Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Redirect and recovery from virus damage


  • This topic is locked This topic is locked
36 replies to this topic

#1 Smedlow

Smedlow

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 22 April 2011 - 11:49 PM

I am not a novice, and am comfortable using various tools and have generally been successful, but I am stumped this time.

A few weeks ago, I was installing a piece of software and Avira went off. Many things were installed in a short period of time. Since that time, I have scanned and removed many different malware, but still have the following problems:

1. Google Redirect
2. Can not start the Windows Security Service
3. Can not start Windows Defender Service
4. MS Security Essentials will not install

I have run the tools requested and am posting the logs from DDS. Gmer, after running through the running services and after scanning files for a while, slows to a crawl. I ran it for more than 24 hours without finishing. I restarted and tried it again and it is again using about 48-50% of the cpu and the mouse and keyboard and audio are jerky and slow. There are no other processes using anything to speak of except System Idle. I will leave it running and hopefully it will finish some day. Meanwhile, I am including the DDS.txt here and attaching the Attach.txt.

I have run Norman Malware Cleaner, Malwarebytes, TDSSkiller, Hitman Pro, Spybot S&D, ESET, and others, but am happy to do so again.

Thanks in advance for your help.


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Eldon DeKay at 16:01:40.66 on Fri 04/22/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\system32\IoctlSvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\CtHelper.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Avanquest\PowerDesk\PDExplo.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\UltraMon\UltraMonUiAcc.exe
C:\Users\Eldon DeKay\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
mLocal Page =
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No File
uRun: [Device Detector] DevDetect.exe -autorun
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {38E51477-DDB4-4aed-9D61-D0C193E10749} - {38E51477-DDB4-4aed-9D61-D0C193E10749} - c:\program files\drmremoval\YouTubeRipper.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {8645EBA2-9680-4A41-A4DC-F3A31E0F63AA} = 8.8.8.8,8.8.4.4
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\qualcomm\eudora\EuShlExt.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\eldond~1\appdata\roaming\mozilla\firefox\profiles\sml57h2q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/webhp?rls=ig
FF - component: c:\users\eldon dekay\appdata\roaming\idm\idmmzcc3\components\idmmzcc.dll
FF - component: c:\users\eldon dekay\appdata\roaming\mozilla\firefox\profiles\sml57h2q.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\opera\program\plugins\npdjvu.dll
FF - plugin: c:\program files\opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\opera\program\plugins\nprpjplug.dll
FF - plugin: c:\users\eldon dekay\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\eldon dekay\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\eldon dekay\appdata\roaming\mozilla\firefox\profiles\sml57h2q.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\users\eldon dekay\appdata\roaming\mozilla\plugins\npcoolirisplugin.dll
FF - plugin: c:\users\eldon dekay\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\eldon dekay\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R? Amazon Download Agent;Amazon Download Agent
R? ASPI;Advanced SCSI Programming Interface Driver
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? gupdate1c98f16c5d54266;Google Update Service (gupdate1c98f16c5d54266)
R? InnoMIO;InnoMIO
R? iTurns;iTurns
R? NDISKIO;NDISKIO
R? ntrconnect;ntrconnect
R? pbfilter;pbfilter
R? Revoflt;Revoflt
R? SandraAgentSrv;SiSoftware Deployment Agent Service
R? SBSDWSCService;SBSD Security Center Service
R? SMServer;SMServer
R? SwitchBoard;Adobe SwitchBoard
R? UPnPService;UPnPService
R? WatAdminSvc;Windows Activation Technologies Service
S? aswMonFlt;aswMonFlt
S? ctgame;Game Port
S? hotcore3;hc3ServiceName
S? IDMWFP;IDMWFP
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? SSPORT;SSPORT
S? StarWindServiceAE;StarWind AE Service
S? UltraMonUtility;UltraMon Utility Driver
S? WMDrive;WMDrive
.
=============== Created Last 30 ================
.
2011-04-22 18:57:57 801792 ----a-w- c:\windows\system32\FntCache.dll
2011-04-20 04:03:51 -------- d-----w- c:\users\eldon dekay\DoctorWeb
2011-04-19 07:21:49 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-19 07:21:46 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-19 07:21:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-19 06:36:09 -------- d-sh--w- C:\$RECYCLE.BIN
2011-04-19 03:27:54 240008 ----a-w- c:\windows\system32\drivers\netio.sys
2011-04-18 19:51:50 12872 ----a-w- c:\windows\system32\bootdelete.exe
2011-04-18 14:27:50 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-04-18 14:27:23 -------- d-----w- c:\progra~2\Hitman Pro
2011-04-17 13:05:19 -------- d-----w- c:\program files\ESET
2011-04-17 06:12:33 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
2011-04-17 05:07:58 -------- d-----w- c:\users\eldond~1\appdata\local\temp
2011-04-17 04:52:12 98816 ----a-w- c:\windows\sed.exe
2011-04-17 04:52:12 89088 ----a-w- c:\windows\MBR.exe
2011-04-17 04:52:12 256512 ----a-w- c:\windows\PEV.exe
2011-04-17 04:52:12 161792 ----a-w- c:\windows\SWREG.exe
2011-04-16 20:01:33 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-16 20:01:32 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-16 20:01:32 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-16 20:01:29 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-16 20:01:29 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-16 20:01:28 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-16 20:01:28 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-04-16 20:00:54 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-04-16 20:00:51 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-16 20:00:50 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-16 20:00:49 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-16 20:00:49 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-16 20:00:47 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-16 20:00:47 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-16 20:00:47 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-16 20:00:47 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-06 16:55:12 6792528 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{4b199828-faf8-4a83-8434-87d9999c5661}\mpengine.dll
2011-04-06 14:04:52 -------- d-----w- c:\users\eldond~1\appdata\roaming\DiskAid
2011-04-05 14:30:58 -------- d-----w- c:\users\eldon dekay\Audiobooks
2011-04-05 14:28:04 -------- d-----w- c:\users\eldond~1\appdata\roaming\MP3toiPodAudioBookConverter
2011-04-05 14:27:32 -------- d-----w- c:\program files\MP3ToIpodAudioBookConverter
2011-04-02 05:57:32 -------- d-----w- C:\alfred
2011-04-02 05:42:56 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2011-04-01 15:24:03 90112 --sha-r- c:\windows\system32\CTSBASWL.dll
.
==================== Find3M ====================
.
2011-04-22 18:57:57 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-04-22 18:57:57 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-22 18:57:57 3181568 ----a-w- c:\windows\system32\mf.dll
2011-04-22 18:57:57 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-22 18:57:57 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-04-22 18:57:57 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-04-22 18:57:57 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-04-22 18:57:57 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-22 18:57:57 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2011-04-22 18:57:57 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-04-22 18:57:57 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2011-04-22 18:57:57 107520 ----a-w- c:\windows\system32\cdd.dll
2011-04-22 18:57:57 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-04-17 06:03:29 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-03 02:11:20 222080 ------w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 16:02:26.06 ===============

Finally, after more than 48 hours, GMER finished. I tried to attach the log,but it is 1.49megs, and the max file size is 494K. I broke it into 5 segments so they would be uploadable, but the max to upload is 512k, so I will attach the 1st segment and if you want to see the other 4, please let me know.

Merged posts. ~ OB

Attached Files


Edited by Orange Blossom, 27 April 2011 - 04:27 PM.


BC AdBot (Login to Remove)

 


#2 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,779 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:04:12 PM

Posted 01 May 2011 - 08:34 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.
If you are unable to create a log because your computer cannot start up successfully please provide detailed information about the Windows version you are using: What we in particular need to know is version, edition and if it is a 32bit or a 64bit system.
If you are unsure about any of these caracteristics, just let us know and we'll help you figuring it out. Please also tell us if you have your Windows CD/DVD handy.


Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.
We need to create an OTL Report
  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • In the custom scan box paste the following:
    msconfig
    safebootminimal
    activex
    drivers32
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    wininit.exe
    hlp.dat
    /md5stop
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt<--Will be minimized

In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#3 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 01 May 2011 - 09:24 AM

Thanks for helping me. Active virus activity is not currently obvious, but I still have the following problems.

