers\aswFsBlk.SYS

0x02D3A000 \SystemRoot\system32\drivers\WudfPf.sys

0x02D5B000 \SystemRoot\system32\DRIVERS\lltdio.sys

0x02D70000 \SystemRoot\system32\DRIVERS\rspndr.sys

0x02C00000 \SystemRoot\system32\drivers\HTTP.sys

0x02CC8000 \SystemRoot\system32\DRIVERS\bowser.sys

0x02D88000 \SystemRoot\System32\drivers\mpsdrv.sys

0x02DA0000 \SystemRoot\system32\DRIVERS\mrxsmb.sys

0x05600000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys

0x0564E000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys

0x05671000 \SystemRoot\system32\drivers\peauth.sys

0x05717000 \SystemRoot\System32\Drivers\secdrv.SYS

0x05722000 \SystemRoot\System32\DRIVERS\srvnet.sys

0x0574F000 \SystemRoot\System32\drivers\tcpipreg.sys

0x05761000 \SystemRoot\System32\DRIVERS\srv2.sys

0x07EFE000 \SystemRoot\System32\DRIVERS\srv.sys

0x07F93000 \SystemRoot\system32\DRIVERS\WUDFRd.sys

0x07FC4000 \SystemRoot\System32\Drivers\fastfat.SYS

0x07E71000 \??\C:\Windows\system32\Drivers\PROCEXP113.SYS

0x07E8A000 \SystemRoot\system32\DRIVERS\dtsoftbus01.sys

0x07ED0000 \SystemRoot\system32\DRIVERS\cdfs.sys

0x07EED000 \??\c:\program files\dell support center\pcdsrvc_x64.pkms

0x77320000 \Windows\System32\ntdll.dll

0x47BB0000 \Windows\System32\smss.exe

0xFF640000 \Windows\System32\apisetschema.dll

0xFFD80000 \Windows\System32\autochk.exe

0xFF560000 \Windows\System32\usp10.dll

0xFF350000 \Windows\System32\ole32.dll

0xFF340000 \Windows\System32\nsi.dll

0xFF2F0000 \Windows\System32\Wldap32.dll

0xFF270000 \Windows\System32\difxapi.dll

0xFF1F0000 \Windows\System32\shlwapi.dll

0xFF1A0000 \Windows\System32\ws2_32.dll

0xFF190000 \Windows\System32\lpk.dll

0xFF060000 \Windows\System32\rpcrt4.dll

0x77200000 \Windows\System32\kernel32.dll

0xFE2D0000 \Windows\System32\shell32.dll

0xFE260000 \Windows\System32\gdi32.dll

0x774F0000 \Windows\System32\normaliz.dll

0xFE1C0000 \Windows\System32\clbcatq.dll

0xFE0E0000 \Windows\System32\advapi32.dll

0xFE040000 \Windows\System32\msvcrt.dll

0xFDF60000 \Windows\System32\oleaut32.dll

0x77100000 \Windows\System32\user32.dll

0xFDEC0000 \Windows\System32\comdlg32.dll

0x774E0000 \Windows\System32\psapi.dll

0xFDD40000 \Windows\System32\urlmon.dll

0xFDC10000 \Windows\System32\wininet.dll

0xFDBE0000 \Windows\System32\imm32.dll

0xFDA00000 \Windows\System32\setupapi.dll

0xFD9E0000 \Windows\System32\sechost.dll

0xFD9C0000 \Windows\System32\imagehlp.dll

0xFD8B0000 \Windows\System32\msctf.dll

0xFD650000 \Windows\System32\iertutil.dll

0xFD610000 \Windows\System32\wintrust.dll

0xFD570000 \Windows\System32\comctl32.dll

0xFD400000 \Windows\System32\crypt32.dll

0xFD390000 \Windows\System32\KernelBase.dll

0xFD350000 \Windows\System32\cfgmgr32.dll

0xFD330000 \Windows\System32\devobj.dll

0xFD320000 \Windows\System32\msasn1.dll

0x774D0000 \Windows\SysWOW64\normaliz.dll

Processes (total 73):

0 System Idle Process

4 System

388 C:\Windows\System32\smss.exe

520 csrss.exe

584 C:\Windows\System32\wininit.exe

604 csrss.exe

640 C:\Windows\System32\services.exe

668 C:\Windows\System32\lsass.exe

676 C:\Windows\System32\lsm.exe

764 C:\Windows\System32\winlogon.exe

828 C:\Windows\System32\svchost.exe

920 C:\Windows\System32\svchost.exe

968 C:\Windows\System32\atiesrxx.exe

156 C:\Windows\System32\svchost.exe

528 C:\Windows\System32\svchost.exe

732 C:\Windows\System32\svchost.exe

1124 C:\Windows\System32\svchost.exe

1180 C:\Program Files\Dell\DellDock\DockLogin.exe

1224 C:\Windows\System32\atieclxx.exe

1276 C:\Windows\System32\svchost.exe

1408 C:\Program Files\AVAST Software\Avast\AvastSvc.exe

1784 C:\Windows\System32\spoolsv.exe

1820 C:\Windows\System32\svchost.exe

1936 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

1964 C:\Program Files (x86)\Bonjour\mDNSResponder.exe

1988 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe

2100 C:\Windows\System32\spool\drivers\x64\3\dleaserv.exe

2332 C:\Windows\System32\dleacoms.exe

2432 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

2492 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe

2560 C:\Windows\System32\svchost.exe

2624 C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe

2668 C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

2760 C:\Windows\System32\taskhost.exe

2816 C:\Windows\System32\dwm.exe

2848 C:\Windows\explorer.exe

1884 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAEM.exe

3024 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

3636 C:\Windows\System32\svchost.exe

3724 C:\Windows\System32\svchost.exe

3840 WUDFHost.exe

2128 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

1056 C:\Windows\System32\rundll32.exe

1036 C:\Windows\System32\rundll32.exe

3940 C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe

2968 C:\Windows\System32\SearchIndexer.exe

2064 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

3860 C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

4196 C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

4308 C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

4448 C:\Program Files (x86)\Razer\DeathAdder\razertra.exe

4456 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

4464 C:\Program Files\Windows Media Player\wmpnetwk.exe

4472 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

4480 C:\Program Files\AVAST Software\Avast\AvastUI.exe

4516 C:\Program Files (x86)\iTunes\iTunesHelper.exe

4556 C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe

4908 C:\Windows\System32\svchost.exe

5112 C:\Program Files\iPod\bin\iPodService.exe

3344 C:\Windows\SysWOW64\ctfmon.exe

4936 C:\Windows\System32\svchost.exe

4240 C:\Windows\System32\wuauclt.exe

1876 C:\Windows\System32\audiodg.exe

856 C:\Windows\SysWOW64\svchost.exe

6324 C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe

8184 C:\Windows\System32\taskhost.exe

5564 C:\Windows\System32\SearchProtocolHost.exe

6604 C:\Program Files\Dell Support Center\pcdrcui.exe

4136 C:\Windows\System32\SearchFilterHost.exe

8364 C:\Windows\System32\notepad.exe

8356 C:\Program Files (x86)\Real\RealPlayer\realplay.exe

4108 C:\Users\troyswi\Desktop\MBRCheck.exe

7052 C:\Windows\System32\conhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`bae00000 (NTFS)

PhysicalDrive0 Model Number: ST31000528AS, Rev: CC46

Size Device Name MBR Status

--------------------------------------------

931 GB \\.\PhysicalDrive0 Dell Inspiron MBR code detected

SHA1: AE3E0A945D44C8EA304A19A8F50F69065C34344B

Done!

--

aswMBR

aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software

Run date: 2011-07-31 16:20:21

-----------------------------

16:20:21.042 OS Version: Windows x64 6.1.7600

16:20:21.042 Number of processors: 8 586 0x1E05

16:20:21.043 ComputerName: STEVESWI-PC UserName: troyswi

16:20:25.472 Initialize success

16:20:25.710 AVAST engine defs: 11073100

16:20:29.180 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1

16:20:29.182 Disk 0 Vendor: ST310005 CC46 Size: 953869MB BusType: 8

16:20:29.198 Disk 0 MBR read successfully

16:20:29.201 Disk 0 MBR scan

16:20:29.203 Disk 0 Windows VISTA default MBR code

16:20:29.205 Service scanning

16:20:31.915 Modules scanning

16:20:31.918 Disk 0 trace - called modules:

16:20:31.936 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll

16:20:31.939 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007e78060]

16:20:31.942 3 CLASSPNP.SYS[fffff88001a5e43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007adf050]

16:20:33.749 AVAST engine scan C:\Windows

16:20:37.087 AVAST engine scan C:\Windows\system32

16:21:49.487 AVAST engine scan C:\Windows\system32\drivers

16:22:03.181 AVAST engine scan C:\Users\troyswi

16:22:47.118 Disk 0 MBR has been saved successfully to "C:\Users\troyswi\Desktop\MBR.dat"

16:22:47.123 The log file has been saved successfully to "C:\Users\troyswi\Desktop\aswMBR.txt"

MBR.zip

Link to post
Share on other sites

ComboFix 11-07-31.04 - troyswi 08/01/2011 11:46:50.2.8 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8151.6316 [GMT -4:00]

Running from: c:\users\troyswi\Desktop\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))

.

.

2011-08-01 15:54 . 2011-08-01 15:54 -------- d-----w- c:\users\tammiswi\AppData\Local\temp

2011-08-01 15:54 . 2011-08-01 15:54 -------- d-----w- c:\users\steveswi\AppData\Local\temp

2011-08-01 15:54 . 2011-08-01 15:54 -------- d-----w- c:\users\steffiswi\AppData\Local\temp

2011-08-01 15:54 . 2011-08-01 15:54 -------- d-----w- c:\users\Guest\AppData\Local\temp

2011-08-01 15:54 . 2011-08-01 15:54 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-07-31 17:43 . 2011-07-31 17:43 376320 ----a-r- c:\users\troyswi\AppData\Roaming\Microsoft\Installer\{52B65911-1559-4ED5-9461-46957FDD48CD}\Icon52B659113.exe

2011-07-31 17:37 . 2011-07-31 17:37 -------- d-----w- c:\program files (x86)\2K Games

2011-07-31 17:35 . 2011-07-31 17:35 -------- d-----w- c:\program files (x86)\AGEIA Technologies

2011-07-31 17:35 . 2011-07-31 17:35 -------- d-----w- c:\windows\SysWow64\AGEIA

2011-07-31 17:30 . 2011-07-31 17:30 272448 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys

2011-07-31 17:30 . 2011-07-31 17:30 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro

2011-07-31 17:29 . 2011-07-31 17:32 -------- d-----w- c:\users\troyswi\AppData\Roaming\DAEMON Tools Pro

2011-07-31 17:29 . 2011-07-31 17:30 -------- d-----w- c:\programdata\DAEMON Tools Pro

2011-07-20 14:24 . 2011-07-20 14:24 -------- d-----w- c:\users\Default\AppData\Roaming\Xfire

2011-07-20 14:21 . 2011-07-20 14:21 -------- d-----w- c:\windows\SysWow64\config\systemprofile\Tracing

2011-07-20 14:18 . 2011-07-20 14:18 -------- d-sh--w- c:\windows\system32\%APPDATA%

2011-07-13 12:15 . 2011-06-02 06:45 243200 ----a-w- c:\windows\system32\wow64.dll

2011-07-13 12:15 . 2011-06-02 06:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll

2011-07-13 12:15 . 2011-06-02 06:42 16384 ----a-w- c:\windows\system32\ntvdm64.dll

2011-07-13 12:15 . 2011-06-02 05:59 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

2011-07-13 12:15 . 2011-06-02 05:56 25600 ----a-w- c:\windows\SysWow64\setup16.exe

2011-07-13 12:15 . 2011-06-02 05:54 5120 ----a-w- c:\windows\SysWow64\wow32.dll

2011-07-13 12:15 . 2011-06-02 03:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe

2011-07-13 12:15 . 2011-06-02 03:50 2048 ----a-w- c:\windows\SysWow64\user.exe

2011-07-08 18:01 . 2011-07-08 18:01 -------- d-----w- c:\program files\iPod

2011-07-08 18:00 . 2011-07-08 18:00 -------- d-----w- c:\program files (x86)\Apple Software Update

2011-07-08 17:59 . 2011-07-08 17:59 -------- d-----w- c:\program files\Bonjour

2011-07-08 17:59 . 2011-07-08 17:59 -------- d-----w- c:\program files (x86)\Bonjour

2011-07-03 20:02 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-07-03 20:02 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-07-03 20:02 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe

2011-07-03 20:02 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-07-03 20:02 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-07-03 20:02 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-07-03 20:02 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2011-07-03 20:02 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr

2011-07-03 20:02 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe

2011-07-03 20:02 . 2011-07-03 20:02 -------- d-----w- c:\programdata\AVAST Software

2011-07-03 20:02 . 2011-07-03 20:02 -------- d-----w- c:\program files\AVAST Software

2011-07-03 01:30 . 2011-07-03 01:30 -------- d-----w- c:\programdata\SUPERAntiSpyware.com

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-07-07 15:51 . 2011-05-17 17:50 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-07-06 23:52 . 2010-09-08 19:50 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-07-06 23:52 . 2010-09-08 19:50 25912 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-20 12:57 . 2011-06-29 23:33 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E0BF790A-8F23-4DC6-9B78-347AE6DC5A9E}\mpengine.dll

2011-06-02 05:56 . 2011-07-13 12:15 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2011-05-29 21:17 . 2003-03-19 01:14 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll

2011-05-29 21:17 . 2003-02-21 09:42 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll

2011-05-28 03:25 . 2011-06-16 09:57 1638912 ----a-w- c:\windows\system32\mshtml.tlb

2011-05-28 03:00 . 2011-06-16 09:57 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb

2011-05-24 23:14 . 2011-06-29 23:33 270720 ------w- c:\windows\system32\MpSigStub.exe

2011-05-24 11:21 . 2011-06-29 23:15 404992 ----a-w- c:\windows\system32\umpnpmgr.dll

2011-05-24 10:34 . 2011-06-29 23:15 64512 ----a-w- c:\windows\SysWow64\devobj.dll

2011-05-24 10:34 . 2011-06-29 23:15 44544 ----a-w- c:\windows\SysWow64\devrtl.dll

