Hi Gringo,
Thanks for your response. I have generated all logs and have them written below. I also would like to inform you that when I attempted to use the RookitUnhooker, it came up with a box and this message "sorry but unhandled exception has occurred. Program will be terminated. Exception code: 0xC0000005. Instruction address: 0x00402EAA. Attempt to read at address: 0xFFFFFFFF - Error Log Generated, please report to developers". However - I'm not sure where that log can be found? Anyway, here are the other logs as requested:
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 02-Jul-11 5:27:31 PM
System Uptime: 29-Aug-11 12:09:01 PM (2 hours ago)
.
Motherboard: Acer | | Aspire 5740
Processor: Intel® Core i3 CPU M 330 @ 2.13GHz | CPU 1 | 917/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 432.024 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP114: 25-Aug-11 10:47:42 AM - Installed 7-Zip 9.20 (x64 edition)
RP115: 25-Aug-11 11:07:54 AM - Removed 7-Zip 9.20 (x64 edition)
RP116: 25-Aug-11 4:42:35 PM - Installed HiJackThis
RP117: 26-Aug-11 11:18:40 AM - Revo Uninstaller's restore point - Evernote v. 4.4.2
RP118: 26-Aug-11 5:03:05 PM - Installed Eraser 6.0.8.2273
.
==== Installed Programs ======================
.
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 9
Adobe Shockwave Player 11.6
Atheros Client Installation Program
D3DX10
Definition update for Microsoft Office 2010 (KB982726)
Dropbox
Elements 9 Organizer
Elements STI Installer
FileHippo.com Update Checker
Foxit Reader 5.0
Google Update Helper
HiJackThis
Intel® Control Center
Intel® Management Engine Components
Intel® Processor Graphics
Intel® Rapid Storage Technology
Junk Mail filter update
KeyScrambler
Malwarebytes' Anti-Malware version 1.51.1.1800
Mesh Runtime
Messenger Companion
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_CRT_x86
Mozilla Firefox 6.0 (x86 en-US)
MSVCRT
MSVCRT_amd64
Norton 360
Norton DNS
Realtek High Definition Audio Driver
Screenpresso
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Sophos Anti-Rootkit 1.5.20
swMSM
System Requirements Lab for Intel
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2010 (KB2494150)
VLC media player 1.1.11
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Yahoo! Detect
.
==== Event Viewer Messages From Past Week ========
.
29-Aug-11 12:11:54 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the file specified.
29-Aug-11 12:10:20 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: An instance of the service is already running.
29-Aug-11 12:09:50 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
29-Aug-11 12:09:50 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
25-Aug-11 4:59:05 PM, Error: Service Control Manager [7000] - The MEMSWEEP2 service failed to start due to the following error: This driver has been blocked from loading
25-Aug-11 4:59:05 PM, Error: Application Popup [1060] - \??\C:\Windows\system32\90E.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
25-Aug-11 4:15:46 PM, Error: Application Popup [1060] - \??\C:\Windows\system32\3912.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
.