1. Google Redirect
2. Can't start Security Service
3. Can't start Windows Defender
4. Can't install MS Security Essentials

I can start the services above, but they stop immediately.


OTL.txt

OTL logfile created on: 5/1/2011 5:47:20 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Eldon DeKay\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.63 Gb Total Space | 133.92 Gb Free Space | 19.17% Space Free | Partition Type: NTFS
Drive F: | 146.38 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ELDONDEKAY | User Name: Eldon DeKay | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/01 05:45:48 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Eldon DeKay\Desktop\OTL.exe
PRC - [2011/04/29 09:20:27 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/04/19 18:56:47 | 003,253,656 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2011/04/16 22:03:29 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\javaw.exe
PRC - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/12/20 18:08:56 | 000,443,728 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2010/08/23 21:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2010/05/25 07:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2010/02/14 04:35:22 | 000,228,192 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMonUiAcc.exe
PRC - [2010/02/14 03:53:52 | 000,352,256 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMonTaskbar.exe
PRC - [2010/02/14 03:53:28 | 000,492,544 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMon.exe
PRC - [2009/10/30 21:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/09/15 16:07:10 | 000,602,960 | ---- | M] (ACD Systems International Inc.) -- C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
PRC - [2009/07/13 17:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2007/05/28 08:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007/04/09 12:32:32 | 000,019,456 | ---- | M] (Creative Technology Ltd) -- C:\Windows\System32\CtHelper.exe


========== Modules (SafeList) ==========

MOD - [2011/05/01 05:45:48 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Eldon DeKay\Desktop\OTL.exe
MOD - [2010/08/20 21:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2010/02/14 03:53:56 | 000,210,432 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\RTSUltraMonHook.dll
MOD - [2010/02/14 03:52:06 | 000,325,120 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMonResButtons.dll
MOD - [2009/07/13 17:03:50 | 001,624,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\GdiPlus.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/08/23 21:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2010/05/10 22:11:48 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/07/14 13:58:30 | 000,245,760 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\Windows\System32\snmvtsvc.exe -- (SMServer)
SRV - [2009/07/13 17:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 17:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 17:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/02/02 01:33:18 | 000,317,440 | ---- | M] (Amazon.com) [On_Demand | Stopped] -- C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe -- (Amazon Download Agent)
SRV - [2009/01/26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Stopped] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/10/31 19:14:26 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/10/29 15:00:50 | 000,089,600 | ---- | M] (NTRglobal) [Disabled | Stopped] -- C:\Program Files\NTR global\NTRconnect\NTRconnect.exe -- (ntrconnect)
SRV - [2008/10/21 15:50:00 | 000,548,864 | ---- | M] (Magix AG) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- (UPnPService)
SRV - [2008/09/01 16:43:18 | 000,098,488 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2007/05/28 08:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)


========== Driver Services (SafeList) ==========

DRV - [2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/11/26 10:38:14 | 000,083,696 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\idmwfp.sys -- (IDMWFP)
DRV - [2010/05/27 12:02:15 | 000,721,904 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/03/10 23:57:15 | 000,035,200 | ---- | M] (WinMount International Inc) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\WMDrive.sys -- (WMDrive)
DRV - [2010/02/16 12:06:58 | 000,040,560 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\hotcore3.sys -- (hotcore3)
DRV - [2009/12/30 12:21:16 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/12/19 10:22:01 | 000,104,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2009/11/11 17:23:46 | 000,030,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
DRV - [2009/11/11 17:23:44 | 000,022,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV - [2009/09/28 03:02:44 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Peerblock\pbfilter.sys -- (pbfilter)
DRV - [2009/07/13 17:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 17:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 17:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 15:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 15:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 15:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 14:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/06/10 13:19:48 | 009,853,248 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/02/20 16:36:52 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/02/05 12:06:59 | 000,051,792 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2008/11/14 03:11:30 | 000,017,184 | ---- | M] (Realtime Soft Ltd) [Kernel | Auto | Running] -- C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys -- (UltraMonUtility)
DRV - [2008/09/16 05:03:40 | 000,025,344 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\iTurns.sys -- (iTurns)
DRV - [2008/07/29 13:35:18 | 000,021,920 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\WNt500x86\sandra.sys -- (SANDRA)
DRV - [2008/03/13 18:09:51 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pfc.sys -- (pfc)
DRV - [2007/10/26 00:33:32 | 000,018,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctgame.sys -- (ctgame)
DRV - [2007/08/09 19:12:32 | 000,131,616 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvrd32.sys -- (nvrd32)
DRV - [2007/08/09 19:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2007/04/18 08:59:40 | 000,098,600 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\COMMONFX.DLL -- (COMMONFX.DLL)
DRV - [2007/04/12 08:10:26 | 000,164,608 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CT20XUT.DLL -- (CT20XUT.DLL)
DRV - [2007/04/12 08:10:26 | 000,066,816 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTHWIUT.DLL -- (CTHWIUT.DLL)
DRV - [2007/04/12 08:10:24 | 001,317,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTEXFIFX.DLL -- (CTEXFIFX.DLL)
DRV - [2007/04/12 08:10:22 | 000,323,328 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTEDSPSY.DLL -- (CTEDSPSY.DLL)
DRV - [2007/04/12 08:10:22 | 000,128,768 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTEDSPIO.DLL -- (CTEDSPIO.DLL)
DRV - [2007/04/12 08:10:20 | 000,280,320 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTEDSPFX.DLL -- (CTEDSPFX.DLL)
DRV - [2007/04/12 08:10:20 | 000,094,976 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTERFXFX.DLL -- (CTERFXFX.DLL)
DRV - [2007/04/12 08:10:18 | 000,168,192 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\CTEAPSFX.DLL -- (CTEAPSFX.DLL)
DRV - [2007/04/12 08:10:16 | 000,560,384 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\CTSBLFX.DLL -- (CTSBLFX.DLL)
DRV - [2007/04/12 08:10:16 | 000,546,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\CTAUDFX.DLL -- (CTAUDFX.DLL)
DRV - [2007/04/10 06:00:24 | 000,157,480 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2007/04/10 05:59:04 | 000,126,760 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2007/04/10 04:32:06 | 000,189,736 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\haP17v2k.sys -- (hap17v2k)
DRV - [2007/04/10 04:31:18 | 000,163,112 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\haP16v2k.sys -- (hap16v2k)
DRV - [2007/04/10 04:29:10 | 000,797,992 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ha10kx2k.sys -- (ha10kx2k)
DRV - [2007/04/10 04:28:36 | 000,092,968 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\emupia2k.sys -- (emupia)
DRV - [2007/04/10 04:25:46 | 000,014,632 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2007/04/10 04:21:06 | 000,347,128 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2007/04/10 04:20:38 | 000,520,488 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2007/04/10 04:19:30 | 000,511,272 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2006/11/28 21:46:24 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\APLMp50.sys -- (APLMp50)
DRV - [2006/11/22 09:52:08 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT)
DRV - [2006/11/10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
DRV - [2002/07/17 16:20:32 | 000,084,832 | ---- | M] (Adaptec) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ASPI32.SYS -- (ASPI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://anywhere.ebay.com/browser/internet-explorer/9/welcome
IE - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=