2011-05-24 10:34 . 2011-06-29 23:15 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll

2011-05-24 10:32 . 2011-06-29 23:15 252928 ----a-w- c:\windows\SysWow64\drvinst.exe

2011-05-10 12:06 . 2011-05-10 12:06 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys

2011-05-10 12:06 . 2011-05-10 12:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll

2011-05-08 14:59 . 2011-05-08 14:59 380008 ----a-w- c:\windows\SysWow64\PMangAX0.dll

2011-05-04 05:30 . 2011-06-29 23:15 2326016 ----a-w- c:\windows\system32\tquery.dll

2011-05-04 05:28 . 2011-06-29 23:15 2228224 ----a-w- c:\windows\system32\mssrch.dll

2011-05-04 05:28 . 2011-06-29 23:15 779264 ----a-w- c:\windows\system32\mssvp.dll

2011-05-04 05:28 . 2011-06-29 23:15 75264 ----a-w- c:\windows\system32\msscntrs.dll

2011-05-04 05:28 . 2011-06-29 23:15 491520 ----a-w- c:\windows\system32\mssph.dll

2011-05-04 05:28 . 2011-06-29 23:15 288256 ----a-w- c:\windows\system32\mssphtb.dll

2011-05-04 05:24 . 2011-06-29 23:15 593408 ----a-w- c:\windows\system32\SearchIndexer.exe

2011-05-04 05:24 . 2011-06-29 23:15 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe

2011-05-04 05:24 . 2011-06-29 23:15 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe

2011-05-04 04:53 . 2011-06-29 23:15 1553920 ----a-w- c:\windows\SysWow64\tquery.dll

2011-05-04 04:52 . 2011-06-29 23:15 1401856 ----a-w- c:\windows\SysWow64\mssrch.dll

2011-05-04 04:52 . 2011-06-29 23:15 666624 ----a-w- c:\windows\SysWow64\mssvp.dll

2011-05-04 04:52 . 2011-06-29 23:15 337408 ----a-w- c:\windows\SysWow64\mssph.dll

2011-05-04 04:52 . 2011-06-29 23:15 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll

2011-05-04 04:52 . 2011-06-29 23:15 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll

2011-05-04 04:52 . 2011-06-29 23:15 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe

2011-05-04 04:52 . 2011-06-29 23:15 428032 ----a-w- c:\windows\SysWow64\SearchIndexer.exe

2011-05-04 04:52 . 2011-06-29 23:15 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe

2011-05-04 02:51 . 2011-06-16 09:57 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys

2011-05-04 02:51 . 2011-06-16 09:57 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-05-04 02:51 . 2011-06-16 09:57 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys

.

.

((((((((((((((((((((((((((((( SnapShot@2011-07-31_15.12.00 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-10-29 13:03 . 2008-10-29 13:03 70936 c:\windows\SysWOW64\PhysXLoader.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 23320 c:\windows\SysWOW64\PhysXDevice.dll

+ 2009-07-14 04:54 . 2011-08-01 15:56 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:54 . 2011-07-31 15:11 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:54 . 2011-07-31 15:11 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2011-08-01 15:56 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2011-07-31 15:11 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2011-08-01 15:56 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelTraditionalChinese.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelSwedish.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelSpanish.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelSimplifiedChinese.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelPortugese.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelKorean.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelJapanese.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelGerman.dll

+ 2008-10-07 13:13 . 2008-10-07 13:13 58648 c:\windows\SysWOW64\AgCPanelFrench.dll

+ 2010-08-30 21:48 . 2011-08-01 15:57 71560 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2011-08-01 15:43 31174 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2010-09-08 19:37 . 2011-08-01 15:57 21702 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3033937009-333567816-1246851426-1003_UserData.bin

- 2009-07-14 05:30 . 2011-07-14 07:18 86016 c:\windows\system32\DriverStore\infpub.dat

+ 2009-07-14 05:30 . 2011-07-31 17:30 86016 c:\windows\system32\DriverStore\infpub.dat

+ 2010-09-07 22:32 . 2011-07-31 17:43 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-09-07 22:32 . 2011-07-26 13:19 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-09-07 22:32 . 2011-07-26 13:19 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-09-07 22:32 . 2011-07-31 17:43 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2011-07-26 13:19 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2011-07-31 17:43 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-09-08 17:01 . 2011-07-31 15:12 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-09-08 17:01 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-09-08 17:01 . 2011-07-31 15:12 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-09-08 17:01 . 2011-08-01 15:56 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-09-08 17:01 . 2011-07-31 15:12 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-09-08 17:01 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-09-07 23:54 . 2011-07-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-09-07 23:54 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-09-07 23:54 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-09-07 23:54 . 2011-07-31 15:12 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2011-07-31 17:36 . 2011-07-31 17:36 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

- 2010-12-22 21:54 . 2011-07-30 15:09 58880 c:\windows\.jagex_cache_32\runescape\jagmisc.dll

+ 2010-12-22 21:54 . 2011-07-31 23:29 58880 c:\windows\.jagex_cache_32\runescape\jagmisc.dll

- 2010-12-22 21:54 . 2011-07-30 15:09 84992 c:\windows\.jagex_cache_32\runescape\jagdx.dll

+ 2010-12-22 21:54 . 2011-07-31 23:29 84992 c:\windows\.jagex_cache_32\runescape\jagdx.dll

- 2010-12-22 21:54 . 2011-07-30 15:09 65536 c:\windows\.jagex_cache_32\runescape\hw3d.dll

+ 2010-12-22 21:54 . 2011-07-31 23:29 65536 c:\windows\.jagex_cache_32\runescape\hw3d.dll

+ 2011-08-01 15:55 . 2011-08-01 15:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2011-07-31 15:11 . 2011-07-31 15:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2011-08-01 15:55 . 2011-08-01 15:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2011-07-31 15:11 . 2011-07-31 15:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-10-07 13:13 . 2008-10-07 13:13 197912 c:\windows\SysWOW64\physxcudart_20.dll

+ 2008-10-15 13:04 . 2008-10-15 13:04 288024 c:\windows\SysWOW64\PhysXCplUI.exe

+ 2008-10-15 13:04 . 2008-10-15 13:04 288024 c:\windows\SysWOW64\PhysXCompatCplUI.exe

- 2010-09-08 21:51 . 2011-07-31 15:11 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

+ 2010-09-08 21:51 . 2011-08-01 15:55 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

+ 2008-10-07 13:13 . 2008-10-07 13:13 116977 c:\windows\SysWOW64\AGEIA\AG1021\diag.bin

+ 2008-10-07 13:13 . 2008-10-07 13:13 214629 c:\windows\SysWOW64\AGEIA\AG1021\app.bin

+ 2008-10-07 13:13 . 2008-10-07 13:13 119473 c:\windows\SysWOW64\AGEIA\AG1011\diag.bin

+ 2008-10-07 13:13 . 2008-10-07 13:13 199885 c:\windows\SysWOW64\AGEIA\AG1011\app.bin

+ 2009-07-14 02:36 . 2011-08-01 15:48 660234 c:\windows\system32\perfh009.dat

- 2009-07-14 02:36 . 2011-06-30 01:41 660234 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2011-08-01 15:48 121162 c:\windows\system32\perfc009.dat

- 2009-07-14 02:36 . 2011-06-30 01:41 121162 c:\windows\system32\perfc009.dat

- 2009-07-14 05:30 . 2011-07-14 07:18 143360 c:\windows\system32\DriverStore\infstrng.dat

+ 2009-07-14 05:30 . 2011-07-31 17:30 143360 c:\windows\system32\DriverStore\infstrng.dat

- 2009-07-14 05:30 . 2011-07-14 07:18 143360 c:\windows\system32\DriverStore\infstor.dat

+ 2009-07-14 05:30 . 2011-07-31 17:30 143360 c:\windows\system32\DriverStore\infstor.dat

+ 2011-07-31 17:30 . 2011-07-31 17:30 272448 c:\windows\system32\DriverStore\FileRepository\dtsoftbus01.inf_amd64_neutral_4baca17e76db849b\dtsoftbus01.sys

+ 2009-07-14 05:01 . 2011-08-01 15:54 419036 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2011-07-31 15:10 419036 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2010-09-08 21:56 . 2010-09-08 21:56 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

- 2010-12-22 21:54 . 2011-07-30 15:09 153088 c:\windows\.jagex_cache_32\runescape\jaggl.dll

+ 2010-12-22 21:54 . 2011-07-31 23:29 153088 c:\windows\.jagex_cache_32\runescape\jaggl.dll

+ 2010-12-22 21:54 . 2011-07-31 23:29 148480 c:\windows\.jagex_cache_32\runescape\jaclib.dll

- 2010-12-22 21:54 . 2011-07-30 15:09 148480 c:\windows\.jagex_cache_32\runescape\jaclib.dll

+ 2009-09-22 15:25 . 2009-09-22 15:25 1149952 c:\windows\Installer\847c10.msi

- 2010-09-08 21:56 . 2010-09-08 21:56 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2010-09-08 21:56 . 2010-09-08 21:56 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2011-07-31 17:36 . 2011-07-31 17:36 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2010-12-22 21:54 . 2011-07-31 23:29 1010688 c:\windows\.jagex_cache_32\runescape\sw3d.dll

- 2010-12-22 21:54 . 2011-07-30 15:09 1010688 c:\windows\.jagex_cache_32\runescape\sw3d.dll

+ 2009-07-14 02:34 . 2011-08-01 08:54 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

- 2009-07-14 02:34 . 2011-07-31 15:07 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2011-07-31 17:35 . 2011-07-31 17:35 34017280 c:\windows\Installer\847c0b.msi

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{05560ADF-7B25-40FF-B408-3F6E6F512EB4}]

c:\windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll [bU]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]

"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2009-07-17 237568]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-14 98304]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2010-02-09 1807680]

"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584]

"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]

"DeathAdder"="c:\program files (x86)\Razer\DeathAdder\razerhid.exe" [2010-05-05 251392]

"Dell V310-V510 Series"="c:\program files (x86)\Dell V310-V510 Series\fm3032.exe" [2010-01-18 316072]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-01-07 232104]

"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2011-05-29 273544]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160]

.

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\steffiswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\steveswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\tammiswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\troyswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"SoftwareSASGeneration"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R2 BPA_Execution;AutoMate BPA Server 8 Execution Server;c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_EXEC.exe [2011-02-11 376832]

R2 BPA_Management;AutoMate BPA Server 8 Management Server;c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_MAN.exe [2011-02-11 376832]

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 EFS32;Encrypting File System (EFS) ;c:\windows\system32\OnLineIDCpl32.exe [x]

R2 FLEXnet Licensing Service32;FLEXnet Licensing Service ;c:\windows\system32\catsrv32.exe [x]

R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]

R2 wcncsvc32;Windows Connect Now - Config Registrar ;c:\windows\system32\capiprovider32.exe [x]

R3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys [x]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072]

R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

R3 X6va003;X6va003;c:\users\troyswi\AppData\Local\Temp\003EA60.tmp [x]

R3 X6va005;X6va005;c:\users\troyswi\AppData\Local\Temp\0056A5A.tmp [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S1 aswSnx;aswSnx; [x]

S1 aswSP;aswSP; [x]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]

S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 aswFsBlk;aswFsBlk; [x]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]

S2 BPAAgent8;AutoMate BPA Server 8 Agent;c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe [2011-02-11 11323392]

S2 dlea_device;dlea_device;c:\windows\system32\dleacoms.exe [2010-01-07 1052328]

S2 dleaCATSCustConnectService;dleaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe [2010-01-07 33448]

S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]

S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-09-14 1956136]

S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

Akamai REG_MULTI_SZ Akamai

.

Contents of the 'Scheduled Tasks' folder

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3033937009-333567816-1246851426-1003Core.job

- c:\users\troyswi\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-10 20:20]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3033937009-333567816-1246851426-1003UA.job

- c:\users\troyswi\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-10 20:20]

.

2011-07-26 c:\windows\Tasks\One-Click Tweak.job

- c:\program files (x86)\Advanced PC Tweaker\OneClick.exe [2011-01-25 23:40]

.

2011-07-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]

.

2011-08-01 c:\windows\Tasks\SystemToolsDailyTest.job

- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-07 8158240]

"RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]

"RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]

"dleamon.exe"="c:\program files (x86)\Dell V310-V510 Series\dleamon.exe" [2010-01-18 770728]

"EzPrint"="c:\program files (x86)\Dell V310-V510 Series\ezprint.exe" [2010-01-18 139944]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://sigma.pokemonvortex.org/your_team.php

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105

IE: {{602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - {A310506F-6BA4-48c4-8887-1F462277AA12} - mscoree.dll

TCP: DhcpNameServer = 192.168.1.1 68.87.64.150 68.87.75.198

DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab

DPF: {93C449FA-ECFB-402F-A8C7-37E4F8D60E49} - hxxp://dl.pmang.com/common/pmangctl/pmangax.cab

FF - ProfilePath - c:\users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\

FF - prefs.js: browser.search.selectedEngine - DAEMON Search

FF - prefs.js: browser.startup.homepage - hxxp://forums.ijji.com/forumdisplay.php?f=79

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 64848

FF - prefs.js: network.proxy.type - 0

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - Ext: avast! WebRep: wrc@avast.com - c:\program files\AVAST Software\Avast\WebRep\FF

FF - Ext: Easy-Hide-IP Firefox Plugin: support@easy-hide-ip.com - c:\program files (x86)\Easy-Hide-IP\ff-extension

FF - Ext: iMacros for Firefox: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} - %profile%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}

FF - user.js: network.protocol-handler.warn-external.dnupdate - false

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]

"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va003]

"ImagePath"="\??\c:\users\troyswi\AppData\Local\Temp\003EA60.tmp"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005]

"ImagePath"="\??\c:\users\troyswi\AppData\Local\Temp\0056A5A.tmp"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files\AVAST Software\Avast\AvastSvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAEM.exe

c:\program files (x86)\Razer\DeathAdder\razertra.exe

c:\program files (x86)\Razer\DeathAdder\razerofa.exe

.

**************************************************************************

.

Completion time: 2011-08-01 12:01:50 - machine was rebooted

ComboFix-quarantined-files.txt 2011-08-01 16:01

ComboFix2.txt 2011-07-31 15:17

.

Pre-Run: 725,583,777,792 bytes free

Post-Run: 725,326,815,232 bytes free

.

