MALWAREBYTES came back clean with first scan (been coming back clean. i have scanned this pc before today)
MINITOOLBOX
MiniToolBox by Farbar Version: 23-07-2012
Ran by BRUCE (administrator) on 20-08-2012 at 13:56:41
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
DW1520 Wireless-N WLAN Half-Mini Card = Wireless Network Connection (Connected)
SonicWALL NetExtender Adapter = Local Area Connection 2 (Connected)
Intel® 82577LM Gigabit Network Connection = Local Area Connection (Media disconnected)
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
reset
set global
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : clark-b
Primary Dns Suffix . . . . . . . : csa1.com
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : csa1.com
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . : csa1.com
Description . . . . . . . . . . . : DW1520 Wireless-N WLAN Half-Mini Card
Physical Address. . . . . . . . . : 90-00-4E-19-15-AC
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::e4d6:6169:ed38:7f16%12(Preferred)
IPv4 Address. . . . . . . . . . . : 10.1.148.23(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.240.0
Lease Obtained. . . . . . . . . . : Friday, August 17, 2012 2:03:25 PM
Lease Expires . . . . . . . . . . : Tuesday, August 28, 2012 2:03:26 PM
Default Gateway . . . . . . . . . : 10.1.150.254
DHCP Server . . . . . . . . . . . : 1.1.1.1
DHCPv6 IAID . . . . . . . . . . . : 244318286
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-20-3D-9A-5C-26-0A-47-BE-AC
DNS Servers . . . . . . . . . . . : 10.1.150.221
10.1.150.202
Primary WINS Server . . . . . . . : 10.1.150.221
NetBIOS over Tcpip. . . . . . . . : Enabled
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : csa1.com
Description . . . . . . . . . . . : Intel® 82577LM Gigabit Network Connection
Physical Address. . . . . . . . . : 5C-26-0A-47-BE-AC
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 12:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft 6to4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Reusable ISATAP Interface {8C84A5E7-350E-4C28-B31A-B61196141A9D}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : csa1.com
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #11
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: oprsvr2.csa1.com
Address: 10.1.150.221
Name: google.com
Addresses: 2607:f8b0:4002:802::1000
74.125.134.113
74.125.134.101
74.125.134.102
74.125.134.138
74.125.134.100
74.125.134.139
Pinging google.com [74.125.134.113] with 32 bytes of data:
Reply from 74.125.134.113: bytes=32 time=29ms TTL=47
Reply from 74.125.134.113: bytes=32 time=25ms TTL=47
Ping statistics for 74.125.134.113:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 25ms, Maximum = 29ms, Average = 27ms
Server: oprsvr2.csa1.com
Address: 10.1.150.221
Name: yahoo.com
Addresses: 98.138.253.109
98.139.183.24
72.30.38.140
Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
Reply from 98.138.253.109: bytes=32 time=79ms TTL=47
Reply from 98.138.253.109: bytes=32 time=117ms TTL=47
Ping statistics for 98.138.253.109:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 79ms, Maximum = 117ms, Average = 98ms
Server: oprsvr2.csa1.com
Address: 10.1.150.221
Name: bleepingcomputer.com
Address: 208.43.87.2
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
12...90 00 4e 19 15 ac ......DW1520 Wireless-N WLAN Half-Mini Card
10...5c 26 0a 47 be ac ......Intel® 82577LM Gigabit Network Connection
1...........................Software Loopback Interface 1
11...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
14...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
26...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #11
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 10.1.150.254 10.1.148.23 25
10.1.144.0 255.255.240.0 On-link 10.1.148.23 281
10.1.148.23 255.255.255.255 On-link 10.1.148.23 281
10.1.159.255 255.255.255.255 On-link 10.1.148.23 281
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 10.1.148.23 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 10.1.148.23 281
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
12 281 fe80::/64 On-link
12 281 fe80::e4d6:6169:ed38:7f16/128
On-link
1 306 ff00::/8 On-link
12 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (08/20/2012 10:25:16 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHFE7A.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:25:15 AM) (Source: Symantec AntiVirus) (User: )
Description: Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHFE7A.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:25:15 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHFE7A.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:54 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF8D2.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:53 AM) (Source: Symantec AntiVirus) (User: )
Description: Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF8D2.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:53 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF8D2.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:30 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF855.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:29 AM) (Source: Symantec AntiVirus) (User: )
Description: Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF855.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:29 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF855.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:08 AM) (Source: Symantec AntiVirus) (User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF565.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
System errors:
=============
Error: (08/17/2012 02:03:24 PM) (Source: Microsoft-Windows-GroupPolicy) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (08/17/2012 02:03:22 PM) (Source: NETLOGON) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain CSASTAFF1 due to the following:
%%1311
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Error: (08/17/2012 01:15:15 PM) (Source: Microsoft-Windows-GroupPolicy) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (08/17/2012 01:15:13 PM) (Source: NETLOGON) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain CSASTAFF1 due to the following:
%%1311
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Error: (08/16/2012 07:57:21 AM) (Source: NETLOGON) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain CSASTAFF1 due to the following:
%%1311
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Error: (08/06/2012 10:23:38 AM) (Source: Microsoft-Windows-GroupPolicy) (User: NT AUTHORITY)
Description: The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.