==== End Of File ===========================
DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by admin at 14:29:02 on 2011-08-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1780.485 [GMT 10:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Norton DNS\NortonDNSSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Users\admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\PROGRA~2\NORTON~3\NORTON~1.EXE
C:\Program Files\PeerBlock\peerblock.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\splwow64.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\admin\Downloads\Defogger.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page =
https://www.startpage.com/
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO: PrivateSkyIEPlugIn: {88951971-a6da-4a34-8f85-0b8acabead07} - C:\Program Files (x86)\CertiVox Ltd\PrivateSky Internet Explorer Connector\adxloader.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: PrivateSky Internet Explorer ToolBar: {5cd1d50b-04f6-42d1-8f19-d55a23960fa7} - C:\Program Files (x86)\CertiVox Ltd\PrivateSky Internet Explorer Connector\adxloader.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\coIEPlg.dll
TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
StartupFolder: C:\Users\admin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
mPolicies-system: UseOEMBackground = 0 (0x0)
mPolicies-system: DisplayLastLogonInfo = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{FB4FD47B-1A9D-4208-A4FA-ED58FCC00B70} : NameServer = 198.153.192.1,198.153.194.1
TCP: Interfaces\{FB4FD47B-1A9D-4208-A4FA-ED58FCC00B70} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{FB4FD47B-1A9D-4208-A4FA-ED58FCC00B70}\14D2455616D6 : DhcpNameServer = 203.134.12.90 203.134.102.90
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-X64: 0x1 - No File
BHO-X64: KeyScramblerBHO Class: {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
BHO-X64: QFX Software KeyScrambler - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: PrivateSkyIEPlugIn: {88951971-a6da-4a34-8f85-0b8acabead07} - C:\Program Files (x86)\CertiVox Ltd\PrivateSky Internet Explorer Connector\adxloader.dll
BHO-X64: 0x1 - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: PrivateSky Internet Explorer ToolBar: {5cd1d50b-04f6-42d1-8f19-d55a23960fa7} - C:\Program Files (x86)\CertiVox Ltd\PrivateSky Internet Explorer Connector\adxloader.dll
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\coIEPlg.dll
TB-X64: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\314pdq55.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=llya694le36z&scc=1<mpl=default<mplcache=2&from=login|https://www.facebook.com/
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110812.001\BHDrvx64.sys [2011-8-12 1151096]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110826.030\IDSviA64.sys [2011-8-27 488568]
R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [?]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\drivers\N360x64\0501000.01D\SYMNETS.SYS --> C:\Windows\system32\drivers\N360x64\0501000.01D\SYMNETS.SYS [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [2010-9-30 169408]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-7-3 13336]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [2011-8-20 130008]