- - End Of File - - 8A5A2CC6A0C103AC800C241464590617

Link to post
Share on other sites

First, do you recognize these 2 websites?

bgweb.nowcdn.co.kr

pmang.com

Please let me know :)

-------

Next, please do the following:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KILLALL::

Driver::

X6va003

X6va005

File::

c:\users\troyswi\AppData\Local\Temp\003EA60.tmp

c:\users\troyswi\AppData\Local\Temp\0056A5A.tmp

Reglock::

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now ;)

Link to post
Share on other sites

The first website, I do not recognize.

The second, however, I do. It's Korean, but I play(ed) a game called "Special Force" hosted by the company.

--

ComboFix 11-08-01.02 - troyswi 08/01/2011 13:34:58.3.8 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.8151.6057 [GMT -4:00]

Running from: c:\users\troyswi\Desktop\ComboFix.exe

Command switches used :: c:\users\troyswi\Desktop\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

FILE ::

"c:\users\troyswi\AppData\Local\Temp\003EA60.tmp"

"c:\users\troyswi\AppData\Local\Temp\0056A5A.tmp"

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_X6VA003

-------\Legacy_X6VA005

-------\Service_X6va003

-------\Service_X6va005

.

.

((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))

.

.

2011-08-01 17:40 . 2011-08-01 17:40 -------- d-----w- c:\users\tammiswi\AppData\Local\temp

2011-08-01 17:40 . 2011-08-01 17:40 -------- d-----w- c:\users\steveswi\AppData\Local\temp

2011-08-01 17:40 . 2011-08-01 17:40 -------- d-----w- c:\users\steffiswi\AppData\Local\temp

2011-08-01 17:40 . 2011-08-01 17:40 -------- d-----w- c:\users\Guest\AppData\Local\temp

2011-08-01 17:40 . 2011-08-01 17:40 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-07-31 17:43 . 2011-07-31 17:43 376320 ----a-r- c:\users\troyswi\AppData\Roaming\Microsoft\Installer\{52B65911-1559-4ED5-9461-46957FDD48CD}\Icon52B659113.exe

2011-07-31 17:37 . 2011-07-31 17:37 -------- d-----w- c:\program files (x86)\2K Games

2011-07-31 17:35 . 2011-07-31 17:35 -------- d-----w- c:\program files (x86)\AGEIA Technologies

2011-07-31 17:35 . 2011-07-31 17:35 -------- d-----w- c:\windows\SysWow64\AGEIA

2011-07-31 17:30 . 2011-07-31 17:30 272448 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys

2011-07-31 17:30 . 2011-07-31 17:30 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro

2011-07-31 17:29 . 2011-07-31 17:32 -------- d-----w- c:\users\troyswi\AppData\Roaming\DAEMON Tools Pro

2011-07-31 17:29 . 2011-07-31 17:30 -------- d-----w- c:\programdata\DAEMON Tools Pro

2011-07-20 14:24 . 2011-07-20 14:24 -------- d-----w- c:\users\Default\AppData\Roaming\Xfire

2011-07-20 14:21 . 2011-07-20 14:21 -------- d-----w- c:\windows\SysWow64\config\systemprofile\Tracing

2011-07-20 14:18 . 2011-07-20 14:18 -------- d-sh--w- c:\windows\system32\%APPDATA%

2011-07-13 12:15 . 2011-06-02 06:45 243200 ----a-w- c:\windows\system32\wow64.dll

2011-07-13 12:15 . 2011-06-02 06:45 13312 ----a-w- c:\windows\system32\wow64cpu.dll

2011-07-13 12:15 . 2011-06-02 06:42 16384 ----a-w- c:\windows\system32\ntvdm64.dll

2011-07-13 12:15 . 2011-06-02 05:59 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll

2011-07-13 12:15 . 2011-06-02 05:56 25600 ----a-w- c:\windows\SysWow64\setup16.exe

2011-07-13 12:15 . 2011-06-02 05:54 5120 ----a-w- c:\windows\SysWow64\wow32.dll

2011-07-13 12:15 . 2011-06-02 03:51 7680 ----a-w- c:\windows\SysWow64\instnm.exe

2011-07-13 12:15 . 2011-06-02 03:50 2048 ----a-w- c:\windows\SysWow64\user.exe

2011-07-08 18:01 . 2011-07-08 18:01 -------- d-----w- c:\program files\iPod

2011-07-08 18:00 . 2011-07-08 18:00 -------- d-----w- c:\program files (x86)\Apple Software Update

2011-07-08 17:59 . 2011-07-08 17:59 -------- d-----w- c:\program files\Bonjour

2011-07-08 17:59 . 2011-07-08 17:59 -------- d-----w- c:\program files (x86)\Bonjour

2011-07-03 20:02 . 2011-07-04 11:36 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-07-03 20:02 . 2011-07-04 11:32 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-07-03 20:02 . 2011-07-04 11:43 253888 ----a-w- c:\windows\system32\aswBoot.exe

2011-07-03 20:02 . 2011-07-04 11:36 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-07-03 20:02 . 2011-07-04 11:35 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-07-03 20:02 . 2011-07-04 11:32 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-07-03 20:02 . 2011-07-04 11:32 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2011-07-03 20:02 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr

2011-07-03 20:02 . 2011-07-04 11:43 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe

2011-07-03 20:02 . 2011-07-03 20:02 -------- d-----w- c:\programdata\AVAST Software

2011-07-03 20:02 . 2011-07-03 20:02 -------- d-----w- c:\program files\AVAST Software

2011-07-03 01:30 . 2011-07-03 01:30 -------- d-----w- c:\programdata\SUPERAntiSpyware.com

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-07-07 15:51 . 2011-05-17 17:50 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-07-06 23:52 . 2010-09-08 19:50 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-07-06 23:52 . 2010-09-08 19:50 25912 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-06-20 12:57 . 2011-06-29 23:33 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E0BF790A-8F23-4DC6-9B78-347AE6DC5A9E}\mpengine.dll

2011-06-02 05:56 . 2011-07-13 12:15 44032 ----a-w- c:\windows\apppatch\acwow64.dll

2011-05-29 21:17 . 2003-03-19 01:14 499712 ----a-w- c:\windows\SysWow64\msvcp71.dll

2011-05-29 21:17 . 2003-02-21 09:42 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll

2011-05-28 03:25 . 2011-06-16 09:57 1638912 ----a-w- c:\windows\system32\mshtml.tlb

2011-05-28 03:00 . 2011-06-16 09:57 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb

2011-05-24 23:14 . 2011-06-29 23:33 270720 ------w- c:\windows\system32\MpSigStub.exe

2011-05-24 11:21 . 2011-06-29 23:15 404992 ----a-w- c:\windows\system32\umpnpmgr.dll

2011-05-24 10:34 . 2011-06-29 23:15 64512 ----a-w- c:\windows\SysWow64\devobj.dll

2011-05-24 10:34 . 2011-06-29 23:15 44544 ----a-w- c:\windows\SysWow64\devrtl.dll

2011-05-24 10:34 . 2011-06-29 23:15 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll

2011-05-24 10:32 . 2011-06-29 23:15 252928 ----a-w- c:\windows\SysWow64\drvinst.exe

2011-05-10 12:06 . 2011-05-10 12:06 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys

2011-05-10 12:06 . 2011-05-10 12:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll

2011-05-08 14:59 . 2011-05-08 14:59 380008 ----a-w- c:\windows\SysWow64\PMangAX0.dll

2011-05-04 05:30 . 2011-06-29 23:15 2326016 ----a-w- c:\windows\system32\tquery.dll

2011-05-04 05:28 . 2011-06-29 23:15 2228224 ----a-w- c:\windows\system32\mssrch.dll

2011-05-04 05:28 . 2011-06-29 23:15 779264 ----a-w- c:\windows\system32\mssvp.dll

2011-05-04 05:28 . 2011-06-29 23:15 75264 ----a-w- c:\windows\system32\msscntrs.dll

2011-05-04 05:28 . 2011-06-29 23:15 491520 ----a-w- c:\windows\system32\mssph.dll

2011-05-04 05:28 . 2011-06-29 23:15 288256 ----a-w- c:\windows\system32\mssphtb.dll

2011-05-04 05:24 . 2011-06-29 23:15 593408 ----a-w- c:\windows\system32\SearchIndexer.exe

2011-05-04 05:24 . 2011-06-29 23:15 249856 ----a-w- c:\windows\system32\SearchProtocolHost.exe

2011-05-04 05:24 . 2011-06-29 23:15 113664 ----a-w- c:\windows\system32\SearchFilterHost.exe

2011-05-04 04:53 . 2011-06-29 23:15 1553920 ----a-w- c:\windows\SysWow64\tquery.dll

2011-05-04 04:52 . 2011-06-29 23:15 1401856 ----a-w- c:\windows\SysWow64\mssrch.dll

2011-05-04 04:52 . 2011-06-29 23:15 666624 ----a-w- c:\windows\SysWow64\mssvp.dll

2011-05-04 04:52 . 2011-06-29 23:15 337408 ----a-w- c:\windows\SysWow64\mssph.dll

2011-05-04 04:52 . 2011-06-29 23:15 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll

2011-05-04 04:52 . 2011-06-29 23:15 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll

2011-05-04 04:52 . 2011-06-29 23:15 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe

2011-05-04 04:52 . 2011-06-29 23:15 428032 ----a-w- c:\windows\SysWow64\SearchIndexer.exe

2011-05-04 04:52 . 2011-06-29 23:15 164352 ----a-w- c:\windows\SysWow64\SearchProtocolHost.exe

2011-05-04 02:51 . 2011-06-16 09:57 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys

2011-05-04 02:51 . 2011-06-16 09:57 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-05-04 02:51 . 2011-06-16 09:57 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys

.

.

((((((((((((((((((((((((((((( SnapShot_2011-08-01_15.56.27 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-07-14 04:54 . 2011-08-01 17:44 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:54 . 2011-08-01 15:56 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-07-14 04:54 . 2011-08-01 17:44 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2011-08-01 15:56 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2011-08-01 15:56 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2011-08-01 17:44 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 05:10 . 2011-08-01 15:57 31190 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

- 2010-09-08 17:01 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-09-08 17:01 . 2011-08-01 17:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-09-08 17:01 . 2011-08-01 17:44 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-09-08 17:01 . 2011-08-01 15:56 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2010-09-08 17:01 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-09-08 17:01 . 2011-08-01 17:44 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-09-07 23:54 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-09-07 23:54 . 2011-08-01 17:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-09-07 23:54 . 2011-08-01 15:56 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-09-07 23:54 . 2011-08-01 17:07 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2011-08-01 15:55 . 2011-08-01 15:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2011-08-01 15:55 . 2011-08-01 17:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2011-08-01 15:55 . 2011-08-01 15:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2011-08-01 15:55 . 2011-08-01 17:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2010-09-08 21:51 . 2011-08-01 17:42 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

- 2010-09-08 21:51 . 2011-08-01 15:55 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat

- 2009-07-14 02:36 . 2011-08-01 15:48 660234 c:\windows\system32\perfh009.dat

+ 2009-07-14 02:36 . 2011-08-01 16:02 660234 c:\windows\system32\perfh009.dat

- 2009-07-14 02:36 . 2011-08-01 15:48 121162 c:\windows\system32\perfc009.dat

+ 2009-07-14 02:36 . 2011-08-01 16:02 121162 c:\windows\system32\perfc009.dat

+ 2009-07-14 02:34 . 2011-08-01 16:10 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

- 2009-07-14 02:34 . 2011-08-01 08:54 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{05560ADF-7B25-40FF-B408-3F6E6F512EB4}]

c:\windows\SysWow64\api-ms-win-core-memory-l1-1-032.dll [bU]

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2011-03-17 842048]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]

"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2009-07-17 237568]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-14 98304]

"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2010-02-09 1807680]

"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584]

"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]

"DeathAdder"="c:\program files (x86)\Razer\DeathAdder\razerhid.exe" [2010-05-05 251392]

"Dell V310-V510 Series"="c:\program files (x86)\Dell V310-V510 Series\fm3032.exe" [2010-01-18 316072]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-01-07 232104]

"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]

"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2011-05-29 273544]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160]

.

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\steffiswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\steveswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\tammiswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\troyswi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-15 1324384]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"SoftwareSASGeneration"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

R2 BPA_Execution;AutoMate BPA Server 8 Execution Server;c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_EXEC.exe [2011-02-11 376832]

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 EFS32;Encrypting File System (EFS) ;c:\windows\system32\OnLineIDCpl32.exe [x]

R2 FLEXnet Licensing Service32;FLEXnet Licensing Service ;c:\windows\system32\catsrv32.exe [x]

R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]

R2 wcncsvc32;Windows Connect Now - Config Registrar ;c:\windows\system32\capiprovider32.exe [x]

R3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys [x]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [2011-05-12 25072]

R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]

S1 aswSnx;aswSnx; [x]

S1 aswSP;aswSP; [x]

S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]

S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]

S2 aswFsBlk;aswFsBlk; [x]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]

S2 BPA_Management;AutoMate BPA Server 8 Management Server;c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_MAN.exe [2011-02-11 376832]

S2 BPAAgent8;AutoMate BPA Server 8 Agent;c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe [2011-02-11 11323392]

S2 dlea_device;dlea_device;c:\windows\system32\dleacoms.exe [2010-01-07 1052328]

S2 dleaCATSCustConnectService;dleaCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe [2010-01-07 33448]

S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]

S2 TeamViewer5;TeamViewer 5;c:\program files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-09-14 1956136]

S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-06-01 2337144]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]

S3 danewFltr;NewDeathAdder Mouse;c:\windows\system32\drivers\danew.sys [x]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]

S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

Akamai REG_MULTI_SZ Akamai

.

Contents of the 'Scheduled Tasks' folder

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3033937009-333567816-1246851426-1003Core.job

- c:\users\troyswi\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-10 20:20]

.

2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3033937009-333567816-1246851426-1003UA.job

- c:\users\troyswi\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-10 20:20]

.

2011-07-26 c:\windows\Tasks\One-Click Tweak.job

- c:\program files (x86)\Advanced PC Tweaker\OneClick.exe [2011-01-25 23:40]

.

2011-07-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job

- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]

.