========== FireFox ==========

FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/webhp?rls=ig"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: autopager@mozilla.org:0.6.2.6
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..extensions.enabledItems: piclens@cooliris.com:1.12.2.44172
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: foxmarks@kei.com:3.9.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.5
FF - prefs.js..extensions.enabledItems: mozilla_cc@internetdownloadmanager.com:7.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 09:20:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010/01/02 10:03:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Extensions
[2011/04/26 16:50:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\extensions
[2011/01/14 09:53:31 | 000,000,000 | ---D | M] ("CoolPreviews") -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2011/04/16 20:18:16 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/04/16 20:18:18 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\extensions\foxmarks@kei.com
[2011/04/16 20:18:19 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\extensions\piclens@cooliris.com
[2008/12/22 15:29:28 | 000,000,890 | ---- | M] () -- C:\Users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\searchplugins\conduit.xml
[2011/04/19 17:34:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/02/09 18:04:34 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\ELDON DEKAY\APPDATA\ROAMING\IDM\IDMMZCC3
() (No name found) -- C:\USERS\ELDON DEKAY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SML57H2Q.DEFAULT\EXTENSIONS\AUTOPAGER@MOZILLA.ORG.XPI
[2010/01/02 09:46:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/29 09:20:27 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 00:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/16 21:05:38 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\..\Toolbar\ShellBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\..\Toolbar\WebBrowser: (no name) - {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No CLSID value found.
O4 - HKLM..\Run: [CTHelper] C:\Windows\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKU\.DEFAULT..\Run: [DevconDefaultDB] C:\Windows\System32\READREG.exe (Creative Technology Limited)
O4 - HKU\S-1-5-18..\Run: [DevconDefaultDB] C:\Windows\System32\READREG.exe (Creative Technology Limited)
O4 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000..\Run: [Device Detector] File not found
O4 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\DrmRemoval\YouTubeRipper.dll ()
O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\DrmRemoval\YouTubeRipper.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-3243215932-1131571249-2604786237-1000\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper: C:\Users\Eldon DeKay\Pictures\Desktop Backgrounds\PDRM0011.JPG
O24 - Desktop BackupWallPaper: C:\Users\Eldon DeKay\Pictures\Desktop Backgrounds\PDRM0011.JPG
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 13:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/10/19 20:15:52 | 000,000,493 | ---- | M] () - C:\autoexec.bat.xmp -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{BAB33F8B-47C7-41D6-B2A4-E4BDD433078B} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: VIDC.ACDV - C:\Windows\System32\ACDV.dll (ACD Systems)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.ffds - - File not found
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/05/01 05:45:45 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Eldon DeKay\Desktop\OTL.exe
[2011/04/28 11:35:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/04/28 11:35:42 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011/04/22 10:59:26 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2011/04/22 10:59:26 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/04/22 10:59:26 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/04/22 10:59:26 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011/04/22 10:59:26 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/04/22 10:59:26 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/04/22 10:59:26 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011/04/22 10:59:26 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011/04/22 10:59:26 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011/04/22 10:59:26 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2011/04/22 10:59:26 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011/04/22 10:59:26 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/04/22 10:59:26 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011/04/22 10:59:26 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2011/04/22 10:59:26 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/04/22 10:59:26 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2011/04/22 10:59:26 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2011/04/22 10:59:26 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2011/04/22 10:59:26 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2011/04/22 10:59:26 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2011/04/22 10:59:26 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011/04/22 10:59:26 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2011/04/22 10:59:26 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011/04/22 10:59:26 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2011/04/22 10:59:26 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2011/04/22 10:59:26 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011/04/22 10:59:26 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2011/04/22 10:59:26 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2011/04/22 10:59:26 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2011/04/22 10:59:26 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011/04/22 10:59:26 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011/04/22 10:59:26 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/04/22 10:59:26 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2011/04/22 10:59:26 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2011/04/22 10:59:26 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011/04/22 10:59:26 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2011/04/22 10:59:26 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011/04/22 10:59:26 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011/04/22 10:59:26 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011/04/22 10:57:57 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011/04/22 10:57:57 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2011/04/22 10:57:57 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2011/04/22 10:57:57 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011/04/22 10:57:57 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011/04/22 10:57:57 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011/04/22 10:57:57 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011/04/22 10:57:57 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011/04/22 10:57:57 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2011/04/22 10:57:57 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011/04/22 10:57:57 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011/04/22 10:57:57 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011/04/22 10:57:57 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011/04/22 10:57:57 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011/04/20 06:36:46 | 005,497,592 | ---- | C] (AVG Technologies) -- C:\Users\Eldon DeKay\Desktop\avg_isct_stb_all_2011_1321_cnet.exe
[2011/04/20 06:35:25 | 003,050,664 | ---- | C] (Piriform Ltd) -- C:\Users\Eldon DeKay\Desktop\ccsetup305.exe
[2011/04/19 20:03:51 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\DoctorWeb
[2011/04/19 19:01:57 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\Desktop\GooredFix Backups
[2011/04/19 17:34:55 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2011/04/18 23:21:49 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/18 23:21:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/18 23:21:46 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/04/18 23:21:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/18 22:37:25 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/04/18 22:36:09 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/04/18 22:21:53 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/04/18 19:27:54 | 000,240,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2011/04/18 19:25:06 | 007,866,472 | ---- | C] (Microsoft Corporation) -- C:\Users\Eldon DeKay\Desktop\mseinstall.exe
[2011/04/18 18:28:58 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/04/18 11:51:50 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\System32\bootdelete.exe
[2011/04/18 06:27:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro
[2011/04/17 22:57:13 | 006,449,984 | ---- | C] (SurfRight B.V.) -- C:\Users\Eldon DeKay\Desktop\HitmanPro35.exe
[2011/04/17 05:18:31 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Eldon DeKay\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/17 05:05:19 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/04/17 05:04:07 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Eldon DeKay\Desktop\esetsmartinstaller_enu.exe
[2011/04/16 22:12:33 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/04/16 22:04:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/04/16 22:03:36 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/04/16 22:03:36 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/04/16 22:03:36 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/04/16 21:59:53 | 000,885,024 | ---- | C] (Sun Microsystems, Inc.) -- C:\Users\Eldon DeKay\Desktop\jxpiinstall.exe
[2011/04/16 21:07:58 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\AppData\Local\temp
[2011/04/16 20:52:12 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/04/16 20:52:12 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/04/16 20:52:12 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/04/16 20:52:04 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/04/16 20:49:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/04/16 20:42:11 | 001,377,112 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Eldon DeKay\Desktop\tdsskiller.exe
[2011/04/16 12:01:29 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2011/04/16 12:01:28 | 000,294,912 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011/04/16 12:01:28 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011/04/16 12:00:54 | 002,331,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011/04/16 12:00:51 | 000,191,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FXSCOVER.exe
[2011/04/16 12:00:49 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2011/04/16 12:00:49 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2011/04/06 06:04:52 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\AppData\Roaming\DiskAid
[2011/04/05 06:30:58 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\Audiobooks
[2011/04/05 06:28:04 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\AppData\Roaming\MP3toiPodAudioBookConverter
[2011/04/05 06:27:41 | 000,000,000 | ---D | C] -- C:\Users\Eldon DeKay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 to iPod Audio Book Converter
[2011/04/05 06:27:32 | 000,000,000 | ---D | C] -- C:\Program Files\MP3ToIpodAudioBookConverter
[2011/04/01 21:57:32 | 000,000,000 | ---D | C] -- C:\alfred