R2 Norton DNS;Norton DNS;C:\Program Files (x86)\Norton DNS\NortonDNSSvc.exe [2010-10-14 97664]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-7-13 2320920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-8-20 136824]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 KeyScrambler;KeyScrambler;C:\Windows\system32\drivers\keyscrambler.sys --> C:\Windows\system32\drivers\keyscrambler.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 pbfilter;pbfilter;C:\Program Files\PeerBlock\pbfilter.sys [2011-7-30 24176]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2011-8-28 156288]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\90E.tmp --> C:\Windows\system32\90E.tmp [?]
S3 tapoas;TAP-Win32 Adapter OAS;C:\Windows\system32\DRIVERS\tapoas.sys --> C:\Windows\system32\DRIVERS\tapoas.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-08-28 14:33:10 -------- d-----w- C:\Program Files\Defraggler
2011-08-28 13:47:19 3126944 ----a-w- C:\Users\admin\FP_AX_CAB_INSTALLER.exe
2011-08-27 15:24:31 -------- d-----r- C:\Sandbox
2011-08-27 13:07:33 -------- d-----w- C:\Users\admin\AppData\Roaming\Foxit Software
2011-08-27 04:47:18 -------- d-----w- C:\Users\admin\AppData\Local\{BC85352E-3221-4462-91D6-3A9054D936C0}
2011-08-27 04:47:03 -------- d-----w- C:\Users\admin\AppData\Local\{EF88101A-5B9E-4B52-8486-74D09C225EBC}
2011-08-26 14:02:44 -------- d-----w- C:\Users\admin\AppData\Local\{9A655EB0-B3AA-406C-8706-EB8FD9E62706}
2011-08-26 14:02:31 -------- d-----w- C:\Users\admin\AppData\Local\{ADC24C75-DDC4-45F3-90CB-FDBBC8CDC6D8}
2011-08-26 14:02:30 -------- d-----w- C:\Users\admin\AppData\Local\{EA362B73-306B-4EBF-A42C-D252D0FBD0F2}
2011-08-26 07:04:11 -------- d-----w- C:\Program Files\Eraser
2011-08-26 02:40:54 -------- d-----w- C:\Program Files\Sandboxie
2011-08-26 00:55:13 -------- d-----w- C:\Program Files (x86)\VS Revo Group
2011-08-25 12:55:32 -------- d-----w- C:\Program Files (x86)\FileHippo.com
2011-08-25 06:43:55 388096 ----a-r- C:\Users\admin\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-25 06:43:55 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-08-25 06:18:43 6144 ------w- C:\Windows\System32\90E.tmp
2011-08-25 06:15:39 6144 ------w- C:\Windows\System32\3912.tmp
2011-08-25 06:15:08 -------- d-----w- C:\Program Files (x86)\Sophos
2011-08-24 10:50:13 -------- d-----w- C:\Users\admin\AppData\Local\Opera
2011-08-24 00:27:36 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-24 00:27:36 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-23 12:16:58 -------- d-----r- C:\Users\admin\Dropbox
2011-08-23 12:12:47 -------- d-----w- C:\Users\admin\AppData\Roaming\Dropbox
2011-08-23 12:01:14 -------- d-----w- C:\Users\admin\AppData\Local\{A7CE9A93-6F2C-413C-BF5E-D702ECFD20B1}
2011-08-23 12:01:02 -------- d-----w- C:\Users\admin\AppData\Local\{49D62A3A-51B1-49F9-837A-D7FD62C0FAA5}
2011-08-23 11:58:38 -------- d-----w- C:\Windows\en
2011-08-23 11:56:41 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-08-23 11:54:04 48488 ----a-w- C:\Windows\System32\drivers\fssfltr.sys
2011-08-23 10:12:22 -------- d-----w- C:\GrampsPortable
2011-08-22 12:42:26 -------- d-----w- C:\Program Files (x86)\Norton DNS
2011-08-22 07:05:54 -------- d-----w- C:\Program Files\Speccy
2011-08-22 05:01:16 -------- d-----w- C:\Users\admin\AppData\Local\Secunia PSI
2011-08-22 05:01:07 -------- d-----w- C:\Program Files (x86)\Secunia
2011-08-20 10:24:16 -------- d-----w- C:\Program Files\Axantum
2011-08-20 06:01:00 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2011-08-20 06:00:59 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2011-08-20 06:00:59 -------- d-----w- C:\Program Files\Symantec
2011-08-20 06:00:59 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2011-08-20 06:00:46 912504 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\SymEFA64.sys
