I would attach a GMER but my os is W7 64bit
DDS
Quote
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26
Run by Lewis Kwong at 1:54:12 on 2012-02-02
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8190.5559 [GMT 13:00]
.
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
C:\Windows\system32\inetsrv\inetinfo.exe
C:\Windows\system32\mqsvc.exe
c:\xampp\mysql\bin\mysqld.exe
C:\Windows\SysWoW64\svchost.exe
C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Program Files (x86)\Realtek\RTL8185 Wireless LAN Utility\RtlService.exe
C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe
C:\Program Files (x86)\Realtek\RTL8185 Wireless LAN Utility\RtWlan.exe
C:\Program Files (x86)\PC Tools Security\pctsSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\PC Tools Security\pctsGui.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Smith Micro\StuffIt 2010\ArcNameService.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\mqtgsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe
C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe
C:\Users\Lewis Kwong\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe
C:\Windows\splwow64.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\SysWoW64\svchost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = local;*.local;127.0.0.1:9421;
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Lewis Kwong\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: TextAloud: {f053c368-5458-45b2-9b4d-d8914bdddbff} - C:\PROGRA~2\TEXTAL~1\TAForIE.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
uRun: [FlashGet 3] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe" -minimize
uRun: [ManyCam] "C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe"
uRun: [Octoshape Streaming Services] "C:\Users\Lewis Kwong\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
uRun: [Gadwin PrintScreen Pro] "C:\Program Files (x86)\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" /nosplash
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
mRun: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun: [ISTray] "C:\Program Files (x86)\PC Tools Security\pctsGui.exe" /hideGUI
StartupFolder: C:\Users\LEWISK~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
StartupFolder: C:\Users\LEWISK~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ROLLER~1.LNK - C:\Users\Lewis Kwong\AppData\Local\Temp\{46C303E0-9B9A-4E6B-8D82-ABBF089CB687}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: SoftwareSASGeneration = 1 (0x1)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
LSP: C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: kuaiche.com\software
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {3D3BF1F8-9696-4A5E-B4F1-49101C997B70} - hxxp://www.freetalker.com/VaxSIPUserAgentCAB.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{48C33E8C-A3D2-46C7-A216-35305E6FEBBF} : DhcpNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{51B25B49-E072-46CC-8F56-9385DB1C4AEC} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{BA30575C-5282-4BF3-AC11-C73441C94515} : DhcpNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~4\Office12\GRA32A~1.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Lewis Kwong\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
BHO-X64: FlashGetBHO - No File
BHO-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: TextAloud: {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~2\TEXTAL~1\TAForIE.dll
TB-X64: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Diamondback] C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
mRun-x64: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
mRun-x64: [ISTray] "C:\Program Files (x86)\PC Tools Security\pctsGui.exe" /hideGUI
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Lewis Kwong\AppData\Roaming\Mozilla\Firefox\Profiles\8eb6968l.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.nz/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.ftp - 125.164.121.103
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 125.164.121.103
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - 125.164.121.103
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 125.164.121.103
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 125.164.121.103
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: C:\Users\Lewis Kwong\AppData\Roaming\Mozilla\Firefox\Profiles\8eb6968l.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashgetXpi.dll
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Lewis Kwong\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\Lewis Kwong\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Lewis Kwong\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Users\Lewis Kwong\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;C:\Windows\system32\drivers\PCTCore64.sys --> C:\Windows\system32\drivers\PCTCore64.sys [?]
R0 pctDS;PC Tools Data Store;C:\Windows\system32\drivers\pctDS64.sys --> C:\Windows\system32\drivers\pctDS64.sys [?]
R0 pctEFA;PC Tools Extended File Attributes;C:\Windows\system32\drivers\pctEFA64.sys --> C:\Windows\system32\drivers\pctEFA64.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-7-19 140672]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-1-25 136360]
R2 AntiVirService;Avira AntiVir Guard;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-1-25 269480]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 cpuz133;cpuz133;\??\C:\Windows\system32\drivers\cpuz133_x64.sys --> C:\Windows\system32\drivers\cpuz133_x64.sys [?]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-12-17 8704]
R2 Realtek8185;Realtek8185;C:\Program Files (x86)\Realtek\RTL8185 Wireless LAN Utility\RtlService.exe [2010-3-11 36864]
R2 sdAuxService;PC Tools Auxiliary Service;C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe [2012-2-1 366840]
R2 sdCoreService;PC Tools Security Service;C:\Program Files (x86)\PC Tools Security\pctsSvc.exe [2012-2-1 1150936]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-15 2228008]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys --> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2010-7-4 139880]
R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-9-26 4924336]
S3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys --> C:\Windows\system32\DRIVERS\revoflt.sys [?]