[2011/04/01 21:43:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerDesk 7
[2011/04/01 21:42:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/11/26 20:46:29 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Eldon DeKay\AppData\Roaming\pcouffin.sys
[2007/04/09 12:32:58 | 000,034,816 | ---- | C] ( ) -- C:\Windows\System32\a3d.dll
[2007/04/09 12:19:16 | 000,010,240 | ---- | C] ( ) -- C:\Windows\System32\killapps.exe
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/01 05:45:48 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Eldon DeKay\Desktop\OTL.exe
[2011/05/01 05:27:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/01 05:01:00 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3243215932-1131571249-2604786237-1000UA.job
[2011/04/30 22:27:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1ca574754e2ba80.job
[2011/04/30 12:01:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3243215932-1131571249-2604786237-1000Core.job
[2011/04/27 03:03:50 | 000,011,104 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 03:03:50 | 000,011,104 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/26 16:46:26 | 000,618,026 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/04/26 16:46:26 | 000,104,340 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/04/26 16:42:14 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2011/04/26 16:40:31 | 000,005,426 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011/04/26 16:40:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/26 16:39:52 | 2415,558,656 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/26 16:39:51 | 000,032,592 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000003-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/26 16:39:51 | 000,032,592 | ---- | M] () -- C:\Windows\System32\BMXState-{00000003-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/26 16:39:51 | 000,032,088 | ---- | M] () -- C:\Windows\System32\BMXCtrlState-{00000003-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/26 16:39:51 | 000,032,088 | ---- | M] () -- C:\Windows\System32\BMXBkpCtrlState-{00000003-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/26 16:39:51 | 000,011,564 | ---- | M] () -- C:\Windows\System32\DVCState-{00000003-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/22 20:39:38 | 000,002,052 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/04/22 15:59:27 | 000,625,664 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\dds.scr
[2011/04/22 15:57:59 | 000,000,020 | ---- | M] () -- C:\Users\Eldon DeKay\defogger_reenable
[2011/04/22 15:56:49 | 000,050,477 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\Defogger.exe
[2011/04/22 15:52:06 | 000,002,056 | -H-- | M] () -- C:\Users\Eldon DeKay\Documents\Default.rdp
[2011/04/22 11:21:01 | 000,001,457 | ---- | M] () -- C:\Users\Eldon DeKay\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/22 10:59:26 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat
[2011/04/22 10:59:26 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/04/22 10:59:26 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/04/22 10:59:26 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011/04/22 10:59:26 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/04/22 10:59:26 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/04/22 10:59:26 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2011/04/22 10:59:26 | 000,420,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011/04/22 10:59:26 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2011/04/22 10:59:26 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2011/04/22 10:59:26 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2011/04/22 10:59:26 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/04/22 10:59:26 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll
[2011/04/22 10:59:26 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2011/04/22 10:59:26 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/04/22 10:59:26 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll
[2011/04/22 10:59:26 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2011/04/22 10:59:26 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll
[2011/04/22 10:59:26 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe
[2011/04/22 10:59:26 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe
[2011/04/22 10:59:26 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2011/04/22 10:59:26 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll
[2011/04/22 10:59:26 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2011/04/22 10:59:26 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll
[2011/04/22 10:59:26 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll
[2011/04/22 10:59:26 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2011/04/22 10:59:26 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2011/04/22 10:59:26 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe
[2011/04/22 10:59:26 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2011/04/22 10:59:26 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2011/04/22 10:59:26 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2011/04/22 10:59:26 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2011/04/22 10:59:26 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/04/22 10:59:26 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll
[2011/04/22 10:59:26 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll
[2011/04/22 10:59:26 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2011/04/22 10:59:26 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll
[2011/04/22 10:59:26 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2011/04/22 10:59:26 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2011/04/22 10:59:26 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2011/04/22 10:57:57 | 003,181,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011/04/22 10:57:57 | 001,619,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2011/04/22 10:57:57 | 001,495,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ExplorerFrame.dll
[2011/04/22 10:57:57 | 001,170,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2011/04/22 10:57:57 | 001,074,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2011/04/22 10:57:57 | 000,739,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2011/04/22 10:57:57 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2011/04/22 10:57:57 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2011/04/22 10:57:57 | 000,219,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2011/04/22 10:57:57 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2011/04/22 10:57:57 | 000,196,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011/04/22 10:57:57 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2011/04/22 10:57:57 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\XpsRasterService.dll
[2011/04/22 10:57:57 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cdd.dll
[2011/04/22 08:07:30 | 000,039,936 | ---- | M] () -- C:\Users\Eldon DeKay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/20 18:06:40 | 000,301,568 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\u1ufw6ub.exe
[2011/04/20 06:37:15 | 005,497,592 | ---- | M] (AVG Technologies) -- C:\Users\Eldon DeKay\Desktop\avg_isct_stb_all_2011_1321_cnet.exe
[2011/04/20 06:35:42 | 003,050,664 | ---- | M] (Piriform Ltd) -- C:\Users\Eldon DeKay\Desktop\ccsetup305.exe
[2011/04/19 17:34:57 | 000,001,142 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/18 23:21:49 | 000,001,117 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/18 22:07:35 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\Windows\System32\bootdelete.exe
[2011/04/18 21:52:37 | 000,016,968 | ---- | M] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2011/04/18 19:26:29 | 007,866,472 | ---- | M] (Microsoft Corporation) -- C:\Users\Eldon DeKay\Desktop\mseinstall.exe
[2011/04/18 18:29:00 | 000,002,360 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\Google Chrome.lnk
[2011/04/18 12:45:03 | 004,958,588 | ---- | M] () -- C:\Windows\{00000003-00000000-00000008-00001102-00000004-20021102}.CDF
[2011/04/18 12:45:03 | 004,958,588 | ---- | M] () -- C:\Windows\{00000003-00000000-00000008-00001102-00000004-20021102}.BAK
[2011/04/18 12:34:20 | 003,864,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/04/18 12:03:33 | 000,379,392 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\subinacl.msi
[2011/04/17 22:59:00 | 006,449,984 | ---- | M] (SurfRight B.V.) -- C:\Users\Eldon DeKay\Desktop\HitmanPro35.exe
[2011/04/17 05:19:51 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Eldon DeKay\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/17 05:17:11 | 000,085,504 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\Inherit.exe
[2011/04/17 05:04:58 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Eldon DeKay\Desktop\esetsmartinstaller_enu.exe
[2011/04/17 04:34:50 | 000,006,130 | ---- | M] () -- C:\Windows\UEDIT32.INI
[2011/04/16 22:03:29 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011/04/16 22:03:29 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/04/16 22:03:29 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/04/16 22:03:29 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/04/16 21:59:53 | 000,885,024 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\Eldon DeKay\Desktop\jxpiinstall.exe
[2011/04/16 21:05:38 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/04/16 20:43:08 | 001,377,112 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Eldon DeKay\Desktop\tdsskiller.exe
[2011/04/16 20:39:17 | 004,323,092 | R--- | M] () -- C:\Users\Eldon DeKay\Desktop\ComboFix.exe
[2011/04/16 17:25:51 | 000,032,592 | ---- | M] () -- C:\Windows\System32\BMXStateBkp-{00000004-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/16 17:25:51 | 000,032,592 | ---- | M] () -- C:\Windows\System32\BMXState-{00000004-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/16 17:25:51 | 000,032,088 | ---- | M] () -- C:\Windows\System32\BMXCtrlState-{00000004-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/16 17:25:51 | 000,032,088 | ---- | M] () -- C:\Windows\System32\BMXBkpCtrlState-{00000004-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/16 17:25:51 | 000,011,564 | ---- | M] () -- C:\Windows\System32\DVCState-{00000004-00000000-00000008-00001102-00000004-20021102}.rfx
[2011/04/16 17:25:36 | 004,958,588 | ---- | M] () -- C:\Windows\{00000004-00000000-00000008-00001102-00000004-20021102}.CDF
[2011/04/16 17:25:36 | 004,958,588 | ---- | M] () -- C:\Windows\{00000004-00000000-00000008-00001102-00000004-20021102}.BAK
[2011/04/16 17:25:28 | 000,051,922 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\Spider Two Suits.gam
[2011/04/16 17:24:47 | 000,000,172 | ---- | M] () -- C:\Windows\wininit.ini
[2011/04/05 12:49:22 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2011/04/04 20:22:17 | 000,000,017 | ---- | M] () -- C:\Users\Eldon DeKay\AppData\Local\resmon.resmoncfg
[2011/04/04 17:50:36 | 000,262,951 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\contacts_20110404.zip
[2011/04/01 21:44:35 | 000,001,009 | ---- | M] () -- C:\Users\Eldon DeKay\Desktop\PowerDesk 7.lnk
[2011/04/01 21:43:46 | 000,001,103 | ---- | M] () -- C:\Users\Eldon DeKay\Application Data\Microsoft\Internet Explorer\Quick Launch\PowerDesk 7.lnk
[2011/04/01 08:08:46 | 130,876,744 | ---- | M] (Norman ASA) -- C:\Users\Eldon DeKay\Desktop\Norman_Malware_Cleaner.exe
[2011/04/01 07:24:03 | 000,090,112 | RHS- | M] () -- C:\Windows\System32\CTSBASWL.dll