2011-08-20 06:00:46 744568 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\srtsp64.sys
2011-08-20 06:00:46 450680 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\SymDS64.sys
2011-08-20 06:00:46 40568 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\srtspx64.sys
2011-08-20 06:00:46 386168 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\symnets.sys
2011-08-20 06:00:46 171128 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\Ironx64.sys
2011-08-20 06:00:37 -------- d-----w- C:\Windows\System32\drivers\N360x64\0501000.01D
2011-08-20 06:00:37 -------- d-----w- C:\Windows\System32\drivers\N360x64
2011-08-20 06:00:36 -------- d-----w- C:\Program Files (x86)\Norton 360
2011-08-20 05:29:46 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8C60AACE-F350-4A59-BD81-0D56F0CEDEB4}\mpengine.dll
2011-08-20 05:29:05 125872 ----a-w- C:\Windows\System32\GEARAspi64.dll
2011-08-20 05:29:05 106928 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2011-08-20 04:50:08 -------- d-----w- C:\Users\admin\AppData\Local\{57C6BA92-BA06-45D9-8B06-C076205996C5}
2011-08-20 04:49:56 -------- d-----w- C:\Users\admin\AppData\Local\{2AE30E37-B3D9-4A40-B65D-BAE576707D0B}
2011-08-20 02:14:00 -------- d-----w- C:\Program Files (x86)\Foxit Software
2011-08-19 05:59:33 -------- d-----w- C:\Users\admin\AppData\Local\Tific
2011-08-18 13:05:57 273088 ----a-w- C:\Windows\System32\drivers\keyscrambler.sys
2011-08-18 13:05:56 -------- d-----w- C:\Program Files (x86)\KeyScrambler
2011-08-16 09:59:31 6144 ------w- C:\Windows\System32\5FEC.tmp
2011-08-16 09:56:28 6144 ------w- C:\Windows\System32\9323.tmp
2011-08-16 05:07:24 -------- d-----w- C:\Users\admin\AppData\Local\Solid State Networks
2011-08-15 13:04:15 -------- d-----w- C:\Windows\Logon Personalization
2011-08-15 12:48:34 -------- d-----w- C:\Program Files\Common Files\Intel
2011-08-15 12:48:32 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2011-08-15 12:39:50 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2011-08-11 05:41:55 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-08-11 00:53:33 -------- d-----w- C:\Users\admin\AppData\Local\{E1A876B5-0CF8-4063-AD70-F3608AE09B3F}
2011-08-11 00:53:20 -------- d-----w- C:\Users\admin\AppData\Local\{D8B355F6-8340-4809-8715-211DEA129341}
2011-08-10 03:39:14 -------- d-----w- C:\Users\admin\AppData\Local\{C0A35E24-D4F3-47F2-AC7D-AE2C8536AAB8}
2011-08-10 03:39:02 -------- d-----w- C:\Users\admin\AppData\Local\{26BA24C2-5807-4C60-92F9-23E0668165B7}
2011-08-09 15:38:30 -------- d-----w- C:\Users\admin\AppData\Local\{099B33D9-EB96-40AD-8B0A-9F9DDC2DE7C8}
2011-08-09 15:38:16 -------- d-----w- C:\Users\admin\AppData\Local\{168FB851-6B66-43EE-AF61-F5FAE26375E0}
2011-08-09 14:16:48 -------- d-----w- C:\Users\admin\AppData\Roaming\QuickScan
2011-08-09 13:15:31 -------- d-----w- C:\Users\admin\AppData\Roaming\KC Softwares
2011-08-09 01:00:42 -------- d-----w- C:\Users\admin\AppData\Local\{5AAF2874-DB99-44AD-8159-D276717AC031}
2011-08-09 01:00:31 -------- d-----w- C:\Users\admin\AppData\Local\{DEFB5808-391F-499E-B3A3-49578B18D864}
2011-08-08 13:01:30 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-08-08 13:01:25 -------- d-----w- C:\Program Files (x86)\MBAM
2011-08-08 09:11:47 -------- d-----w- C:\Users\admin\AppData\Local\{53FDEBC6-B72D-4308-B54E-4ABD2DC6055C}
2011-08-08 09:11:35 -------- d-----w- C:\Users\admin\AppData\Local\{25EF01AD-FB23-486C-990D-6CCC344E663A}
2011-08-07 00:36:21 -------- d-----w- C:\Users\admin\AppData\Local\{4D7BE3AA-BFD5-4E21-B6A5-B925931651A6}