Error: (08/06/2012 10:23:37 AM) (Source: NETLOGON) (User: )
Description: This computer was not able to set up a secure session with a domain
controller in domain CSASTAFF1 due to the following:
%%1311
This may lead to authentication problems. Make sure that this
computer is connected to the network. If the problem persists,
please contact your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in the specified
domain. Otherwise, this computer sets up the secure session to any domain controller
in the specified domain.
Error: (08/06/2012 09:56:55 AM) (Source: Service Control Manager) (User: )
Description: The Windows Defender service terminated with the following error:
%%126
Error: (08/06/2012 09:55:59 AM) (Source: Service Control Manager) (User: )
Description: The Windows Defender service terminated with the following error:
%%126
Error: (08/06/2012 09:55:53 AM) (Source: Service Control Manager) (User: )
Description: The Windows Defender service terminated with the following error:
%%126
Microsoft Office Sessions:
=========================
Error: (08/20/2012 10:25:16 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHFE7A.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:25:15 AM) (Source: Symantec AntiVirus)(User: )
Description: Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHFE7A.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:25:15 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHFE7A.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:54 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF8D2.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:53 AM) (Source: Symantec AntiVirus)(User: )
Description: Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF8D2.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:53 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF8D2.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:30 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF855.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:29 AM) (Source: Symantec AntiVirus)(User: )
Description: Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF855.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:29 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF855.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Error: (08/20/2012 10:24:08 AM) (Source: Symantec AntiVirus)(User: )
Description: Security Risk Found!Risk: Trojan.Gen.2 in File: C:\Users\bruce.CSASTAFF1\AppData\Local\temp\DWHF565.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
=========================== Installed Programs ============================
AccelerometerP11 (Version: 2.00.00.12)
Adobe Acrobat X Pro - English, Français, Deutsch (Version: 10.1.4)
Adobe Download Manager (Version: 1.6.2.102)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.271)
Adobe Reader X (10.1.4) (Version: 10.1.4)
Adobe Shockwave Player 11.5 (Version: 11.5.9.620)
BioAPI Framework (Version: 1.0.2)
Cisco EAP-FAST Module (Version: 2.2.14)
Cisco LEAP Module (Version: 1.0.19)
Cisco PEAP Module (Version: 1.1.6)
Custom (Version: 12.34.56.789)
CyberLink PowerDVD 9.5 (Version: 9.5.1.3225)
D3DX10 (Version: 15.4.2368.0902)
Default (Version: 11.01.006)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell ControlVault Host Components Installer 64 bit (Version: 2.0.20.159)
Dell Data Protection | Access (Version: 01.01.00.085)
Dell Data Protection | Access (Version: 2.0.00000.085)
Dell Data Protection | Access | Drivers (Version: 1.00.011)
Dell Data Protection | Access | Middleware (Version: 1.00.005)
Dell Edoc Viewer (Version: 1.0.0)
Dell System Manager (Version: 1.5.00000)
Dell Touchpad (Version: 7.1107.101.205)
DellAccess (Version: 01.01.00.053)
Descriptions Now 5.13 (Version: 5.13.0003)
DirectX 9 Runtime (Version: 1.00.0000)
doPDF 7.2 printer
Dropbox (Version: 1.4.7)
DW WLAN Card Utility (Version: 5.60.48.35)
EMBASSY Security Center (Version: 04.03.00.067)
eReg (Version: 1.20.138.34)
ESET Online Scanner v3
Gemalto (Version: 01.64.01.0010)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.4.3203.136)
Google Update Helper (Version: 1.3.21.115)
GoToMeeting 5.1.0.880 (Version: 5.1.0.880)
HP Software Update (Version: 2.0.37.20031205)
HR Comply
HumanConcepts OrgPlus 4.0
HumanConcepts OrgPlus 6 (Version: 6.0.0)
Intel® Graphics Media Accelerator Driver (Version: 8.15.10.2182)
Intel® Network Connections 15.2.89.0 (Version: 15.2.89.0)
Intel® Rapid Storage Technology (Version: 9.6.0.1014)
Java Auto Updater (Version: 2.0.5.1)
Java 6 Update 23 (64-bit) (Version: 6.0.230)
Java 6 Update 26 (Version: 6.0.260)
Junk Mail filter update (Version: 15.4.3502.0922)
Lawson Interface Desktop (200805) 9.0.1.2 (Version: 9.0.1.2)
LiveUpdate 3.2 (Symantec Corporation) (Version: 3.2.0.26)
Logitech SetPoint 6.22 (Version: 6.22.24)
Malwarebytes Anti-Malware version 1.62.0.1300 (Version: 1.62.0.1300)
Mesh Runtime (Version: 15.4.5722.2)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Lync 2010 (Version: 4.0.7577.4103)
Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Visio 2010 (Version: 14.0.6029.1000)
Microsoft Office Visio MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Online Services Sign-in Assistant (Version: 7.250.4287.0)
Microsoft Silverlight (Version: 4.1.10329.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visio 2010 Service Pack 1 (SP1)
Microsoft Visio Premium 2010 (Version: 14.0.6029.1000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
NTRU TCG Software Stack (Version: 2.1.34)
PC-CCID (Version: 2.0.0)
People Manager 3.04 (Version: 3.04)
Performance Now 4.01 (Version: 4.01)
Performance Now 401 (Version: 4.01.0002)
PhotoShowExpress (Version: 2.0.063)
Photosmart 140,240,7200,7600,7700,7900 Series (Version: 2.0)
Policies Now 6.01 (Version: 6.01)
Policies Now 6.01 (Version: 6.01.0002 - (setup build 0002))
Preboot Manager (Version: 03.03.00.049)
Private Information Manager (Version: 07.01.00.007)
PSShortcutsP (Version: 1.01.0000)
PSUsage (Version: 1.30.0000)
QFolder (Version: 1.00.0000)
RBVirtualFolder64Inst (Version: 1.00.0000)
Reader 2.1 (Version: 2.1.2.1143)
Remote Backup (Version: 11.01.006)
Roxio Activation Module (Version: 1.0)
Roxio BackOnTrack (Version: 1.3.3)
Roxio Burn (Version: 1.8)
Roxio Creator Starter (Version: 1.0.439)
Roxio Creator Starter (Version: 12.1.77.0)
Roxio Creator Starter (Version: 5.0.0)
Roxio Express Labeler 3 (Version: 3.2.2)
Roxio File Backup (Version: 1.3.2)
Sonic CinePlayer Decoder Pack (Version: 4.3.0)
SonicWALL SSL-VPN NetExtender (Version: 4.0.134)
SPBA 5.9 (Version: 5.9.4.6686)
Symantec AntiVirus Win64 (Version: 10.2.298.0)
Trusted Drive Manager (Version: 4.0.0.512)
UltraVNC 1.0.8.2 (Version: 1.0.8.2)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Upek Touchchip Fingerprint Reader (Version: 1.2.004)
Wave Infrastructure Installer (Version: 07.66.40.0008)
Wave Support Software Installer (Version: 05.13.00.014)
Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6) (Version: 09/11/2009 1.0.1.6)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
========================= Memory info: ===================================
Percentage of memory in use: 55%
Total physical RAM: 3957.83 MB
Available physical RAM: 1748.17 MB
Total Pagefile: 7913.85 MB
Available Pagefile: 4387.45 MB
Total Virtual: 4095.88 MB
Available Virtual: 3970.51 MB
========================= Partitions: =====================================
1 Drive c: (OS) (Fixed) (Total:230.11 GB) (Free:158.39 GB) NTFS
2 Drive d: (READER) (Fixed) (Total:2 GB) (Free:1.55 GB) NTFS
5 Drive g: (SILVER) (Removable) (Total:3.72 GB) (Free:3.7 GB) FAT32
========================= Users: ========================================
User accounts for \\CLARK-B
admin Administrator bruce
back Guest
**** End of log ****
FSS
Farbar Service Scanner Version: 06-08-2012
Ran by BRUCE (administrator) on 20-08-2012 at 13:59:42
Running from "G:\Second Set\3"
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
ADWCLEANER
# AdwCleaner v1.801 - Logfile created 08/20/2012 at 14:00:56
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : BRUCE - CLARK-B
# Boot Mode : Normal
# Running from : G:\Second Set\4\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
***** [Registry] *****
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.7601.17514
[OK] Registry is clean.
*************************
AdwCleaner[S1].txt - [624 octets] - [20/08/2012 14:00:56]
########## EOF - C:\AdwCleaner[S1].txt - [751 octets] ##########
# AdwCleaner v1.801 - Logfile created 08/20/2012 at 14:00:56
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : BRUCE - CLARK-B
# Boot Mode : Normal
# Running from : G:\Second Set\4\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
***** [Registry] *****
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.7601.17514
[OK] Registry is clean.
*************************
AdwCleaner[S1].txt - [624 octets] - [20/08/2012 14:00:56]
########## EOF - C:\AdwCleaner[S1].txt - [751 octets] ##########
RKILL
Rkill 2.2.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 08/20/2012 02:06:15 PM in x64 mode.
Windows Version: Windows 7
Checking for Windows services to stop.
* No malware services found to stop.
Checking for processes to terminate.
* C:\Windows\SysWOW64\hphmon05.exe (PID: 2292) [WD-HEUR]
1 proccess terminated!
Checking Registry for malware related settings.
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKLM\Software\Classes\.com "@" has been changed to ComFile!
* HKLM\Software\Classes\.com "@" was reset to comfile!
Performing miscellaneous checks.
* No issues found.
Checking Windows Service Integrity:
* atapi => \SystemRoot\system32\drivers\atapi.sys [Incorrect ImagePath]
* pcmcia => system32\DRIVERS\pcmcia.sys [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Program finished at: 08/20/2012 02:06:51 PM
Execution time: 0 hours(s), 0 minute(s), and 36 seconds(s)