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/22 16:07:36 | 000,301,568 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\gmer.exe
[2011/04/22 15:59:26 | 000,625,664 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\dds.scr
[2011/04/22 15:57:37 | 000,000,020 | ---- | C] () -- C:\Users\Eldon DeKay\defogger_reenable
[2011/04/22 15:56:43 | 000,050,477 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\Defogger.exe
[2011/04/22 10:59:26 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011/04/20 18:06:32 | 000,301,568 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\u1ufw6ub.exe
[2011/04/20 06:42:01 | 000,475,418 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\Silent Runners.vbs
[2011/04/19 17:34:57 | 000,001,154 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/04/19 17:34:57 | 000,001,142 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/18 23:21:49 | 000,001,117 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/18 19:28:42 | 000,002,052 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/04/18 18:29:00 | 000,002,360 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\Google Chrome.lnk
[2011/04/18 12:03:32 | 000,379,392 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\subinacl.msi
[2011/04/18 06:27:50 | 000,016,968 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2011/04/17 05:17:06 | 000,085,504 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\Inherit.exe
[2011/04/16 20:52:12 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/04/16 20:52:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/04/16 20:52:12 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/04/16 20:52:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/04/16 20:52:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/04/16 20:38:51 | 004,323,092 | R--- | C] () -- C:\Users\Eldon DeKay\Desktop\ComboFix.exe
[2011/04/16 17:25:28 | 000,051,922 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\Spider Two Suits.gam
[2011/04/04 20:22:17 | 000,000,017 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Local\resmon.resmoncfg
[2011/04/04 17:50:35 | 000,262,951 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\contacts_20110404.zip
[2011/04/01 21:44:35 | 000,001,009 | ---- | C] () -- C:\Users\Eldon DeKay\Desktop\PowerDesk 7.lnk
[2011/04/01 21:43:46 | 000,001,103 | ---- | C] () -- C:\Users\Eldon DeKay\Application Data\Microsoft\Internet Explorer\Quick Launch\PowerDesk 7.lnk
[2011/04/01 07:24:03 | 000,090,112 | RHS- | C] () -- C:\Windows\System32\CTSBASWL.dll
[2011/01/01 11:32:49 | 000,129,024 | ---- | C] () -- C:\Windows\System32\AVERM.dll
[2011/01/01 11:32:49 | 000,028,672 | ---- | C] () -- C:\Windows\System32\AVEQT.dll
[2010/12/18 13:08:49 | 000,069,632 | ---- | C] () -- C:\Windows\System32\realbap1.dll
[2010/12/18 13:08:49 | 000,045,568 | ---- | C] () -- C:\Windows\System32\realbsf1.dll
[2010/10/25 08:38:54 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll
[2010/04/13 21:27:37 | 000,000,648 | ---- | C] () -- C:\Windows\PhotoBee.INI
[2010/04/09 06:29:17 | 000,000,023 | ---- | C] () -- C:\ProgramData\downloadlist.sav
[2010/04/09 06:09:30 | 000,000,174 | ---- | C] () -- C:\ProgramData\Setting.dat
[2010/04/09 06:09:30 | 000,000,022 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Roaming\UserFlag.ini
[2010/04/09 05:57:24 | 000,000,128 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Local\00000014
[2010/03/27 20:37:17 | 000,015,620 | ---- | C] () -- C:\Windows\System32\SystemRes13.sm.SYS
[2010/03/19 22:30:43 | 000,000,043 | ---- | C] () -- C:\Windows\MezzmoMediaServer.INI
[2010/03/13 12:10:52 | 000,000,007 | ---- | C] () -- C:\Windows\sysres10.dat
[2010/02/12 17:11:12 | 000,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2010/02/09 19:31:49 | 000,000,020 | ---- | C] () -- C:\Windows\simpwt.dat
[2010/02/05 13:04:47 | 000,039,424 | ---- | C] () -- C:\Windows\System32\rpiAccessProcess.dll
[2010/01/28 15:10:51 | 000,000,423 | ---- | C] () -- C:\Windows\System32\dext536.ini
[2010/01/28 15:10:50 | 000,001,609 | ---- | C] () -- C:\Windows\Remove.ini
[2010/01/08 17:06:33 | 000,039,936 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/02 12:02:31 | 000,005,426 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/01/02 10:22:51 | 000,021,316 | ---- | C] () -- C:\Windows\System32\emptyregdb.dat
[2009/12/23 07:45:13 | 000,000,050 | ---- | C] () -- C:\Windows\MegaManager.INI
[2009/12/22 18:45:48 | 000,000,040 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Roaming\cdr.ini
[2009/11/26 20:46:30 | 000,007,887 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Roaming\pcouffin.cat
[2009/11/26 20:46:29 | 000,001,144 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Roaming\pcouffin.inf
[2009/11/12 10:36:26 | 000,000,686 | -H-- | C] () -- C:\Windows\System32\tpicfg.ini
[2009/11/08 17:35:39 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2009/10/01 06:31:49 | 000,000,083 | ---- | C] () -- C:\Windows\System32\gpupdate.bin
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/13 20:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 20:33:53 | 003,864,080 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 18:05:48 | 000,618,026 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 18:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 18:05:48 | 000,104,340 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 18:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 18:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 18:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 16:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 15:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 15:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 15:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 13:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/03/15 18:19:51 | 000,000,600 | R--- | C] () -- C:\Windows\System32\hppapr02.dat
[2009/03/15 18:19:42 | 000,000,138 | ---- | C] () -- C:\Windows\System32\AddPort.ini
[2009/03/15 18:19:15 | 000,000,839 | ---- | C] () -- C:\Windows\hpntwksetup.ini
[2009/03/15 18:13:55 | 000,130,821 | ---- | C] () -- C:\Windows\hppins03.dat
[2009/03/06 06:30:41 | 000,110,602 | ---- | C] () -- C:\Windows\System32\xcdsfx32.bin
[2009/02/14 18:36:16 | 000,015,620 | ---- | C] () -- C:\Windows\System32\SystemRes10.b30.SYS
[2008/12/05 08:13:56 | 000,000,108 | RHS- | C] () -- C:\Windows\neoqaz2.dll
[2008/11/21 23:41:14 | 000,105,472 | ---- | C] () -- C:\Windows\System32\APOMngr.dll
[2008/11/21 23:41:14 | 000,067,072 | ---- | C] () -- C:\Windows\System32\CmdRtr.dll
[2008/11/18 19:31:48 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2008/11/14 08:01:50 | 000,065,536 | ---- | C] () -- C:\Windows\System32\eztw32.dll
[2008/11/14 07:52:46 | 000,143,540 | ---- | C] () -- C:\Windows\Curves 2 Uninstaller.exe
[2008/11/14 07:04:40 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RBRegEx350.dll
[2008/11/14 07:04:40 | 000,067,072 | ---- | C] () -- C:\Windows\System32\LP0310.dll
[2008/11/14 07:04:40 | 000,061,952 | ---- | C] () -- C:\Windows\System32\rbap350.dll
[2008/11/14 07:04:40 | 000,041,472 | ---- | C] () -- C:\Windows\System32\MBSPlugin.DLL
[2008/11/14 07:04:40 | 000,040,960 | ---- | C] () -- C:\Windows\System32\RBShell400.dll
[2008/11/14 07:04:40 | 000,037,888 | ---- | C] () -- C:\Windows\System32\MBSRegistryPlugin.DLL
[2008/11/14 07:04:40 | 000,035,328 | ---- | C] () -- C:\Windows\System32\MBSFolderPlugin.DLL
[2008/11/14 07:04:40 | 000,031,744 | ---- | C] () -- C:\Windows\System32\MBSMacTTPlugin.DLL
[2008/11/14 07:04:40 | 000,029,184 | ---- | C] () -- C:\Windows\System32\LP0301Gestalt.dll
[2008/11/14 07:04:40 | 000,028,160 | ---- | C] () -- C:\Windows\System32\MBSRegPlugin.DLL
[2008/11/14 07:04:40 | 000,028,160 | ---- | C] () -- C:\Windows\System32\LP0301ResFork.dll
[2008/11/14 07:04:40 | 000,027,648 | ---- | C] () -- C:\Windows\System32\LP0301LinkFile.dll
[2008/11/02 09:36:22 | 000,185,856 | ---- | C] () -- C:\Windows\System32\Bmp2Jpeg.dll
[2008/11/01 23:19:49 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/10/29 18:43:10 | 000,022,328 | ---- | C] () -- C:\Users\Eldon DeKay\AppData\Roaming\PnkBstrK.sys
[2008/10/10 09:08:59 | 000,006,130 | ---- | C] () -- C:\Windows\UEDIT32.INI
[2008/09/28 23:12:17 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008/09/26 12:03:22 | 000,000,172 | ---- | C] () -- C:\Windows\wininit.ini
[2008/09/26 09:34:32 | 000,237,568 | ---- | C] () -- C:\Windows\System32\rmc_rtspdl.dll
[2008/08/05 16:45:34 | 000,106,496 | ---- | C] () -- C:\Windows\System32\jacob.dll
[2008/07/15 21:40:55 | 000,000,036 | ---- | C] () -- C:\Windows\mafosav.INI
[2008/07/13 07:39:04 | 000,022,723 | ---- | C] () -- C:\Windows\System32\SSGR3l3.dll
[2008/05/29 11:47:32 | 002,023,424 | ---- | C] () -- C:\Windows\System32\QtCore4.dll
[2008/05/24 02:07:44 | 000,000,024 | ---- | C] () -- C:\Windows\System32\Drv32_16.ini
[2008/04/24 00:49:52 | 007,315,456 | ---- | C] () -- C:\Windows\System32\QtGui4.dll
[2008/04/08 13:53:44 | 000,020,333 | ---- | C] () -- C:\Windows\cmaudio.ini
[2008/04/03 09:31:32 | 000,000,165 | ---- | C] () -- C:\Windows\Quicken.ini
[2008/03/13 13:43:52 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2008/03/07 21:11:38 | 000,003,636 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2008/03/07 20:16:40 | 000,000,047 | ---- | C] () -- C:\Windows\InoSetup.ini
[2008/03/07 19:55:05 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2007/12/04 16:03:54 | 000,001,602 | ---- | C] () -- C:\Windows\hppmdl03.dat
[2007/04/12 08:10:28 | 000,105,728 | ---- | C] () -- C:\Windows\System32\APOMgrH.dll
[2007/04/09 12:55:14 | 000,097,785 | ---- | C] () -- C:\Windows\System32\instwdm.ini
[2007/04/09 12:55:14 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini
[2007/04/09 12:33:50 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CTBurst.dll
[2007/04/09 12:32:32 | 000,037,888 | ---- | C] () -- C:\Windows\System32\psconv.exe
[2007/04/09 12:24:30 | 000,325,821 | ---- | C] () -- C:\Windows\System32\ctdlang.dat
[2007/04/09 12:24:30 | 000,046,273 | ---- | C] () -- C:\Windows\System32\ctdnlstr.dat
[2007/04/09 12:21:44 | 000,048,128 | ---- | C] () -- C:\Windows\System32\regplib.exe
[2007/04/09 12:21:28 | 000,149,838 | ---- | C] () -- C:\Windows\System32\ctbas2w.dat
[2007/04/09 12:19:44 | 000,274,587 | ---- | C] () -- C:\Windows\System32\ctsbas2w.dat
[2007/04/09 12:19:36 | 000,241,084 | ---- | C] () -- C:\Windows\System32\CTSBASW.DAT
[2007/04/09 12:19:36 | 000,115,166 | ---- | C] () -- C:\Windows\System32\CTBASICW.DAT
[2007/04/09 12:19:20 | 000,313,207 | ---- | C] () -- C:\Windows\System32\ctstatic.dat
[2007/04/09 12:19:20 | 000,053,932 | ---- | C] () -- C:\Windows\System32\ctdaught.dat
[2007/04/09 12:19:18 | 000,005,120 | ---- | C] () -- C:\Windows\System32\enlocstr.exe
[2006/10/02 09:25:18 | 000,000,307 | ---- | C] () -- C:\Windows\System32\kill.ini
[2006/09/06 13:42:58 | 000,237,568 | R--- | C] () -- C:\Windows\System32\hppapr02.dll
[2005/06/16 10:17:16 | 000,071,680 | ---- | C] () -- C:\Windows\System32\ctmmactl.dll
[2003/10/06 00:21:31 | 000,000,000 | -H-- | C] () -- C:\ProgramData\sdpsenv.dat
[2002/03/21 15:39:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\UNACEV2.DLL
[2001/07/07 04:00:00 | 000,003,399 | ---- | C] () -- C:\Windows\System32\hptcpmon.ini
[2001/03/13 20:22:21 | 000,000,080 | --S- | C] () -- C:\Windows\System32\argtmp39.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2006/11/01 13:06:18 | 000,162,616 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\RegDelNull.exe