2011-08-01 c:\windows\Tasks\SystemToolsDailyTest.job

- c:\program files\Dell Support Center\uaclauncher.exe [2011-06-21 18:09]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2011-07-04 11:43 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"combofix"="c:\combofix\CF21527.cfxxe" [X]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-07 8158240]

"RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]

"RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568]

"dleamon.exe"="c:\program files (x86)\Dell V310-V510 Series\dleamon.exe" [2010-01-18 770728]

"EzPrint"="c:\program files (x86)\Dell V310-V510 Series\ezprint.exe" [2010-01-18 139944]

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://sigma.pokemonvortex.org/your_team.php

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105

IE: {{602AB448-D389-4a54-B6A6-CE57AA0CCFC4} - {A310506F-6BA4-48c4-8887-1F462277AA12} - mscoree.dll

TCP: DhcpNameServer = 192.168.1.1 68.87.64.150 68.87.75.198

DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} - hxxp://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab

DPF: {93C449FA-ECFB-402F-A8C7-37E4F8D60E49} - hxxp://dl.pmang.com/common/pmangctl/pmangax.cab

FF - ProfilePath - c:\users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\

FF - prefs.js: browser.search.selectedEngine - DAEMON Search

FF - prefs.js: browser.startup.homepage - hxxp://forums.ijji.com/forumdisplay.php?f=79

FF - prefs.js: network.proxy.http - 127.0.0.1

FF - prefs.js: network.proxy.http_port - 64848

FF - prefs.js: network.proxy.type - 0

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - Ext: avast! WebRep: wrc@avast.com - c:\program files\AVAST Software\Avast\WebRep\FF

FF - Ext: Easy-Hide-IP Firefox Plugin: support@easy-hide-ip.com - c:\program files (x86)\Easy-Hide-IP\ff-extension

FF - Ext: iMacros for Firefox: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} - %profile%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}

FF - user.js: network.protocol-handler.warn-external.dnupdate - false

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]

"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"

.

------------------------ Other Running Processes ------------------------

.

c:\program files\AVAST Software\Avast\AvastSvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAEM.exe

c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\program files (x86)\Razer\DeathAdder\razertra.exe

c:\program files (x86)\Razer\DeathAdder\razerofa.exe

.

**************************************************************************

.

Completion time: 2011-08-01 13:48:47 - machine was rebooted

ComboFix-quarantined-files.txt 2011-08-01 17:48

ComboFix2.txt 2011-08-01 16:01

ComboFix3.txt 2011-07-31 15:17

.

Pre-Run: 725,417,672,704 bytes free

Post-Run: 725,103,517,696 bytes free

.

- - End Of File - - 5FEC0CDFC9DF8BD07E10C5B0E73602C5

Link to post
Share on other sites

Your logs appear to be clean ;) How are things running now?

Before we move on, let's run the following online scans to make sure there's nothing hiding that we may have missed:

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats is Unchecked and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

--------

Please use the Internet Explorer and run a BitDefender Online scan from Here

  • Please check I agree with the Terms and Conditions and click Start Here
  • You will need to allow an Active X install for the scan to run.
  • Leave the scanning options at default and click Start Scan

Please post the results in your next reply.

Link to post
Share on other sites

Things have been running fine.. but, the first scanner picked up "66" infections. :blink:

ESETSmartInstaller@High as CAB hook log:

OnlineScanner64.ocx - registred OK

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255)

# OnlineScanner.ocx=1.0.0.6528

# api_version=3.0.2

# EOSSerial=e3778748677c154685b00feb2f891a79

# end=finished

# remove_checked=false

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-08-01 10:01:22

# local_time=2011-08-01 06:01:22 (-0500, Eastern Daylight Time)

# country="United States"

# lang=9

# osver=6.1.7600 NT

# compatibility_mode=5893 16776574 100 94 2115295 63774383 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=263983

# found=66

# cleaned=0

# scan_time=5148

C:\Program Files (x86)\Advanced PC Tweaker\AdvancedPCTweaker.exe a variant of Win32/Adware.AdvPCTweak application (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{0772bda2-530f-42b7-9717-fb7bd7d5026b}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{0823b41f-9676-431a-b2e7-4d360a7b743d}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{1ab7b2f2-034e-4cfd-aba2-4f5f2878f831}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{1dda916b-a2f7-4c9f-a773-dfe5adb23c88}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{40271a83-fe52-42c9-875b-5aa69ffec208}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{4636f24c-e3f1-4390-87e2-02ba08372da5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{4f55d6e9-4cf3-403b-8a77-20413087e102}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{4fbf8087-30c4-46f6-97e9-d56b8795e341}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{6b36e3c7-6f23-4017-b302-04187ec1b696}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{747fd0e4-ec3c-4356-9960-10e2f4a63739}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{77c2c07a-9d90-481d-92ea-84c4f59e4841}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{7c926b72-a3c2-4747-a0e3-04b82b926203}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{907f6615-ca17-4a2e-b168-874b3da349f9}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{a7148e08-9dcc-430c-a305-e8f7b8c0ded5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{aaed32ad-1e47-4745-8b74-773216ecc790}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{b4d6a01a-4879-4c28-8a4a-4e244fe73384}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{c014d80a-b4ed-42ca-ac38-a0160cb5066a}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{df28687c-9a39-4e15-854f-af3247fc7fd8}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{e6b52706-93b9-473f-90fd-3cfb0e53dd4e}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{eb4dbe48-31c6-41f7-8c39-722171be23ef}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steffiswi\AppData\Roaming\Mozilla\Firefox\Profiles\m53ewzf2.default\extensions\{facca4a5-2dc8-4aad-8f8f-5d9ee93d66b9}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{0772bda2-530f-42b7-9717-fb7bd7d5026b}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{0823b41f-9676-431a-b2e7-4d360a7b743d}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{1ab7b2f2-034e-4cfd-aba2-4f5f2878f831}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{1dda916b-a2f7-4c9f-a773-dfe5adb23c88}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{40271a83-fe52-42c9-875b-5aa69ffec208}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{4636f24c-e3f1-4390-87e2-02ba08372da5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{4f55d6e9-4cf3-403b-8a77-20413087e102}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{4fbf8087-30c4-46f6-97e9-d56b8795e341}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{6b36e3c7-6f23-4017-b302-04187ec1b696}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{747fd0e4-ec3c-4356-9960-10e2f4a63739}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{77c2c07a-9d90-481d-92ea-84c4f59e4841}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{7c926b72-a3c2-4747-a0e3-04b82b926203}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{907f6615-ca17-4a2e-b168-874b3da349f9}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{a7148e08-9dcc-430c-a305-e8f7b8c0ded5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{aaed32ad-1e47-4745-8b74-773216ecc790}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{b4d6a01a-4879-4c28-8a4a-4e244fe73384}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{c014d80a-b4ed-42ca-ac38-a0160cb5066a}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{df28687c-9a39-4e15-854f-af3247fc7fd8}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{e6b52706-93b9-473f-90fd-3cfb0e53dd4e}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{eb4dbe48-31c6-41f7-8c39-722171be23ef}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\steveswi\AppData\Roaming\Mozilla\Firefox\Profiles\au5x8lco.default\extensions\{facca4a5-2dc8-4aad-8f8f-5d9ee93d66b9}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{0772bda2-530f-42b7-9717-fb7bd7d5026b}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{0823b41f-9676-431a-b2e7-4d360a7b743d}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{1ab7b2f2-034e-4cfd-aba2-4f5f2878f831}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{1dda916b-a2f7-4c9f-a773-dfe5adb23c88}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{40271a83-fe52-42c9-875b-5aa69ffec208}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{4636f24c-e3f1-4390-87e2-02ba08372da5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{4f55d6e9-4cf3-403b-8a77-20413087e102}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{4fbf8087-30c4-46f6-97e9-d56b8795e341}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{6b36e3c7-6f23-4017-b302-04187ec1b696}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{747fd0e4-ec3c-4356-9960-10e2f4a63739}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{77c2c07a-9d90-481d-92ea-84c4f59e4841}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{7c926b72-a3c2-4747-a0e3-04b82b926203}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{907f6615-ca17-4a2e-b168-874b3da349f9}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{a7148e08-9dcc-430c-a305-e8f7b8c0ded5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{aaed32ad-1e47-4745-8b74-773216ecc790}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{b4d6a01a-4879-4c28-8a4a-4e244fe73384}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{c014d80a-b4ed-42ca-ac38-a0160cb5066a}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{df28687c-9a39-4e15-854f-af3247fc7fd8}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{e6b52706-93b9-473f-90fd-3cfb0e53dd4e}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{eb4dbe48-31c6-41f7-8c39-722171be23ef}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Qoobox\Quarantine\C\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{facca4a5-2dc8-4aad-8f8f-5d9ee93d66b9}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Users\troyswi\AppData\Local\Google\Chrome\User Data\Default\Default\jhlplclcmoknjecmpjigigockbklgfgj\contentscript.js Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I

C:\Users\troyswi\Documents\installer-for-macro-recorder.exe probably a variant of MSIL/Agent.NGQ trojan (unable to clean) 00000000000000000000000000000000 I

--

QuickScan Beta 32-bit v0.9.9.99

-------------------------------

Scan date: Tue Aug 02 12:31:08 2011

Machine ID: 2E236542

No infection found.

-------------------

Processes

---------

Adobe Reader and Acrobat Manager 5976 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

Anti-phishing Domain Advisor 5908 C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

AutoMate 8 1156 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe

AutoMate 8 2080 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAEM.exe

avast! Antivirus 1460 C:\Program Files\AVAST Software\Avast\AvastSvc.exe

avast! Antivirus 6012 C:\Program Files\AVAST Software\Avast\AvastUI.exe

Bonjour 428 C:\Program Files (x86)\Bonjour\mDNSResponder.exe

DAEMON Tools Pro 5292 C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe

DataSafeOnline 5596 C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

distnoted 1412 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe

Dock Login Service 1200 C:\Program Files\Dell\DellDock\DockLogin.exe

ezprint.exe 3372 C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe

Firefox 3804 C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Firefox 1980 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

Game Booster 2364 C:\Program Files (x86)\IObit\Game Booster\GameBox.exe

IAStorDataSvc 2336 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

IAStorIcon 5516 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

IconUtility 5528 C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

iTunes 3764 C:\Program Files (x86)\iTunes\iTunes.exe

iTunes 6020 C:\Program Files (x86)\iTunes\iTunesHelper.exe

MobileDeviceHelper 5088 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe

MobileDeviceService 1968 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

Printer Device Monitor 3344 C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe

Razer OFA 6132 C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe

razerhid Application 5732 C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

razertra Application 5868 C:\Program Files (x86)\Razer\DeathAdder\razertra.exe

RealPlayer (32-bit) 6320 C:\Program Files (x86)\Real\RealPlayer\realplay.exe

RealPlayer (32-bit) 6004 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

SoftThinks Agent Service 2624 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe

TeamViewer 2852 C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe

TeamViewer 2872 C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

Windows® Internet Explorer 3792 C:\Program Files (x86)\Internet Explorer\iexplore.exe

Xfire 3780 C:\Program Files (x86)\Xfire\Xfire.exe

(verified) Microsoft Search Enhancement Pack 2548 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

(verified) Microsoft® Windows® Operating System 1928 C:\Windows\SysWOW64\svchost.exe

Network activity

----------------

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 184.84.236.232

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 69.63.190.10

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 69.63.181.41

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 74.125.226.134

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 72.14.204.102

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 96.17.77.137

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 96.17.77.137

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 96.17.77.137

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 96.17.77.137

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 96.17.77.137

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 96.17.77.137

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 64.233.169.96

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 74.125.226.154

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 69.171.242.14

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 184.84.236.241

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 184.84.236.241

Process AvastSvc.exe (1460) connected on port 80 (HTTP) --> 74.125.226.107

Process svchost.exe (1928) connected on port 443 (HTTP over SSL) --> 208.46.117.195

Process iTunes.exe (3764) connected on port 80 (HTTP) --> 184.51.157.35

Process iTunes.exe (3764) connected on port 80 (HTTP) --> 96.17.150.9

Process iTunes.exe (3764) connected on port 80 (HTTP) --> 184.51.157.8

Process Xfire.exe (3780) connected on port 25999 (Xfire) --> 208.88.178.49

Process iexplore.exe (3792) connected on port 443 (HTTP over SSL) --> 74.125.226.108

Process svchost.exe (1928) listens on ports: 49161 (RPC)

Process iTunes.exe (3764) listens on ports: 3689 (iTunes)

Autoruns and critical files

---------------------------

Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe

Adobe Reader and Acrobat Manager C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

Anti-phishing Domain Advisor C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

ATI Customer Care c:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe

avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastUI.exe

Catalyst® Control Center c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

Creative Updreg C:\Windows\UpdReg.EXE

DAEMON Tools Pro C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe

DataSafeOnline C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

Dell Dock C:\Program Files\Dell\DellDock\DellDock.exe

ezprint.exe C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe

Fax Solutions Software C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe

IAStorIcon C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

IconUtility C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

iTunes C:\Program Files (x86)\iTunes\iTunesHelper.exe

MobileMe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

OneClick.exe C:\Program Files (x86)\Advanced PC Tweaker\OneClick.exe

PC-Doctor for Windows C:\Program Files\Dell Support Center\uaclauncher.exe

Printer Device Monitor C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe

QuickTime C:\Program Files (x86)\QuickTime\QTTask.exe

razerhid Application C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

RealPlayer (32-bit) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

Realtek HD Audio Manager C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

THXAudio C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe

Windows® Internet Explorer c:\windows\syswow64\webcheck.dll

(verified) Google Update C:\Users\troyswi\AppData\Local\Google\Update\GoogleUpdate.exe

(verified) Microsoft® Windows® Operating System c:\windows\system32\userinit.exe

Browser plugins

---------------

AcroIEHelperShim Library C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

Adobe Acrobat C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll

Adobe Acrobat C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll

avast! WebRep C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BitDefender QuickScan C:\Windows\Downloaded Program Files\qsax.dll

Bonjour C:\Program Files (x86)\Bonjour\mdnsNSP.dll

Bonjour C:\Program Files\Bonjour\mdnsNSP.dll

downloadUpdater C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll

downloadUpdater2 C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll

DownStarter2 C:\Windows\Downloaded Program Files\DownStarter2.ocx

Google Update C:\Users\troyswi\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll

ijji Auto Install Plugin for Mozilla C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll

ijjiSetup Module C:\Windows\Downloaded Program Files\ijjiSetup1010.dll

imtcp_xpcom.dll C:\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\imtcp_xpcom.dll