2011-08-07 00:36:11 -------- d-----w- C:\Users\admin\AppData\Local\{5687E15B-719A-4128-8520-99977E31FE4C}
2011-08-06 12:35:42 -------- d-----w- C:\Users\admin\AppData\Local\{B4A9126A-30B5-4978-A56E-8399C498DFFC}
2011-08-06 12:35:29 -------- d-----w- C:\Users\admin\AppData\Local\{10CC49FF-91E0-4F69-9A24-D04AE922FD30}
2011-08-06 00:35:15 -------- d-----w- C:\Users\admin\AppData\Local\{69558A12-C454-46AA-A685-1C55210E2EED}
2011-08-06 00:35:02 -------- d-----w- C:\Users\admin\AppData\Local\{34E17863-4122-420E-8A70-7E4C162243F7}
2011-08-05 12:34:32 -------- d-----w- C:\Users\admin\AppData\Local\{BA31625A-FE31-4B87-A614-71FC4385C173}
2011-08-05 12:34:21 -------- d-----w- C:\Users\admin\AppData\Local\{2D04DD50-7D21-43E3-A193-44235F6B3C2F}
2011-08-05 00:33:45 -------- d-----w- C:\Users\admin\AppData\Local\{11C36487-0F84-49E2-9ECE-763313118463}
2011-08-05 00:33:30 -------- d-----w- C:\Users\admin\AppData\Local\{8F1BE6AF-D266-433E-B993-E0E2D40B85A0}
2011-08-04 12:33:04 -------- d-----w- C:\Users\admin\AppData\Local\{8F8DE338-4961-4672-81DB-C95916F09B2A}
2011-08-04 00:32:52 -------- d-----w- C:\Users\admin\AppData\Local\{CBB6A7FF-8BC1-43E6-B302-88AE1C966CC1}
2011-08-03 12:59:46 -------- d-----w- C:\Users\admin\.kde
2011-08-03 12:32:25 -------- d-----w- C:\Users\admin\AppData\Local\{D45E26CF-4E68-47E7-B5B8-34DF7B82F218}
2011-08-03 00:31:59 -------- d-----w- C:\Users\admin\AppData\Local\{3C4AA2C0-6109-4AF7-870D-B1485443F777}
2011-08-02 09:55:01 -------- d-----w- C:\Users\admin\AppData\Local\{753CC073-2A60-4017-8729-FF65254A5136}
2011-08-01 21:54:35 -------- d-----w- C:\Users\admin\AppData\Local\{68352CC6-F32D-4934-8888-9A1A7EA8E311}
2011-08-01 21:42:57 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2011-08-01 08:31:47 -------- d-----w- C:\Users\admin\AppData\Roaming\SteelBytes
2011-08-01 03:54:59 -------- d-----w- C:\Users\admin\AppData\Local\{5685D143-C66D-4A01-9F39-B289CA02C7E9}
2011-08-01 03:54:59 -------- d-----w- C:\Users\admin\AppData\Local\{133C517A-26B6-4ACF-9B66-F545C39A4EC8}
2011-07-31 15:58:24 -------- d-----w- C:\Users\admin\AppData\Local\CrashDumps
2011-07-31 15:55:34 -------- d-----w- C:\Users\admin\AppData\Roaming\Mail
2011-07-31 15:55:13 -------- d-----w- C:\Users\admin\AppData\Roaming\Claws-mail
2011-07-31 14:28:21 -------- d-----w- C:\Users\admin\AppData\Local\{53979988-C554-46DD-9203-6701BDBD4692}
2011-07-31 13:59:14 -------- d-----w- C:\Users\admin\AppData\Local\GNU
2011-07-31 13:57:09 -------- d-----w- C:\Users\admin\AppData\Roaming\gnupg
2011-07-31 13:57:02 -------- d-----w- C:\ProgramData\GNU
2011-07-31 10:21:42 -------- d-----w- C:\Users\admin\AppData\Local\Diagnostics
2011-07-31 02:27:56 -------- d-----w- C:\Users\admin\AppData\Local\{6271DC01-2BF5-4E20-A604-133E6638DCE5}
.
==================== Find3M ====================
.
2011-08-28 13:52:22 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-09 13:41:17 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-07-06 09:52:42 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-07-02 23:59:56 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2011-07-02 09:04:58 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-07-02 09:04:57 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 08:56:50 17200 ----a-w- C:\Windows\System32\nitrolocalui2.dll
2011-06-21 08:56:48 28976 ----a-w- C:\Windows\System32\nitrolocalmon2.dll
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-06-10 21:46:04 107280 ----a-w- C:\Windows\System32\drivers\bckd.sys
.
============= FINISH: 14:30:23.83 ===============