< MD5 for: EXPLORER.EXE >
[2009/07/13 17:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\ERDNT\cache\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2009/08/02 21:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/02 21:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: WININIT.EXE >
[2009/07/13 17:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\ERDNT\cache\wininit.exe
[2009/07/13 17:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009/07/13 17:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/27 22:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\ERDNT\cache\winlogon.exe
[2009/10/27 22:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\System32\winlogon.exe
[2009/10/27 22:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/27 21:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2009/07/13 17:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 80 bytes -> C:\ProgramData\sdpsenv.dat:naughtypirates
@Alternate Data Stream - 207 bytes -> C:\ProgramData\TEMP:44807EFA
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:EEDA5B17
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:264B2CC4
@Alternate Data Stream - 108 bytes -> C:\Windows:

< End of report >




Extras.txt

OTL Extras logfile created on: 5/1/2011 5:47:20 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Eldon DeKay\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.63 Gb Total Space | 133.92 Gb Free Space | 19.17% Space Free | Partition Type: NTFS
Drive F: | 146.38 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: ELDONDEKAY | User Name: Eldon DeKay | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Pro 3.Manage] -- "C:\Program Files\ACD Systems\ACDSee Pro\3.0\ACDSeeQVPro3.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [File Finder...] -- C:\Program Files\Avanquest\PowerDesk\pdfind.exe /PATH:%1 (Avanquest Software USA, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
"PolicyVersion" = 522

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 1
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\Eldon DeKay\AppData\Local\Temp\wz97e0\Crack\VUESCAN.exe" = C:\Users\Eldon DeKay\AppData\Local\Temp\wz97e0\Crack\VUESCAN.exe:*:Enabled:VUESCAN