InstallShield Update Service C:\Windows\Downloaded Program Files\dwusplay.exe

Java Deployment Toolkit 6.0.230.5 C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

Java Platform SE 6 U23 C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

Java Platform SE 6 U23 C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL

Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL

Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\urlredir.dll

Mozilla Default Plug-in C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll

npitunes.dll C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

NPSWF32.dll C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

PubPlugin C:\Windows\Downloaded Program Files\PubPlugin.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll

QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll

RealJukebox NS Plugin C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll

RealJukebox NS Plugin c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll

RealNetworks RealPlayer Chrome Back C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

RealPlayer Download and Record Plugin C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

RealPlayer Version Plugin C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll

RealPlayer Version Plugin c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll

RealPlayer G2 LiveConnect-Enabled P C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll

RealPlayer G2 LiveConnect-Enabled P c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll

RealPlayer HTML5VideoShim Plug-In ( C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

Silverlight Plug-In c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

Skype Toolbars C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

Software Manager C:\Windows\Downloaded Program Files\isusweb.dll

toolband.dll c:\program files\dell printable web\toolband.dll

Windows Live Toolbar c:\program files (x86)\windows live\toolbar\wltcore.dll

Windows Live® Photo Gallery C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

Windows® Internet Explorer C:\Windows\SysWOW64\ieframe.dll

(verified) InstallShield Update Service C:\Windows\Downloaded Program Files\dwusplay.dll

(verified) Microsoft Search Helper Extention c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll

(verified) Microsoft® Windows Live Login Helper c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll

(verified) Microsoft® Windows® Operating System C:\Windows\system32\mswsock.dll

(verified) Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll

(verified) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll

(verified) Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll

(verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll

Missing files

-------------

File not found: c:\windows\syswow64\api-ms-win-core-memory-l1-1-032.dll

--> HKLM\Software\Classes\CLSID\{05560ADF-7B25-40FF-B408-3F6E6F512EB4}\InprocServer32\"(default)"

Scan

----

MD5: 37bf603c3685289ca684c4d3400a9de7 C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe

MD5: 8580a588316f94bff50f6ae4a4d7d727 C:\Program Files (x86)\Advanced PC Tweaker\OneClick.exe

MD5: debba6f9aa45ba0380c67bf66fe71b6b c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

MD5: 9b5e7eff0485f39a9663314667d97049 c:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe

MD5: 37bc9e0e4b3657b54037777135569d1e C:\Program Files (x86)\Bonjour\mdnsNSP.dll

MD5: f2060a34c8a75bc24a9222eb4f8c07bd C:\Program Files (x86)\Bonjour\mDNSResponder.exe

MD5: d3316f6e3c011435f36e3d6e49b3196c C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe

MD5: c3104be7d2b689ebe47e2aac64c07530 C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

MD5: 203a74767eb81f96a5166b1933db46d0 C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

MD5: bad6bea0de1f69c82bdb74378ce0c20a C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

MD5: 1675e645ec400a7f4b2c8bd38fe074b4 c:\program files (x86)\common files\akamai\netsession_win_2da1ebd.dll

MD5: dddd1d04d5f4360371bc99c7c476f70d C:\Program Files (x86)\Common Files\Apple\Apple Application Support\ASL.dll

MD5: 06da46babe9c21c51830372afe70ca96 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\AVFoundationCF.dll

MD5: d855b0e63ecafe9ebd086af6691e0016 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CFNetwork.dll

MD5: 6d4524c70b6eb229158ff41d024b805e C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreAudioToolbox.dll

MD5: 749cf03badc40453f61fd7025e2ba2f5 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreFoundation.dll

MD5: d4e1562f037d8156fdde5cb5ab3377b9 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreGraphics.dll

MD5: be3d9ec6da7d80a2fbba0e9388e09867 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreMedia.dll

MD5: ec2b45ac3308bdeb17f6eb7c607a62b3 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\CoreVideo.dll

MD5: c052b448e3a413c9bf293ea9b22a001f C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe

MD5: 73b527556c767d1aa789a2853b84d03d C:\Program Files (x86)\Common Files\Apple\Apple Application Support\Foundation.dll

MD5: d30dd708f05fb85ef2c53727ed3573d2 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\icudt40.dll

MD5: 38711bb50d27b7145186f61ce31b3336 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\icuin40.dll

MD5: 9e515554a3ea7b70c975f61971c6977d C:\Program Files (x86)\Common Files\Apple\Apple Application Support\icuuc40.dll

MD5: cffa5331b43eed6f4cedf788c8aebe3a C:\Program Files (x86)\Common Files\Apple\Apple Application Support\JavaScriptCore.dll

MD5: 7ef0c8a9a1a57756f4868e3693173c08 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libdispatch.dll

MD5: 2acb25e989002caf3ed92a2a298cacdd C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libtidy.dll

MD5: 8c5a9f81414d5690c38c8fc0fd2bef38 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

MD5: 290dbd5c1e2dd1540c2c18ce922b6c6d C:\Program Files (x86)\Common Files\Apple\Apple Application Support\MediaToolbox.dll

MD5: 258d35f5f5f5f3f6045488ecdc14faab C:\Program Files (x86)\Common Files\Apple\Apple Application Support\objc.dll

MD5: 0eee814627f4384291687671f76419f6 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\pthreadVC2.dll

MD5: 3fbcef16c830a8f1c85fd3d8ef33dae0 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\QuartzCore.dll

MD5: 10a3be228f8c14be1e4fd716336e4889 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\SQLite3.dll

MD5: 1be0e2e4ab087d788903d57dd25bcb5a C:\Program Files (x86)\Common Files\Apple\Apple Application Support\VideoToolbox.dll

MD5: 5316f0adf07dfa1e71a1e437956cbac5 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit.dll

MD5: 85d2a186afd93a318935791421efc605 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

MD5: 0c0741b3f737624613d140a3589932c7 C:\Program Files (x86)\Common Files\Apple\CoreFP\CoreFP.dll

MD5: f5f7442f5537df61b57f7a52a74c14de C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe

MD5: 9f6ebe3f44f1ed31378d16c9ce764bdf C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper_main.dll

MD5: 20f6f19fe9e753f2780dc2fa083ad597 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

MD5: dc70310b3d079d667b67f0c7067209f3 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll

MD5: 310638ebdd87b49df3d12edb853d5166 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

MD5: 476ca9f7d614fc1383c0b53cd109b286 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\DeviceLink.dll

MD5: e6748a0adc22f0595e31448cac746d3f C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll

MD5: f09378212b9ba9f59b9bc92ac6378968 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\MobileDevice.dll

MD5: 7ea94d3dc0e7b0f655aa58a82378ad73 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServices.dll

MD5: 8669be94f63944e4f899c3950b520241 C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

MD5: 05fc44d32a144925eae45570029fd6e1 c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe

MD5: aa1134efffb90f7ef49567ff3699490c C:\Program Files (x86)\Common Files\Steam\SteamService.exe

MD5: ff5eb78af7dfb68c2fb363537aaf753e c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

MD5: 2a5e8dbc310c2fb7511b9ab8e7cfb297 C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe

MD5: 231b4c5dee44cd17a0182424c8e56b2f C:\Program Files (x86)\DAEMON Tools Pro\Converter.dll

MD5: 6e4020d918f14049188e0d8b5bb27f27 C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe

MD5: 53b0b6260fff1540a2ead4e8178e5017 C:\Program Files (x86)\DAEMON Tools Pro\DTCommonRes.dll

MD5: 82d64ea9fe677d48be76cfcdb8887b6e C:\Program Files (x86)\DAEMON Tools Pro\Engine.dll

MD5: 7f5ca5fef43a1fdb330a7de07cb29988 C:\Program Files (x86)\DAEMON Tools Pro\imgengine.dll

MD5: f841f32ad816dbf130f10d86fab99b1a C:\Program Files (x86)\DAEMON Tools Pro\mfc100u.dll

MD5: 03e9314004f504a14a61c3d364b62f66 C:\Program Files (x86)\DAEMON Tools Pro\MSVCP100.dll

MD5: 67ec459e42d3081dd8fd34356f7cafc1 C:\Program Files (x86)\DAEMON Tools Pro\MSVCR100.dll

MD5: 4698c4dde1ca4a20ba0855f4084ed2ee C:\Program Files (x86)\Dell DataSafe Local Backup\CSTError.dll

MD5: b037c6ec0ed49f728f317352ebc56524 C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll

MD5: e1974a92ac0914a3859359a0a8c82c68 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe

MD5: dd0ad41d14b09ffdff64d2bd7301a357 C:\Program Files (x86)\Dell DataSafe Local Backup\STCoreXml.dll

MD5: 2a159f9ce2534993a5fd91ebb4c4f8bf C:\Program Files (x86)\Dell DataSafe Local Backup\STDisks.dll

MD5: 796b559e9e77415a7caba9e05b71d94a C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll

MD5: a1bf31014d6af7a43598a1250ff5b1cc C:\Program Files (x86)\Dell DataSafe Local Backup\STString.dll

MD5: 812cc763ba8031d13eb0407cf961c2c3 C:\Program Files (x86)\Dell DataSafe Local Backup\STSystems.dll

MD5: 16c94859f2a4f2403f6efd516df4b2b4 C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll

MD5: 35a5c7ad281231c1dea6751a63268de5 C:\Program Files (x86)\Dell DataSafe Online\BuEng.dll

MD5: e8420094cf108385a2f7b2f20437c64b C:\Program Files (x86)\Dell DataSafe Online\cpputils.dll

MD5: 637e9eea864ce9c5778e3c4358b1e0d1 C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe

MD5: 7fc86aa321f35120a051e7c13cb26991 C:\Program Files (x86)\Dell DataSafe Online\OlbEng.dll

MD5: 2ef42b77565da9d46f74ba08306811b4 C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll

MD5: 3c58d3f375b32e15e4afc796d1b141f1 C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll

MD5: 471d7266ad659f79ae0281693f9ccd12 C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll

MD5: 224578e2f25e0fd4b3b7db1c6df235e2 C:\Program Files (x86)\Dell V310-V510 Series\customui.dll

MD5: cc3570cc65aabbab1801ab9e75f02fc3 C:\Program Files (x86)\Dell V310-V510 Series\dleacaps.dll

MD5: 5a183bef69e243a2e481d559fec7f7bc C:\Program Files (x86)\Dell V310-V510 Series\dleacfg.dll

MD5: ba210b3e2fdceffd800fa3625f5e0aa9 C:\Program Files (x86)\Dell V310-V510 Series\dleacnv4.dll

MD5: 0f544b46f9966f29d05e0f998297c7e7 C:\Program Files (x86)\Dell V310-V510 Series\dleacomc.dll

MD5: 2317588da43635e4acbe58aa91aff152 C:\Program Files (x86)\Dell V310-V510 Series\dleadatr.dll

MD5: 931c56e5a6df324fde1b19fc8fd678a5 C:\Program Files (x86)\Dell V310-V510 Series\dleaDRS.dll

MD5: c29daf54dec7253221c88787e64075e7 C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe

MD5: 046e4103ed25becc0f010bd27a24f407 C:\Program Files (x86)\Dell V310-V510 Series\dleamonr.dll

MD5: 572c6429a5508e8c2639bdbe5c282991 C:\Program Files (x86)\Dell V310-V510 Series\dleaptp.dll

MD5: adefbd9c7f72edc8f02f40cb9c11515e C:\Program Files (x86)\Dell V310-V510 Series\dleascw.dll

MD5: a29c926672e80ccba154cee7c46261bf C:\Program Files (x86)\Dell V310-V510 Series\Epfunct.DLL

MD5: 78ee9f0922eb666dcf00a8a92dca6fda C:\Program Files (x86)\Dell V310-V510 Series\EPOEMDll.dll

MD5: 0faad1cd3a19843ebde3026a8bf323c2 C:\Program Files (x86)\Dell V310-V510 Series\epstring.dll

MD5: 2a5566592fd8b23cb4b2663067c21f6e C:\Program Files (x86)\Dell V310-V510 Series\Eputil.DLL

MD5: 249a0b6c55703fb7fe34cfd8acdd00ae C:\Program Files (x86)\Dell V310-V510 Series\Epwizard.DLL

MD5: 00d82d3ac6b915c76bf7d19072077a9b C:\Program Files (x86)\Dell V310-V510 Series\EPWizRes.dll

MD5: 939eb7ecc20709f129495e73d3a7fbe0 C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe

MD5: a0bb9014815452a82bf3ce7fc38e2ea1 C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe

MD5: a20f745d153d28390021ba5ab1983675 C:\Program Files (x86)\Dell V310-V510 Series\Imagutil.DLL

MD5: 8ba16887c3e15f735d81f6470eb3c49f C:\Program Files (x86)\Dell V310-V510 Series\iptk.dll

MD5: 80505248ebd079cb692fc2ff0bf5d754 C:\Program Files (x86)\Dell V310-V510 Series\Ltdis15u.dll

MD5: 8edace1d540666e2909dbbda5e07b40e C:\Program Files (x86)\Dell V310-V510 Series\LTEFX15U.DLL

MD5: 44491323891ee2cdedd31e96449b9e78 C:\Program Files (x86)\Dell V310-V510 Series\Ltfil15u.dll

MD5: 3271a2285738336d273cb0e850c4f9cc C:\Program Files (x86)\Dell V310-V510 Series\Ltimgclr15u.dll

MD5: 5bf0bfda62dd7a3a512f09a9ee31e8bb C:\Program Files (x86)\Dell V310-V510 Series\LTIMGCOR15U.DLL

MD5: cd9704754c0160eeb636bf3e340cab9a C:\Program Files (x86)\Dell V310-V510 Series\LTIMGEFX15U.DLL

MD5: 695c32d334146ad25a2e6305dd3175a2 C:\Program Files (x86)\Dell V310-V510 Series\LTIMGSFX15U.DLL

MD5: d1514e24d2ce523f3d4deafdec50de9f C:\Program Files (x86)\Dell V310-V510 Series\Ltimgutl15u.dll