S3 RTLE8023x64;Realtek 10/100/1000 PCI-E NIC Family NDIS XP(x64) Driver;C:\Windows\system32\DRIVERS\Rtenic64.sys --> C:\Windows\system32\DRIVERS\Rtenic64.sys [?]
S3 sftfs;sftfs;C:\Program Files (x86)\Microsoft Application Virtualization Client\drivers\SftFSlh.sys [2009-9-23 712536]
S3 sftplay;sftplay;C:\Program Files (x86)\Microsoft Application Virtualization Client\drivers\sftplaylh.sys [2009-9-23 261480]
S3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
S3 sftvol;sftvol;C:\Program Files (x86)\Microsoft Application Virtualization Client\drivers\SftVollh.sys [2009-9-23 17752]
S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-9-23 203608]
S4 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2009-9-26 819600]
S4 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-9-23 447848]
.
=============== Created Last 30 ================
.
2012-02-01 12:34:14 6832 ----a-w- C:\Windows\System32\PerfStringBackup.TMP
2012-02-01 12:33:14 838 ----a-w- C:\ProgramData\gjuobaa.tmp
2012-02-01 12:32:34 793 ----a-w- C:\ProgramData\kjuobaa.tmp
2012-02-01 12:32:29 871 ----a-w- C:\ProgramData\jjuobaa.tmp
2012-02-01 12:32:23 841 ----a-w- C:\ProgramData\ijuobaa.tmp
2012-02-01 12:32:19 807 ----a-w- C:\ProgramData\hjuobaa.tmp
2012-02-01 12:24:27 -------- d-----w- C:\_OTM
2012-02-01 12:19:07 862 ----a-w- C:\ProgramData\ieaqbaa.tmp
2012-02-01 12:17:48 -------- d-----w- C:\Program Files (x86)\ESET
2012-02-01 12:02:38 822 ----a-w- C:\ProgramData\leaqbaa.tmp
2012-02-01 11:55:04 802 ----a-w- C:\ProgramData\keaqbaa.tmp
2012-02-01 11:39:20 857 ----a-w- C:\ProgramData\jeaqbaa.tmp
2012-02-01 11:22:17 839 ----a-w- C:\ProgramData\meaqbaa.tmp
2012-02-01 11:13:30 -------- d-----w- C:\$RECYCLE.BIN
2012-02-01 10:24:44 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{83765BFB-EAA6-4A4C-9879-CE84E92891ED}
2012-02-01 09:40:33 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\TSVNCache
2012-02-01 09:20:40 816016 ----a-w- C:\Windows\System32\drivers\pctEFA64.sys
2012-02-01 09:20:40 452872 ----a-w- C:\Windows\System32\drivers\pctDS64.sys
2012-02-01 09:20:32 331368 ----a-w- C:\Windows\System32\drivers\pctgntdi64.sys
2012-02-01 09:20:32 136168 ----a-w- C:\Windows\System32\drivers\pctwfpfilter64.sys
2012-02-01 09:20:20 257232 ----a-w- C:\Windows\System32\drivers\PCTCore64.sys
2012-02-01 09:20:10 92896 ----a-w- C:\Windows\System32\drivers\pctplsg64.sys
2012-02-01 09:19:58 -------- d-----w- C:\Users\Lewis Kwong\AppData\Roaming\PC Tools
2012-02-01 09:19:58 -------- d-----w- C:\ProgramData\PC Tools
2012-02-01 09:19:58 -------- d-----w- C:\Program Files (x86)\PC Tools Security
2012-02-01 09:19:58 -------- d-----w- C:\Program Files (x86)\Common Files\PC Tools
2012-02-01 07:14:35 73216 ----a-w- C:\Windows\SysWow64\osktray.dll
2012-01-31 09:57:17 -------- d-----w- C:\ProgramData\Media Center Programs
2012-01-31 09:57:13 310984 ----a-w- C:\Windows\System32\drivers\atksgt.sys
2012-01-31 09:57:12 42696 ----a-w- C:\Windows\System32\drivers\lirsgt.sys
2012-01-31 06:01:50 -------- d-----w- C:\Program Files (x86)\Atari
2012-01-31 06:01:18 -------- d-----w- C:\Users\Lewis Kwong\AppData\Roaming\Atari
2012-01-31 06:01:00 692224 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2012-01-31 06:01:00 57344 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2012-01-31 06:01:00 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2012-01-31 06:01:00 282756 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2012-01-31 06:01:00 237568 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2012-01-31 06:01:00 163972 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2012-01-31 06:01:00 155648 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2012-01-31 01:25:56 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{A4953A0A-4DCE-4FEE-A7DE-C59D9C16196D}
2012-01-31 00:10:35 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{FB766D93-124D-4DEF-9484-1AAEEA0CFAA1}
2012-01-30 12:10:35 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{A7852753-187C-4AAF-8A70-5CD12569EC48}
2012-01-30 00:10:35 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{1E7BBB8B-DDAD-469E-9AA4-EAEF6B8E37C5}