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{08D53B43-AB77-4895-B148-A5E7DC5DAC3D}" = TouchCopy 09
"{09348778-FDD7-4D5A-A518-583DB64D936E}" = Picture Collage Maker Full
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0EC06B0E-9063-4F00-909D-5ACE78D798D6}" = HDHomeRun
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B280FAF-AE10-4E31-A41A-DB3917D651DC}" = ACDSee Pro 3
"{21199F32-B676-4FE2-A443-EF7DB6B8FD4F}" = Opera 10.10
"{213D87A3-BE42-42CE-9B2C-7BF7A85710DD}" = Imagesynth 2
"{242DE297-BC43-4294-B83D-E0DBFF10A6A3}" = Digital Camera
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2FCAB582-E6F9-45AF-988D-869015108473}" = Namco Museum 50th Anniversary
"{30283233-3BE6-473D-A47C-ED964A2F78B4}_is1" = Inpaint 2.3
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{3328FC27-2F0B-44F8-88B7-6CD77281ED90}" = Librarian Pro
"{334B6B44-2C7F-4AC0-A215-E780541CE033}" = Paragon Drive Copy 9.0 Personal Special Edition
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{414C803A-6115-4DB6-BD4E-FD81EA6BC71C}" = Product_SF_Min_QFolder
"{41BB38A4-ED84-4682-8329-042FEBD8C30B}" = Mega Manager
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{49CC1A6A-3A1A-4EE7-913F-8106B51B59D1}" = Paragon Partition Manager 2009 Special Edition
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C8169AB-B6C1-413B-81B6-73B77127D82F}" = Microsoft File Transfer Manager
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{549514BF-2BDA-422B-9134-67B5A79C2487}" = NTRConnect
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57DA304D-27B0-40D1-A796-92CEFF20FA32}" = hppIOFiles
"{59FD743D-A699-449E-8197-BD2899DAD69A}" = OverDrive Media Console
"{5AFA81C6-6DE9-49b0-B2C1-D53763632D59}_is1" = Duplicate File Remover
"{5CB3DDA0-F143-4E65-A2FA-3C95F82139D2}_is1" = Wondershare Movie Story GAOTD Edition 4.5.0
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.1
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7057ABC2-EFF3-4E43-9806-8BCB6EEA9FE6}" = Microsoft IntelliPoint 7.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ONENOTE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ONENOTE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ONENOTE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ONENOTE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0000-0000-0000000FF1CE}" = Microsoft Office OneNote 2007
"{90120000-00A1-0000-0000-0000000FF1CE}_ONENOTE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0000-0000-0000000FF1CE}_ONENOTE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ONENOTE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ONENOTE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{94B4453A-7C1C-42A1-B1CF-F4EF3DB6DC21}" = Eudora
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9FA2E0CF-64E8-3536-BA71-618A48D9AF55}" = Google Talk Plugin
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA01BA34-88F7-436D-822A-35324727C4C1}" = O&O UnErase
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AEB8F226-C238-4636-A289-E540B725B5BB}_is1" = AnyReader
"{B0513493-04B9-4F21-B4AB-83E750D54256}" = Adobe Photoshop Lightroom 2.7
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{B93251B5-9209-4DAB-867C-AA98D91584CD}" = PowerDesk 7
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE282C23-5484-47FF-B2C1-EBEA5C891033}" = Nero 8 Trial
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{BF50CF00-7CE6-11DE-A06C-005056C00008}" = Paragon Virtualization Manager™ 9.5
"{C2D129C0-7508-11DF-9F1B-005056806466}" = Google Earth
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2196}_is1" = SiSoftware Sandra Professional Business 2009
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C84ED624-5F84-43d8-8914-5301C7EC42F9}" = NetLibrary Media Center
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}" = WinZip 14.0
"{CF969A8C-052F-401F-A2C8-C8819757C001}" = hppManuals2605
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow! 1.0
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D5A9B7C0-8751-11D8-9D75-000129760D75}" = MediaShow 3.0
"{D7F8FF50-EEED-4F79-BE51-ADA945AA17ED}" = AutoPlay Media Studio 7.0
"{D8AC1EB5-E8B0-44A0-B113-899407188A2F}" = hppFonts
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB0F5549-0EEE-4421-A1B2-08FB1468D7F1}" = calibre
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}" = COWON Media Center - jetAudio Plus VX
"{E622695B-3A22-4774-993D-318049488C0C}" = LDS Scriptures CD-ROM Standard Edition
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"{FF7A031F-96C8-404C-99C9-96C675D6099F}" = The Incredible Machine: Even More Contraptions
"7-Zip" = 7-Zip 9.20
"AAA Logo 3.10 Business_is1" = AAA Logo Business Edition 3.10
"AB Commander" = AB Commander
"ABC Amber LIT Converter" = ABC Amber LIT Converter
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"Advanced Audio Titanium_is1" = Audio Recorder Titanium v6.0.2
"Amazon Games & Software Downloader_is1" = Amazon Games & Software Downloader
"AnalogX Extension Changer" = AnalogX Extension Changer
"Angel's Vox" = Angel's Vox 1.2
"AnVir Task Manager" = AnVir Task Manager
"Any DVD Shrink_is1" = Any DVD Shrink 1.2.1
"AnyDVD" = AnyDVD
"Applian Director1.1" = Applian Director
"Artizen HDR" = Artizen HDR 2.4.8
"Ashampoo Core Tuner_is1" = Ashampoo Core Tuner 1.21
"AudioConSole" = Creative Audio Console
"AV Bros. Page Curl Pro 2.1" = AV Bros. Page Curl Pro 2.1 (Remove Only)
"B/W Styler 1.0" = B/W Styler 1.0
"Blow Up" = Alien Skin Blow Up
"ca_movielabel_is1" = Movie Label 2011 v6.1.1
"CDisplayEx_is1" = CDisplayEx 1.4
"Chess3D" = Chess3D 4.0
"CHM To PDF PRO_is1" = CHM To PDF Converter PRO
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"Cool MP3 Splitter_is1" = Cool MP3 Splitter 2.2
"Crazy Machines New from the Lab1.231" = Crazy Machines New from the Lab
"Creative Element Power Tools" = Creative Element Power Tools
"Curves 2" = Curves 2
"Daniusoft Media Converter_is1" = Daniusoft Media Converter(Build 2.3.2.0)
"Digital Editions" = Adobe Digital Editions
"DigitalEditions" = Digital Editions Converter
"Driver Magician_is1" = Driver Magician 3.4
"DrmRemoval_is1" = DrmRemoval 3.8.6
"DVDFab 7_is1" = DVDFab 7.0.3.0 (26/03/2010)
"Dynamic-Photo HDR 4_is1" = Dynamic-Photo HDR 4.7
"EyeCandy5Impact" = Alien Skin Eye Candy 5 Impact
"EyeCandy5Nature" = Alien Skin Eye Candy 5 Nature
"EyeCandy5Textures" = Alien Skin Eye Candy 5 Textures
"FlexTk Ultimate" = FlexTk Ultimate 3.8.44
"Glary Utilities_is1" = Glary Utilities Pro 2.18.0.786
"HP Color LaserJet 2605" = HP Color LaserJet 2605 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"Image Doctor 2" = Alien Skin Image Doctor 2
"InstallShield_{213D87A3-BE42-42CE-9B2C-7BF7A85710DD}" = Imagesynth 2
"Internet Download Manager" = Internet Download Manager
"IsoBuster_is1" = IsoBuster 1.5
"JDownloader" = JDownloader
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"LogoMaker_is1" = LogoMaker 3.0
"Lupas Rename 2000_is1" = Lupas Rename 2000 v5.0 Release
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Micro DVD Player" = Micro DVD Player
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Neat Image_is1" = Neat Image v5.9 Pro+
"nik Sharpener Pro 2.0 Complete" = nik Sharpener Pro 2.0 Complete
"NVIDIA Drivers" = NVIDIA Drivers
"ONENOTE" = Microsoft Office OneNote 2007
"OpenAL" = OpenAL
"Paragon Easy CD/DVD Recorder 9.0_is1" = Paragon Easy CD/DVD Recorder 9.0
"Picasa 3" = Picasa 3
"Power Retouche Pro" = Power Retouche Pro
"ProcessLasso" = Process Lasso
"PROR" = Microsoft Office Professional 2007
"Puzzle Master 5" = Puzzle Master 5
"RealAlt_is1" = Real Alternative 2.0.1 Lite
"RecentX_is1" = RecentX 2.0
"Recover Keys_is1" = Recover Keys
"Replay Converter 3" = Replay Converter 3
"Replay Media Catcher 3.01" = Replay Media Catcher 3.01
"Replay Media Catcher 3.02" = Replay Media Catcher 3.02
"Replay Media Catcher 3.11" = Replay Media Catcher
"Replay Media Catcher2.10" = Replay Media Catcher
"Replay Media Catcher2.10D" = Replay Media Catcher
"Replay Music3.93" = Replay Music
"Replay Video Capture4.1" = Replay Video Capture
"Replay_AV_807" = Replay AV 8
"Replay_Media_Splitter_1.2" = Replay Media Splitter 1.7.911
"SEGAGenesisClassics" = SEGA Genesis Classics
"SolSuite_is1" = SolSuite 2011 v11.0
"SysResources Manager10.1" = SysResources Manager
"SysResources Manager10.6" = SysResources Manager
"TextAloud3_is1" = TextAloud 3.0
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"TweakNow PowerPack 2006 Professional_is1" = TweakNow PowerPack 2006 Professional
"Ultra Video Joiner_is1" = Ultra Video Joiner 6.0.1227
"UltraEdit-32" = UltraEdit-32 Uninstall
"VeohProxy" = VeohProxy
"Verbix2008_is1" = Verbix 2008
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"Virtual DJ Pro Full - Atomix Productions" = Virtual DJ Pro Full - Atomix Productions
"Virtual Painter 5 (for Photoshop)" = Virtual Painter 5 (for Photoshop)
"VLC media player" = VLC media player 0.9.8a
"WinAVI Video Converter 10.0_is1" = WinAVI Video Converter
"WinDjView" = WinDjView 1.0.3
"WinMount3_is1" = WinMount V3.2.1117
"WinRAR archiver" = WinRAR archiver
"Wondershare Audio Converter_is1" = Wondershare Audio Converter(Build 4.2.0.56)
"Wondershare FLV Downloader Pro_is1" = Wondershare FLV Downloader Pro(Build 1.4.1.16)
"Wondershare Music Converter_is1" = Wondershare Music Converter(Build 1.1.0.0)
"Wondershare Photo Collage Studio Giveaway Edition_is1" = Wondershare Photo Collage Studio 4.2.8
"Wootalyzer" = Wootalyzer!
"Xenofex2" = Alien Skin Xenofex 2.0
"Xilisoft DVD Ripper Ultimate 5" = Xilisoft DVD Ripper Ultimate
"Xilisoft Video Converter Standard" = Xilisoft Video Converter Standard

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3243215932-1131571249-2604786237-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dr. DivX 2.0 OSS" = Dr. DivX 2.0 OSS
"Facebook Plug-In" = Facebook Plug-In
"FamilySearch Indexing" = FamilySearch Indexing
"Google Chrome" = Google Chrome
"Uninstall FamilySearch Indexing" = Uninstall FamilySearch Indexing
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

#4 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,779 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:04:12 PM

Posted 02 May 2011 - 04:22 PM

Hi,

could you please show me the logs from combofix and tdsskiller?