MD5: 75de43a4302967c786a0da65c649f1a0 C:\Program Files (x86)\Dell V310-V510 Series\Ltkrn15u.dll

MD5: fecc6977944fc212772173c86aa9b0c0 C:\Program Files (x86)\Dell V310-V510 Series\Ltwvc215u.dll

MD5: c10d6a7784e12bf0be4799f675f614c2 C:\Program Files (x86)\Dell V310-V510 Series\PdfLib.dll

MD5: 40f55c563961c01c466e011b6aa61e27 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgr.dll

MD5: 7493ea4de41348f7d3edbf9db298f56a C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

MD5: 852f12ca7c4fc7e3d77b606492435556 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

MD5: 9d26e14c0f3e5b081dae517b99d36f70 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorUIHelper.dll

MD5: 7ff74fece8c0e7b0207d3629ae2a3d16 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorUtil.dll

MD5: adff528ca09752078f26b620a6f42760 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IntelVisualDesign.dll

MD5: d0fff1f89431a60a2cc077452b53a50d C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\ISDI.dll

MD5: e8969a2864a30b2168f25a896088de10 C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll

MD5: bd43a986fa0dc0cbf672638a8de444db C:\Program Files (x86)\Internet Explorer\ieproxy.dll

MD5: 64efaf916c4009f1b84153d0bb491fb0 C:\Program Files (x86)\Internet Explorer\iexplore.exe

MD5: 90a5192af9069ee7f8705e12601ae542 C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll

MD5: 3d944e807cd82ca98ca162affd462b70 C:\Program Files (x86)\IObit\Game Booster\GameBox.exe

MD5: 37e3f2d607c92266c4929600a07eda0e C:\Program Files (x86)\IObit\Game Booster\madBasic_.bpl

MD5: 8c5e41c3d695843e340d1f8dc6b2b7b6 C:\Program Files (x86)\IObit\Game Booster\madDisAsm_.bpl

MD5: a96aa7bb0e192d6593da840a4bc9d289 C:\Program Files (x86)\IObit\Game Booster\madExcept_.bpl

MD5: dd82eb68d97944b192c7803eb585b03c C:\Program Files (x86)\IObit\Game Booster\rtl120.bpl

MD5: 8f8c706296cffc46b15d4d9a309af223 C:\Program Files (x86)\IObit\Game Booster\sqlite3.dll

MD5: 773ebd87010a6f644869a59d98792c9c C:\Program Files (x86)\IObit\Game Booster\vcl120.bpl

MD5: 17d0449deee073043ee1aa92d41a12ff C:\Program Files (x86)\iTunes\GNSDK_DSP.DLL

MD5: 4dc34cadbe2d864bc878a3decb812301 C:\Program Files (x86)\iTunes\GNSDK_MUSICID.DLL

MD5: 1c7a1a9523de142cebf35b18a1eb6afb C:\Program Files (x86)\iTunes\GNSDK_SDKMANAGER.DLL

MD5: dbea5b57707ee73e6657c1b1d12a113f C:\Program Files (x86)\iTunes\GNSDK_SUBMIT.DLL

MD5: 3909bbdec400869bfaae1e7251437b27 C:\Program Files (x86)\iTunes\iTunes.dll

MD5: 88e4e1e5134aba80f4e6a293eca10f3b C:\Program Files (x86)\iTunes\iTunes.exe

MD5: 3ac1a94fde5fb8b52604c67b24fee65e C:\Program Files (x86)\iTunes\iTunes.Resources\en.lproj\iTunesLocalized.DLL

MD5: 5c782da52e48cd60e0a0a9b4a5aa4962 C:\Program Files (x86)\iTunes\iTunes.Resources\iTunes.DLL

MD5: 1bfc98bce60743407cc7ef5556bf63ee C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.DLL

MD5: ba0f6dcc3181a4e3cbb02ec41153bb72 C:\Program Files (x86)\iTunes\iTunesHelper.dll

MD5: 53d96678fb89f056d5285101481297d9 C:\Program Files (x86)\iTunes\iTunesHelper.exe

MD5: 99aaa6c83d40be9db1ba81141b2aebc8 C:\Program Files (x86)\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL

MD5: 562814461db20253b42bb806c994d20d C:\Program Files (x86)\iTunes\iTunesHelper.Resources\iTunesHelper.DLL

MD5: 7f8aefd3bbc0f30c42c59fd27a828dcf C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

MD5: 67e74163c6178aa696e2b4a726770a02 C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

MD5: ea8fcf30d2961369435c84ce3b3063f1 C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

MD5: c3e42cbf8215171a524d123a54ae3233 c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

MD5: 1755f4933644f656c7f30bfb81a8ecd0 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaShadow\SEASHADO.dll

MD5: e0dd4a98c79c83aa67d79c8dfc6d2e4f C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll

MD5: b96306630fa5a5c01579d17af0d407bf C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll

MD5: 055713cd9e0c6aac46afbb3a5b95ef75 C:\Program Files (x86)\Mozilla Firefox\firefox.exe

MD5: 7f238c0745053c966cb71c001f8878c2 C:\Program Files (x86)\Mozilla Firefox\freebl3.dll

MD5: 112bef85c4b01d7b6c3321f4fb01eedd C:\Program Files (x86)\Mozilla Firefox\js3250.dll

MD5: dddbcc60480fee039a094c1662c0beff C:\Program Files (x86)\Mozilla Firefox\MOZCPP19.dll

MD5: b96f14bc7df04b349e82c9003f82558b C:\Program Files (x86)\Mozilla Firefox\MOZCRT19.dll

MD5: 74d4444f5067c2ec41a20f3893299dcd C:\Program Files (x86)\Mozilla Firefox\nspr4.dll

MD5: 99e91ea69a9c33b4349f45b486347019 C:\Program Files (x86)\Mozilla Firefox\nss3.dll

MD5: 4c057d3ad53e4e99af7590351d372093 C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll

MD5: baf720ed50e71d435de7d3929157c8f6 C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll

MD5: 72bc2a9126c01d6d1045a58c0285149d C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll

MD5: aa14af2c8915e41327ac3bc8b32c4548 C:\Program Files (x86)\Mozilla Firefox\plc4.dll

MD5: 8e35d253333530285c47e8d33d1d3c74 C:\Program Files (x86)\Mozilla Firefox\plds4.dll

MD5: 55b35599e4b8c20904cf6be6f50a1f8d C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

MD5: 44cd19d98995cb3056f406113b175820 C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

MD5: 323fe218dac089eed70ca55e6c1c2f1d C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll

MD5: dbe8c34758da614f35ae7011284406bb C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll

MD5: 0af5e73ebb4b49eca597f4edaf2c252b C:\Program Files (x86)\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll

MD5: 4e3216231cba873f1d88cc3a755cc4af C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll

MD5: 90a5192af9069ee7f8705e12601ae542 C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll

MD5: 4e8238ca1046d97636e63abf173772cd C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll

MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll

MD5: 56b73e1adfd768e80369c4a2e68f35df C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll

MD5: e7856c9b1ae2ded52c98e69497308083 C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll

MD5: 64c183111ada8b5f419fad4e70b9ab70 C:\Program Files (x86)\Mozilla Firefox\smime3.dll

MD5: 48dacc767b7c8d77f3dfd501b9e30a6a C:\Program Files (x86)\Mozilla Firefox\softokn3.dll

MD5: f04cb8f40f38d1cc75c44e6c219d80cd C:\Program Files (x86)\Mozilla Firefox\sqlite3.dll

MD5: ced3cfa15858d4b8294980077a1c700e C:\Program Files (x86)\Mozilla Firefox\ssl3.dll

MD5: 0fee7c320c3e864da8f0bf9188594643 C:\Program Files (x86)\Mozilla Firefox\xpcom.dll

MD5: 921cb4d7cfff02d0d818a728afbe09ba C:\Program Files (x86)\Mozilla Firefox\xul.dll

MD5: c098bf3845c738dd4f6f76b55b442d29 C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

MD5: 198eb8c08bc87cd8a0996883a2884742 C:\Program Files (x86)\QuickTime\QTSystem\CoreVideo.qtx

MD5: afdae59fe562a7cdb44f9d4abedac316 C:\Program Files (x86)\QuickTime\QTSystem\QTCF.dll

MD5: 1d856e6e7490447fcfaa46e09a2bf9c9 C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.qts

MD5: 5f692164afa0ae006844b2c1e2b6b1b2 C:\Program Files (x86)\QuickTime\QTSystem\QuickTime3GPP.qtx

MD5: 2ddcb8c83cfd9be00706d91ea0263619 C:\Program Files (x86)\QuickTime\QTSystem\QuickTime3GPPAuthoring.qtx

MD5: 5378df00a458b3e1189b419e4b29990c C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeAudioSupport.qtx

MD5: 366c3385032a92e2b1f38fd083074c45 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeAuthoring.qtx

MD5: 6bc0f686121454054122e1baa865efd2 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeCapture.qtx

MD5: 08bdedf5b34203c49bc455ef8e763b9e C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeEffects.qtx

MD5: 9028acda592cf58abe350e55fd2e6e5c C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeEssentials.qtx

MD5: be1c5da550ed842eb3394dced9a19a6b C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeH264.qtx

MD5: 299077e590eea79e2a241ac3c0942aeb C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeImage.qtx

MD5: cfdfea66f36c30b404ab83aec3015150 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeInternetExtras.qtx

MD5: 4089c7d54bc87a1cf9661634e985f9a0 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG.qtx

MD5: c460d8cc023a69cde786f5fcc2089bea C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG4.qtx

MD5: 3485c7385cffe5e01ea0b420caef2b52 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMPEG4Authoring.qtx

MD5: c87b8c125dfb912b2ba9fda11c938bc6 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeMusic.qtx

MD5: 4257a39b9b08190b9d2dcd15706403f9 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreaming.qtx

MD5: 5dbf2eaca2efff9047f1181bd22ec587 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreamingAuthoring.qtx

MD5: 50b852e53133e6582be4d8c897197455 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeStreamingExtras.qtx

MD5: 111821ad332c87c54192bbc05618a831 C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeVR.qtx

MD5: 0aee5668eb59912f32ff245bfa72465f C:\Program Files (x86)\QuickTime\QTTask.exe

MD5: 88c638bcf3a22438ee7ddf1d98f0a21c C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe

MD5: f694d53c6bf3ee02d128d5a42dbecc9e C:\Program Files (x86)\Razer\DeathAdder\razerlan.dll

MD5: 2a032efae93d6c5de769796fb355185f C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe

MD5: a7e62c93b62c072c3e59cbfdd53c43a6 C:\Program Files (x86)\Razer\DeathAdder\razertra.exe

MD5: 4e8238ca1046d97636e63abf173772cd c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll

MD5: 56b73e1adfd768e80369c4a2e68f35df c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll

MD5: e7856c9b1ae2ded52c98e69497308083 c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll

MD5: f780ee20d47a23060dbce20dc104e272 C:\Program Files (x86)\Real\RealPlayer\realplay.exe

MD5: c68e175584e01b58328681a08bbcdde4 c:\program files (x86)\real\realplayer\rpwa3260.dll

MD5: b114db354d13a21c1ac2b1807ee2f500 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

MD5: db9c119908b4666aef3e5a54def5b3cf C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe

MD5: 8a9828975a857e477efef5a61ba45ac0 C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

MD5: 60083dd364917ab97722c9991c54f4d3 C:\Program Files (x86)\Xfire\icons.dll

MD5: c9cc74d4663dfc29c1691d776f7a0368 C:\Program Files (x86)\Xfire\Xfire.exe

MD5: 99321bdcb0c8df73abcafe4078d92bca C:\Program Files (x86)\Xfire\XFIRE_LANG_us.dll

MD5: 33e246eaa27ee7818e4c2c828c74ec93 C:\Program Files (x86)\Xfire\xfire_toucan_44183.dll

MD5: 08914bc785004fb29cb58ff435ec0a7b C:\Program Files\AVAST Software\Avast\1033\Base.dll

MD5: afde47adfc785bffe2ccaebd31617871 C:\Program Files\AVAST Software\Avast\1033\UILangRes.dll

MD5: 48d892b1b3adb0a6502095ab0014d368 C:\Program Files\AVAST Software\Avast\Aavm4h.dll

MD5: b14242184207da229a3ac25168ffc44a C:\Program Files\AVAST Software\Avast\AavmRpch.dll

MD5: f481bea0373fd30e99c0c85c1a1d9e39 C:\Program Files\AVAST Software\Avast\AhAScr.dll

MD5: 14e6721d9883753a3c4bcf0159fa9ca8 C:\Program Files\AVAST Software\Avast\AhResBhv.dll

MD5: 8b476d677dfe35efe7b3edbf377f0038 C:\Program Files\AVAST Software\Avast\AhResJs.dll

MD5: 958eae9951d450c33785aaa3e8c18643 C:\Program Files\AVAST Software\Avast\AhResMai.dll

MD5: fae73418fe3e9d62d1dc275c1a6470f7 C:\Program Files\AVAST Software\Avast\AhResMes.dll

MD5: ea273c786c0f7537b84cb91dafc33079 C:\Program Files\AVAST Software\Avast\AhResNS.dll

MD5: 8941988b4aaf4713a3b3fcb294b2edf7 C:\Program Files\AVAST Software\Avast\AhResP2P.dll

MD5: a333dd2e324c6ba76a3d3e4bbcb94f3c C:\Program Files\AVAST Software\Avast\AhResStd.dll

MD5: 9fb89dbf8a2a3c26d036b8569b154590 C:\Program Files\AVAST Software\Avast\AhResWS.dll

MD5: ace9981252e1f262ac276b7615ef6feb C:\Program Files\AVAST Software\Avast\ashBase.dll

MD5: effc885db306a3677cc3a62647c6ad08 C:\Program Files\AVAST Software\Avast\ashMaiSv.dll

MD5: f0fe90c1f71fe7f6ddeaef8c0b6c4a24 C:\Program Files\AVAST Software\Avast\ashServ.dll

MD5: 96ffbb4c8e32325c1b49a393284f77ee C:\Program Files\AVAST Software\Avast\ashTask.dll

MD5: 53fa4e859b6440eaf6673e813caa7c4e C:\Program Files\AVAST Software\Avast\ashTaskEx.dll

MD5: af4a3cca045eee5f7a2280284052e361 C:\Program Files\AVAST Software\Avast\ashWebSv.dll