2012-01-29 12:10:36 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{16740E53-9E2E-45A0-9F1B-47478F73870C}
2012-01-29 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{057A0FAC-CB80-4DC3-AC07-6766C291951B}
2012-01-28 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{A07EDDC2-060B-4911-A522-2AB549736479}
2012-01-28 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{4AE50A9F-1604-46C9-8E1B-74F9B866D4C1}
2012-01-27 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{079B7EEB-0344-4DBC-BF62-A9147AA1F960}
2012-01-27 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{4B22DFD5-1D0F-491F-9936-E2E16A3321E4}
2012-01-26 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{20FA1717-0671-465F-889B-9642B383829E}
2012-01-26 07:53:59 178800 ----a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll
2012-01-26 07:48:54 -------- d-----w- C:\Program Files (x86)\EA Sports
2012-01-26 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{44A1CD69-EFC7-47B4-B0C1-7B5B7381AD6E}
2012-01-25 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{370F35C3-99C8-424D-9783-4A97D071BE4B}
2012-01-25 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{7E4F7888-1D40-416A-A153-7A3C350EA8FD}
2012-01-24 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{8968583A-7C85-421D-A4C1-CCF7A6591744}
2012-01-24 01:33:03 -------- d-----w- C:\Users\Lewis Kwong\AppData\Roaming\.tribot
2012-01-24 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{5380DB49-7F5C-4646-AD5D-B297C0026A10}
2012-01-23 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{79BB4856-DE1D-4D44-B07A-07C110CF8A75}
2012-01-23 00:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{B34CC5C2-ACCF-461B-91DF-78AC472F72EB}
2012-01-22 12:11:06 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{D2D1E109-B3F9-47D9-8012-2462E4838F15}
2012-01-22 00:11:15 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{8F6BEB96-4F12-4332-8414-A992C7FF832C}
2012-01-21 12:11:15 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{21143511-92F6-474A-9DF1-6BED5B8D599D}
2012-01-21 00:11:15 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{A2B74A56-5E14-4AD4-B0B4-DABF756BD7FB}
2012-01-19 00:11:15 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{4A568E2C-3DC6-47A4-8A6F-041F01FE80A2}
2012-01-11 00:32:40 -------- d-----w- C:\Program Files (x86)\Wondershare
2012-01-11 00:29:09 -------- d-----w- C:\Program Files (x86)\PDF Password Remover v3.1
2012-01-11 00:21:53 -------- d-----w- C:\Program Files (x86)\PlotSoft
2012-01-10 22:12:46 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{DDFCB4D8-DD0D-4AAC-BCEA-BC1269350186}
2012-01-07 08:24:54 -------- d-----w- C:\Program Files (x86)\raidcall
2012-01-05 02:17:10 -------- d-----w- C:\Windyzone
2012-01-05 02:11:40 -------- d-----w- C:\Perfect World Entertainment
2012-01-04 22:31:16 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{6BE1468B-585C-4971-8679-F5E14EE8A572}
2012-01-04 05:40:40 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{9DD8BD68-F257-4948-8D1C-A503F8FEA877}
2012-01-03 23:24:57 -------- d-----w- C:\Users\Lewis Kwong\AppData\Roaming\Ubisoft
2012-01-03 17:41:03 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{C8E08538-5F8F-4318-B5F5-714290C97948}
2012-01-03 08:41:46 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{3595E372-27F1-4EF8-8A85-DD5CC593FC7C}
2012-01-03 05:48:58 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\Oblivion
2012-01-02 20:41:46 -------- d-----w- C:\Users\Lewis Kwong\AppData\Local\{FB9FC6A9-1F6B-4B94-A510-FC95F7ADB872}
.
==================== Find3M ====================
.
2011-12-10 02:24:08 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-02 10:45:29 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll
2011-12-02 09:48:00 279616 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2011-12-01 20:12:44 377344 ----a-w- C:\Windows\System32\hpb64.dll
2011-12-01 20:11:56 309760 ----a-w- C:\Windows\SysWow64\hpb.dll
2011-11-08 12:50:29 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
.
============= FINISH: 1:55:18.58 ===============
Attached File(s)
-
Attach.txt (15.14K)
Number of downloads: 0

Help
This topic is locked


Back to top