MD5: 5a312e660ba43a3233efc11146d3a318 C:\Program Files\AVAST Software\Avast\ashWsFtr.dll

MD5: 9ad6a0464da99fada8677f495ff84043 C:\Program Files\AVAST Software\Avast\aswAux.dll

MD5: 3992d00ea19fcde5710e31b1768efa20 C:\Program Files\AVAST Software\Avast\aswCmnBS.dll

MD5: a822e400eb848449368a2d6c99dee8e8 C:\Program Files\AVAST Software\Avast\aswCmnIS.dll

MD5: d662f9567979fcacac8301b6ce18971b C:\Program Files\AVAST Software\Avast\aswCmnOS.dll

MD5: 19c6484fd56c29dee30f1c6f8cbd374d C:\Program Files\AVAST Software\Avast\aswData.dll

MD5: 2fd69aee607066766930ceb925db0459 C:\Program Files\AVAST Software\Avast\aswDld.dll

MD5: dc9ec6dbb7b5ac6d1ec070df4e8ed903 C:\Program Files\AVAST Software\Avast\aswEngLdr.dll

MD5: 95ffe45120788d0bac3071a913172a58 C:\Program Files\AVAST Software\Avast\aswIdle.dll

MD5: fd2d867fe775cc5357cecf2f14515b61 C:\Program Files\AVAST Software\Avast\aswLog.dll

MD5: 464fdfa22c63d742de476a83042d53f9 C:\Program Files\AVAST Software\Avast\aswProperty.dll

MD5: acd4e66d0abdcd3e74a1673cdeb38fcc C:\Program Files\AVAST Software\Avast\aswSqLt.dll

MD5: f01e06906743d0bc93d51328f4cdb8ce C:\Program Files\AVAST Software\Avast\aswUtil.dll

MD5: 75d85bd73b985dd443ea640c0a907b4f C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

MD5: d16c826f375a44802bf317982e81a7e2 C:\Program Files\AVAST Software\Avast\AvastSvc.exe

MD5: e7cf222185411c6a3e68273c452b3283 C:\Program Files\AVAST Software\Avast\AvastUI.exe

MD5: d28f68d1b224e4b254fd5fcecc941340 C:\Program Files\AVAST Software\Avast\CommonRes.dll

MD5: 7fdcd696f1245a12f38eea45adee4014 C:\Program Files\AVAST Software\Avast\defs\11080200\algo.dll

MD5: 708a975cdacc2b844e3727dd28a24333 C:\Program Files\AVAST Software\Avast\defs\11080200\aswAR.dll

MD5: 4a438391a6df4ae046c89165dc39637c C:\Program Files\AVAST Software\Avast\defs\11080200\aswCmnBS.dll

MD5: 0ebddd2039b2d47e2e661ec1be65e81e C:\Program Files\AVAST Software\Avast\defs\11080200\aswCmnIS.dll

MD5: e4bd1e2459fa897af867f667eec62d1e C:\Program Files\AVAST Software\Avast\defs\11080200\aswCmnOS.dll

MD5: bd1a4571d002fab759d4db6ba96ad7db C:\Program Files\AVAST Software\Avast\defs\11080200\aswEngin.dll

MD5: c2b0541deb6c44ec3573e8ac568df412 C:\Program Files\AVAST Software\Avast\defs\11080200\aswScan.dll

MD5: fa97ad1885871c3184427138b7c1dd41 C:\Program Files\AVAST Software\Avast\snxhk.dll

MD5: e849bbf4d8045c3e6bf7a23fa91e36ab C:\Program Files\Bonjour\mdnsNSP.dll

MD5: b2553363fd3da02036c628dc62431c25 c:\program files\dell printable web\toolband.dll

MD5: 7317a0b550f7ac0223b7070897670476 c:\program files\dell support center\pcdsrvc_x64.pkms

MD5: 0d1ab6496aaf580f7e36832f43239f3e C:\Program Files\Dell Support Center\uaclauncher.exe

MD5: 0840abbbdf438691ee65a20040635cbe C:\Program Files\Dell\DellDock\DockLogin.exe

MD5: d38469601b72d2da4f847fc642174e21 C:\Program Files\iPod\bin\iPodService.exe

MD5: 08e5d3f98f80e5b7a2e965dfd42c4d21 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

MD5: f4ba00c4a7f7ad09ee1ba53b689a2a7b C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.dll

MD5: 646a678a73513ef59f98aa14e24a99ad C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

MD5: 1a1e09428ece086216d0cbd68414fcfe C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll

MD5: cf44a8b85f5dd1f8eb25639f5dd7e360 C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll

MD5: fa1a3a97a5f3ca404eb55c755336b7dd C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll

MD5: c2591e7bcacbde2eb6d15cff5d7432be C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

MD5: e638c845403ab63112673a0c72c07789 C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll

MD5: 0c316a33bbe35cd1097936393a177656 C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

MD5: d3f58f9d635a70faebd768330c96a441 C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll

MD5: b226054bfa3d3a1920f7b95e54f3e87d C:\Users\troyswi\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll

MD5: 669336429b745492266adaaf3b330e67 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMBasErr.dll

MD5: a6044dcbfe660694fa7f7ebf5c9638a7 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMBasFnc.dll

MD5: fcf7ac4b5afa3782a41ed7a861b5a0f6 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMCondPrm.dll

MD5: aaa4adeaa7f79907697e06d6535001d6 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMEngine.dll

MD5: 019dc76474d8f213a64e8f02f1472496 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMProcessPrm.dll

MD5: 6029847520ec4c1baba408dfcc76c887 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMTaskPrm.dll

MD5: b251c920377719d5326041fc84558d9e C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMTrigPrm.dll

MD5: 88fa057eb9da9c803a912b9c3df1eec7 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\AMWorkflowPrm.dll

MD5: fc8f48c047fa1fd5f847f48824981e43 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA8TrgHk.dll

MD5: d354c50b3ec54cfa9ad6821998367d3e C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPA_TS.exe

MD5: 8f25e14c53359b3511fbd71a90caa9d5 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAEM.exe

MD5: fb2fcdcd1bc5383da13f062efb7f9106 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_EXEC.exe

MD5: 57efbb89a6a940ad332cad5f65a1161b C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\BPAS_MAN.exe

MD5: 5f0742a9cf9dc1f20ac61c7d6353414c C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\CDRVDL32.dll

MD5: 5bb3f0cf453010f34b9fffc3b66e56e5 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\CDRVHF32.DLL

MD5: aeac138029433ea3b11a0a8cb690350b C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\Encrypt.dll

MD5: 5e31fc52f7ccda750fd7982a20fc4f4a C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\Importing.dll

MD5: 177afeba653e34da05a232dab7b6e7c9 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\ztv7z.dll

MD5: 9ec7cf498f3f71e807629577c7bc2d19 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\ztvCabinet.dll

MD5: a3922cd380f968b898da4bb414c38900 C:\Users\troyswi\AppData\Local\Programs\AutoMate BPA Server 8\ztvUnRar38.dll

MD5: 94e542f64cc16eecea2c3b89f3f1ff47 C:\Users\troyswi\AppData\Roaming\Mozilla\Firefox\Profiles\mps0nv2i.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\imtcp_xpcom.dll

MD5: 644d1b1db02e8b2ec8e9d7e43f67e5bb C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\23bc3936180ff789f44259a211dfc7fc\mscorlib.ni.dll

MD5: 4490f1c1ccab3d991fb88f3fbfa75277 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e8add38eb4f9c07790b5be549c5f0dae\System.Configuration.ni.dll

MD5: a7e9b5d775f3a8e40b014365dab5505a C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e979f76558e7e1f7127a5244fb5a0347\System.Drawing.ni.dll

MD5: a4c9eab5ae87cbb4c384c9fe74884539 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\565a1d9d3fed4d64ddb884a49a1a0e25\System.Management.ni.dll

MD5: a8fb825cbca81c4e46ddaaee66753f91 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\443b11b528455611c7549b56349a56eb\System.Runtime.Remoting.ni.dll

MD5: 91481c43bb2427843f45efc509eb8724 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d9b3bb263a38ca5767baf78cacf380d8\System.ServiceProcess.ni.dll

MD5: 7093097140c1617232e301e98ffa4c5d C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\77631b8c99bc572962e558cdac417477\System.Web.Services.ni.dll

MD5: f35825dc45fa8cccd76e03aa4f6ae638 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\bb3ccd9385192fd043a41c62d37e34fe\System.Web.ni.dll

MD5: 7412929627084ac490eff5c282cf44bd C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\933baa29f5feba3093ba81c5b9b82b1c\System.Windows.Forms.ni.dll

MD5: 00652de3983f094cbd2341a53f309a95 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\682572c507ea7552c3db1842c21bf9c8\System.Xml.ni.dll

MD5: aca1c6403496495a150089a48e17df61 C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f7048e198c963fa189cff3aea17dfee3\System.ni.dll

MD5: 7300da7e52cd98dbcdc49a8a38a0c13d C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\93e867e55d7df3a8b4bd1aba3af6f18d\WindowsBase.ni.dll

MD5: 2ce97833ba80e7c319390c4b071bda00 C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\74353039393f68f4c068cc37f759e5be\mscorlib.ni.dll

MD5: 2d7617d3143493eb8bd38290e9d2e51a C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\ca8307311e87b234b2faa5ee08332722\PresentationCore.ni.dll

MD5: ed51ca800645080bbfdda92c1b172742 C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\2250ddb1626087da27fb00f46a679ff5\PresentationFramework.ni.dll

MD5: 1851a98f404057b56bf2ea2276ea1efa C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\b028b6680f5a3b315320a5bf7b659518\SMDiagnostics.ni.dll

MD5: c1fa0945732c9b45c937d2ba15c724ea C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\618e6d3cd8824d6d72ae1767acaa1078\System.Configuration.ni.dll

MD5: f61faa6504ef9939867bc4ca5f50f2c0 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\0d4cdd1b911d6e28b4fd5c43ab39f7ea\System.Core.ni.dll

MD5: 63c13a88fb0520a8e2d46fd529680f16 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\53591520988a6ee49924e1efc911df30\System.Drawing.ni.dll

MD5: e9dafc0221287cfd5340de20875d94b5 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\02c1363d5beb2ae5c5722bc8f6c5b77a\System.IdentityModel.ni.dll

MD5: e28c7575c28cfc0508f395cb8af754bc C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\b9f7f5b0b28dd57cb5400c437c388545\System.Runtime.DurableInstancing.ni.dll

MD5: 051399952f8f2d91e8172c9a022f6714 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\d0ce480f313eb8be9a3a4dd6d7902325\System.Runtime.Serialization.ni.dll

MD5: aff98088ba331df5120f7d7b94b94773 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\dc31b22f78cb510bf470f0ab5ef65816\System.ServiceModel.ni.dll

MD5: 33101aaeff4e876d07f7ecb3616e68db C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f3e016a2e799cfe233b13d88e90c0e0b\System.Windows.Forms.ni.dll

MD5: 2bc43a2c4b0b3bc7863fede5031a9037 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\19f85a4f6faaeb87a9055ccf23a9f8b7\System.Xaml.ni.dll

MD5: 6ac72593c1244399816bb40f21b41af6 C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7cc17b90932adaad5651ceb526cade44\System.Xml.ni.dll

MD5: 68f2e9e1ee53b6aa03ab6ec62c43f145 C:\Windows\assembly\NativeImages_v4.0.30319_32\System\5a8bf6ab1a6ba60e7355fa4cc61fd0c5\System.ni.dll

MD5: cc16b7c2367f8c4762bf770286b0a0b1 C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\3154b66d01dcd674b256e03d5f359fac\WindowsBase.ni.dll

MD5: 9bffe5d6e70604243c1865fc6d1a3fc1 C:\Windows\Downloaded Program Files\DownStarter2.ocx

MD5: d715a946e66028cdb04c9e9f8c7137f5 C:\Windows\Downloaded Program Files\dwusplay.exe

MD5: da607f815683537cb66b955ffe645da9 C:\Windows\Downloaded Program Files\ijjiSetup1010.dll

MD5: 2d54daecba60eb03f9e63dd50669f634 C:\Windows\Downloaded Program Files\isusweb.dll

MD5: 0855be0b05aa4a4f2f7b412eb4f09e02 C:\Windows\Downloaded Program Files\PubPlugin.dll

MD5: 823451876778f382b23afe20ef2ddc20 C:\Windows\Downloaded Program Files\qsax.dll

MD5: 47c071994c3f649f23d9cd075ac9304a C:\Windows\ehome\ehRecvr.exe

MD5: 0862495e0c825893db75ef44faea8e93 C:\Windows\Explorer.exe

MD5: af2d82d297609df60469bfae48645762 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll

MD5: c7673048872bf6ead0a46d17d89b7537 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

MD5: 1a11a757d613f8a815b8e30025522628 C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll

MD5: 7b1028a754bb63bbfc75b6a94c3f47e5 C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll

MD5: fd435df8c9ca7a49ccbf7cd2f7627739 C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll

MD5: f711c8d93a8e4410c284d177b76c7f2b C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll

MD5: 0171af8fb6552436cfbb134ea27cb21b C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll

MD5: 7fc3f2f063254ad029b0436d1d7e8748 C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll

MD5: d5315deb9c5981ae818fae417e967437 C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll

MD5: 522f5b63b0979ea93b45d786ac485149 C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll

MD5: 1815a6f288b835cd5e0099fe0ccdaedb C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll

MD5: c3fdea805ffc0bef4d108b430fba6a4d C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll

MD5: 1463f56a2a1e6398c277dd02cebea8d1 C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll

MD5: 5ffeaf29b6cbb25c92f22b5166746b67 C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll

MD5: a2c43fae9e1f5c79e2ea4855dc4b807a C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll

MD5: 55b910925cbfebaa140f6d7ec82febe6 C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll

MD5: d6850e1cf7009de46bfa7c4437b543f5 C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll

MD5: e3aae01232daa7b436722bdf8511a1e0 C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll

MD5: a93adbd004f305258c4533744cca7a09 C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll

MD5: 91af418cd9698b68a5bd319c0f8a6d52 C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll

MD5: c8affa0e9945732f33b5b5e14a84b751 C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll

MD5: 5d3d9328912c900b42756701dcca2d37 C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll

MD5: 400667a186ae36b6754e9c1466c8ebc6 C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

MD5: 269184e1ae6ff4db7aab5ed25e52b1f4 C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

MD5: f00608e4a2db6e58152784926c1af2ca C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

MD5: 10b13a6d62f3b12828c89d096784e097 C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll

MD5: c0dfe15654baf2784af7456487c3e1ab C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

MD5: 0b1de50bc1c0e71bb7155a71185f0ace C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll

MD5: aedb7dd661b387ad8cabc82fe80b4ed2 C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll

MD5: d82924a11dfc73887e076a540bec135f C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

MD5: f3813b40315a5d9e8611aeb157455b1b C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

MD5: ab4f3484269372226d9ae15747de958f C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll

MD5: e271a35d55fd45c8b4ab0bf76f474c0a C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll

MD5: 9a33ba2673ad543a75868fc95c91da6c C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll

MD5: 1fcfdc07bf8ee25b0a2e1e2790bd52e0 C:\Windows\system32\aticfx32.dll

MD5: c72249ed471f702d95264608b7c282b2 C:\Windows\system32\atiu9pag.dll

MD5: 0a1a3fa8d46cc1d7a46436a0dab3223f C:\Windows\system32\atiumdag.dll

MD5: 3b4f5141009d19a92375d38288c4b868 C:\Windows\system32\atiumdva.dll

MD5: 53831de9162c6c2378574b59eb786bf1 C:\Windows\system32\corpol.dll

MD5: 11cdf138552bfec115b60ed6dc3aceb6 C:\Windows\system32\DEVRTL.dll

MD5: 5e08ac958be05247ff1539e0d1ce7905 C:\Windows\system32\dinput8.dll

MD5: dc3cfded2a4b78aabce289fc1b8def54 C:\Windows\system32\dleacoms.exe

MD5: 68422130f843a88b4d4bdd40493d5e0b C:\Windows\system32\dleasm.dll

MD5: c78973ad87fe43d6016d8ab98821ada3 C:\Windows\system32\dleasmr.dll

MD5: 62390f4ace9e2b63e3ca26b7f7497897 C:\Windows\system32\DNSAPI.dll

MD5: c373ef6e2a25ba99598ca64abc797469 C:\Windows\system32\dnssd.dll

MD5: aa097220efc843a0581dfc06d082d4af C:\Windows\system32\DRIVERS\RxFilter.sys

MD5: 2af58d15edc06ec6fdacce1f19482bbf C:\Windows\system32\Explorer.exe

MD5: 8898c95862d03d16b2a06db4db6bb6b2 C:\Windows\system32\explorerframe.dll

MD5: 0c7b28decceb403b8853f52664f26e9b C:\Windows\system32\IEFRAME.dll

MD5: f88391450bfdd2c789bd98ff54f51745 C:\Windows\system32\IEUI.dll

MD5: 0908dac8249e9ae1c73ef80595ac0bc6 C:\Windows\system32\jsproxy.dll

MD5: 74c76bb54b26ce50c4bc755f92687c63 C:\Windows\system32\MFC42.DLL

MD5: 3a2c4d7ffbb0101cad4fd5de0705757a C:\Windows\system32\msfeeds.dll

MD5: bd669749eaeff96773b5f8d0a43e0068 C:\Windows\System32\msxml3.dll

MD5: 9131fe60adfab595c8da53ad6a06aa31 C:\Windows\system32\npptNT2.sys

MD5: 5764c381949147ebcfb9a7134e2abf06 C:\Windows\system32\ODBC32.dll

MD5: 21cf5c7d8d727dcc337a1d251b6135f4 C:\Windows\system32\schannel.DLL

MD5: 71402c7923f6b7f8acb48e50f35463e7 C:\Windows\system32\SearchIndexer.exe

MD5: 4b9e4ce667df26ada061aa81e9aa841d C:\Windows\system32\SPFILEQ.dll

MD5: e0d525515537e60aba8f3e29209f02e8 C:\Windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe

MD5: 8d908f346eedd752005a32787a6dcafa C:\Windows\System32\StructuredQuery.dll

MD5: 25819a6361f10c30905b5d0fdb8dca42 C:\Windows\system32\t2embed.dll

MD5: 7271b48b193c9624416bd5006cd8b92f C:\Windows\system32\tquery.dll

MD5: f509b44d94db9c832ca26297be0cc04d C:\Windows\System32\vds_ps.dll

MD5: 6d9b75275c3e3a5f51aef81affadb2b6 C:\Windows\System32\wcncsvc.dll

MD5: bb5ec38f8d4600119b4720bc5d4211f1 C:\Windows\System32\webclnt.dll

MD5: 4fb96aacf2f05c7357546becd7678863 C:\Windows\system32\webio.dll

MD5: cc9bbcfc715fbedf7ae476106fe653e9 C:\Windows\system32\WINHTTP.dll

MD5: 374b26395852a9092bde2e4c8d4d0c8d C:\Windows\system32\WSCAPI.dll

MD5: e702ed19c332c1f12c1403d100e2f4f3 C:\Windows\syswow64\CFGMGR32.dll

MD5: 6c9c05d5344b9ab80e9180fc859bc45a C:\Windows\syswow64\DEVOBJ.dll

MD5: 62390f4ace9e2b63e3ca26b7f7497897 C:\Windows\SysWOW64\DNSAPI.dll

MD5: 0c7b28decceb403b8853f52664f26e9b C:\Windows\SysWOW64\ieframe.dll

MD5: 438147dae79299a5a9240219942b4439 C:\Windows\SysWOW64\iepeers.dll

MD5: 570c6b12e7bd623a85ea1f01c75c346a C:\Windows\syswow64\iertutil.dll

MD5: 0bd0665d8bfd321d3b5a898ed09d1df3 C:\Windows\SysWow64\jscript.dll

MD5: 40eacee0b6432cbe2459a11b298e9d88 C:\Windows\syswow64\kernel32.dll

MD5: 4b5feb528fa14672dc016329d6bc6327 C:\Windows\syswow64\KERNELBASE.dll

MD5: efbef826c183cf8edab324ce514d69b7 C:\Windows\SysWOW64\Macromed\Flash\Flash10t.ocx

MD5: 21a67095edc11a528f5434d28bb0ef3c C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

MD5: 1816d4cf1a7cbb72298ab120059226d4 C:\Windows\SysWOW64\mshtml.dll

MD5: 5ed76a46eff78575f99d3bf3302889cf C:\Windows\SysWOW64\ntdll.dll

MD5: e2c2d8c982316c8abf800c6ce3f28fab C:\Windows\syswow64\ole32.dll

MD5: 06333b8d05d4f3a2af25eb14fc0a1dff C:\Windows\syswow64\OLEAUT32.dll

MD5: 21cf5c7d8d727dcc337a1d251b6135f4 C:\Windows\SysWOW64\schannel.dll

MD5: ca4d146eac05ec4ba5fc4936f3369627 C:\Windows\syswow64\urlmon.dll

MD5: 509b666bf56d469c641df55652c76168 C:\Windows\SysWow64\vbscript.dll

MD5: b231b788ce243bb44ce2db900fdbc20e C:\Windows\SysWOW64\WB9ENT.OCX

MD5: 177df28315bf4300ecb5cbeeee961292 c:\windows\syswow64\webcheck.dll

MD5: 27cdaf355cce3762c7f13719e814418b C:\Windows\syswow64\wininet.dll

MD5: a1bac75f7bceee6d471cf12cd19057e3 C:\Windows\SysWOW64\WWB9_32W.DLL

MD5: c419df63e0121d72411285780c2fc6cc C:\Windows\UpdReg.EXE

MD5: 0b3595a4ff0b36d68e5fc67fd7d70fdc C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCP80.dll

MD5: c9564cf4976e7e96b4052737aa2492b4 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll

MD5: d34a527493f39af4491b3e909dc697ca C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll

MD5: 4c39358ebdd2ffcd9132a30e1ec31e16 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll

MD5: cdbe9690cf2b8409facad94fac9479c9 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll

MD5: ca6ade4f7761bb15b3325356dc3b82bb C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll

MD5: fbfca1a574d47ee575448b719cbbf2e4 C:\Windows\WinSxS\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\MFC90ENU.DLL

MD5: d3ead1cf16ba729a7f7c9a5d94aa7c05 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7600.16661_none_ebfb56996c72aefc\COMCTL32.DLL

MD5: 4b8dd8541c0e26602005dd0137333615 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll

No file uploaded.

Scan finished - communication took 2 sec

Total traffic - 0.04 MB sent, 1.45 KB recvd

Scanned 694 files and modules - 62 seconds

==============================================================================

Link to post
Share on other sites

but, the first scanner picked up "66" infections. :blink:

It happens! :lol: They're taken care of, though ;)

I suggest you remove the following application, as it is a "Registry Cleaning Application" - it can damange your computer significantly:

Advanced PC Tweaker

Please download and install Revo Uninstaller (Freeware) from here. Then please run Revo Uninstaller and select Advanced PC Tweaker.

Please click Uninstall icon to uninstall the selected program.

2ev563d.gif

Please choose Advanced.

aubbd2.gif

Then click Next and follow the prompts.

Please click Select All (1.) and Delete (2.)

2hdphqf.gif

to delete all registry items, folders and files listed by Revo.

If asked to restart the computer, please do so immediately.

-----------

Next, please delete the following file (in bold):

C:\Users\troyswi\AppData\Local\Google\Chrome\User Data\Default\Default\jhlplclcmoknjecmpjigigockbklgfgj\contentscript.js

-----------

Other than those 2 issues above, your logs appear to be clean ;)

Before we move on, please take the time to install the following updates, as using outdated applications leaves you extremely vulnerable to getting infected again ;):

I see you have User Accounts Control (UAC) disabled.

This is an important security feature which helps prevent malware and other unwanted software from being installed on your computer.

I strongly suggest you keep it enabled. See this link for instructions on how to enable it: http://windows.microsoft.com/en-US/windows-vista/Turn-User-Account-Control-on-or-off

-----------

Java is out of date and older versions contain vulnerabilities. Please update to the newest version.

Download the newest version from here http://www.oracle.com/technetwork/java/javase/downloads/index.html.

It's important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.

Go to Start > Control Panel and open Add or Remove Programs.

Search in the list for all previous installed versions of Java. (J2SE Runtime Environment).

They will have this icon next to them: javaicon.gif

Select each in turn and click Remove.

Once old versions are gone, please install the newest version.

-----------

Firefox is out of date. Using an outdated version of a web browser leaves you extremely vulnerable to malware!

Please visit Mozilla site and update it to the latest version.

-----------

Please let me know how the updates went, as failed updates may indicate additional malware ;)

Link to post
Share on other sites

I've done everything you've said, and all of the updates & uninstalled programs.. well, it went well. No errors. :]

I have a question, though; the reason I kept the older version of FireFox was because of its look - is it possible to "retrieve" that same look for the newest version of Firefox? o_o I realize it's not a technical issue. :P

Link to post
Share on other sites

Glad to hear the updates went well! :)

I have a question, though; the reason I kept the older version of FireFox was because of its look - is it possible to "retrieve" that same look for the newest version of Firefox? o_o I realize it's not a technical issue. :P

Unfortunately, I don't believe so- I was in the same position but I soon realized that the new Firefox is actually pretty nifty once you get the hang of it :D

Unless there are any further issues, I will now provide you with some suggestions for security software, but first, ComboFix must be uninstalled ;):

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

-------------

Please consider using these ideas to help secure your computer. While there is no way to guarantee safety when you use a computer, these steps will make it much less likely that you will need to endure another infection. While we really like to help people, we would rather help you protect yourself so that you won't need that help in the future. :)

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates or get into the habit of checking Windows Update regularly. They usually have security updates every month. You can set Windows to notify you of Updates so that you can choose, but only do this if you believe you are able to understand which ones are needed. This is a crucial security measure.

It is really dangerous to go online without an antivirus. Without one, you are extremely likely to get infected and the consequences could be even worse next time. All of the following are excellent free antiviruses. Be sure to only install one.

avast!.

AntiVir

AVG

Please consider installing and running some of the following programs; they are either free or have free versions of commercial programs:

Spybot-Search & Destroy

A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features if you don't have the resident part of another anti-spyware program running.

SpywareBlaster

A tutorial on using SpywareBlaster to prevent malware from ever installing on your computer may be found here.

SpywareGuard

A tutorial on using SpywareGuard for real-time protection against spyware and hijackers may be found here.

Please, consider maintaining a firewall with HIPS (Host Intrusion Prevention Systems). Firewalls are extremely important and are the first part of your computer's defense. HIPS stops malware by monitoring its behavior and it's very important, too.

A firewall is a software program or piece of hardware that helps screen out hackers, viruses, and worms that try to reach your computer over the Internet.

If you are using the Windows Firewall please note that it doesn't monitor or block outbound traffic and is therefore less effective than other free alternatives.

These firewalls are good and do have free versions available

A tutorial on understanding and using firewalls may be found here.

If you use Internet Explorer, it is a good idea to use IE-Spyad for ZonedOut which provides protections against malicious websites. (Requires 2 downloads)

Please keep these programs up-to-date and run them whenever you suspect a problem to prevent malware problems. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster and IE-Spyad can be run with any of them.

Note that there are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:

http://www.spywarewarrior.com/rogue_anti-spyware.htm

A similar category of programs is now called "scareware." Scareware programs are active infections that will pop-up on your computer and tell you that you are infected. If you look closely, it will usually have a name that looks like it might be legitimate, but it is NOT one of the programs you installed. It tells you to click and install it right away. If you click on any part of it, including the 'X' to close it, you may actually help it infect your computer further. Keeping protection updated and running resident protection can help prevent these infections. If it happens anyway, get offline as quickly as you can. Pull the internet connection cable or shut down the computer if you have to. Contact someone to help by using another computer if possible. These programs are also sometimes called 'rogues', but they are different than the older version of rogues mentioned above.

Please consider using an alternate browser. Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScripts, can make it even more secure. Opera is another good option.

If you are interested, Firefox may be downloaded from here

Opera is available here: http://www.opera.com/download/

For much more useful information, please also read Tony Klein's excellent article: How did I get infected in the first place

Hopefully these steps will help to keep you error free. If you run into more difficulty, we will certainly do what we can to help. :)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.