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#5 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 02 May 2011 - 05:29 PM

Thanks again. This is a new TDSSKILLER run log. The combofix log is from a run when the problem began. I'll run another, if you like. I'm going to be out of town for two weeks starting this Friday, so if we don't have it wrapped up by then, I may need a hiatus. Thanks.
Eldon




ComboFix 11-04-16.01 - Eldon DeKay 04/18/2011 22:23:05.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3072.2293 [GMT -8:00]
Running from: c:\users\Eldon DeKay\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-19 to 2011-04-19 )))))))))))))))))))))))))))))))
.
.
2011-04-19 06:34 . 2011-04-19 06:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-19 06:34 . 2011-04-19 06:34 -------- d-----w- c:\users\Beverly\AppData\Local\temp
2011-04-19 05:27 . 2011-04-19 05:31 -------- d-----w- C:\3dd515ce17b36af7c24eb660538a
2011-04-19 03:39 . 2011-04-19 03:39 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-19 03:36 . 2011-04-19 03:37 -------- d-----w- C:\9321fb5a4beec585a6eb3733
2011-04-19 03:27 . 2010-04-09 07:24 240008 ----a-w- c:\windows\system32\drivers\netio.sys
2011-04-18 19:51 . 2011-04-19 06:07 12872 ----a-w- c:\windows\system32\bootdelete.exe
2011-04-18 14:27 . 2011-04-19 05:52 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-04-18 14:27 . 2011-04-18 19:51 -------- d-----w- c:\programdata\Hitman Pro
2011-04-17 13:05 . 2011-04-17 13:05 -------- d-----w- c:\program files\ESET
2011-04-17 06:12 . 2011-04-17 06:12 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-04-17 06:04 . 2011-04-17 06:04 -------- d-----w- c:\program files\Common Files\Java
2011-04-17 05:07 . 2011-04-19 06:34 -------- d-----w- c:\users\Eldon DeKay\AppData\Local\temp
2011-04-16 20:00 . 2011-03-03 03:31 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-04-16 20:00 . 2011-02-12 05:30 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-16 20:00 . 2011-03-08 05:38 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-16 20:00 . 2011-03-11 05:40 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-16 20:00 . 2011-03-11 05:40 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-16 20:00 . 2011-02-23 05:05 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-16 20:00 . 2011-02-23 05:05 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-16 20:00 . 2011-02-23 05:05 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-16 20:00 . 2011-02-23 05:05 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-06 16:55 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4B199828-FAF8-4A83-8434-87D9999C5661}\mpengine.dll
2011-04-06 14:04 . 2011-04-06 14:04 -------- d-----w- c:\users\Eldon DeKay\AppData\Roaming\DiskAid
2011-04-05 14:30 . 2011-04-18 03:41 -------- d-----w- c:\users\Eldon DeKay\Audiobooks
2011-04-05 14:28 . 2011-04-05 14:28 -------- d-----w- c:\users\Eldon DeKay\AppData\Roaming\MP3toiPodAudioBookConverter
2011-04-05 14:27 . 2011-04-05 14:27 -------- d-----w- c:\program files\MP3ToIpodAudioBookConverter
2011-04-02 05:57 . 2011-04-02 05:57 -------- d-----w- C:\alfred
2011-04-02 05:42 . 2011-04-02 05:42 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-04-01 15:24 . 2011-04-01 15:24 90112 --sha-r- c:\windows\system32\CTSBASWL.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-17 06:03 . 2010-07-10 14:30 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-03 02:11 . 2009-11-27 06:09 222080 ------w- c:\windows\system32\MpSigStub.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-11-30 17:01 66144 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Device Detector"="DevDetect.exe -autorun" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2007-04-09 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-04-09 19968]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-12 1468256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-2-28 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2005-11-15 86016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Ask and Record FLV Service"="c:\program files\Replay Media Catcher\FLVSrvc.exe" /run
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-27 721904]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-27 1153368]
R3 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-02-02 317440]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-18 84832]
R3 gupdate1c98f16c5d54266;Google Update Service (gupdate1c98f16c5d54266);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 133104]
R3 InnoMIO;InnoMIO;c:\windows\system32\Drivers\IWMIO.sys [x]
R3 iTurns;iTurns; [x]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NDISKIO;NDISKIO;c:\users\ELDOND~1\AppData\Local\Temp\00000431.nmc\nse\bin\ndiskio.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 pbfilter;pbfilter;c:\program files\Peerblock\pbfilter.sys [2009-09-28 16472]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Professional Business 2009\RpcAgentSrv.exe [2008-09-02 98488]
R3 SMServer;SMServer;c:\windows\system32\snmvtsvc.exe [2009-07-14 245760]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2008-10-21 548864]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-11 1343400]
R4 ntrconnect;ntrconnect;c:\program files\NTR global\NTRconnect\NTRconnect.exe [2008-10-29 89600]
S0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2010-02-16 40560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-02-05 51792]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2010-11-26 83696]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2006-11-22 5120]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2008-11-14 17184]
S2 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2010-03-11 35200]
S3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2007-10-26 18840]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2009-11-12 22384]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPFILTER
*Deregistered* - avgntflt
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-19 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-01-14 21:09]
.
2011-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ca574754e2ba80.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 02:40]
.
2011-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 02:40]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3243215932-1131571249-2604786237-1000Core.job
- c:\users\Eldon DeKay\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-06 21:41]
.
2011-04-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3243215932-1131571249-2604786237-1000UA.job
- c:\users\Eldon DeKay\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-06 21:41]
.
.
------- Supplementary Scan -------
.
uLocal Page =
uStart Page = hxxp://www.google.com/
mLocal Page =
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
TCP: {8645EBA2-9680-4A41-A4DC-F3A31E0F63AA} = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\users\Eldon DeKay\AppData\Roaming\Mozilla\Firefox\Profiles\sml57h2q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/webhp?rls=ig
FF - Ext: Cooliris: piclens@cooliris.com - %profile%\extensions\piclens@cooliris.com
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: CoolPreviews : {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} - %profile%\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: AutoPager: autopager@mozilla.org - %profile%\extensions\autopager@mozilla.org
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: IDM CC: mozilla_cc@internetdownloadmanager.com - c:\users\Eldon DeKay\AppData\Roaming\IDM\idmmzcc3
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3243215932-1131571249-2604786237-1000_Classes\CLSID\{43486b1e-8330-49e0-ae35-61005c0e89fd}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000089
"Therad"=dword:00000015
.
[HKEY_USERS\S-1-5-21-3243215932-1131571249-2604786237-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):15,9c,f7,10,eb,51,4c,9a,9e,43,3a,9e,83,2a,2d,67,4a,b1,21,df,06,
c3,ce,cb,80,ae,98,7f,d0,40,81,14,eb,3b,ab,30,7d,81,cd,59,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-04-18 22:37:23
ComboFix-quarantined-files.txt 2011-04-19 06:37
ComboFix2.txt 2011-04-17 05:07
.
Pre-Run: 157,911,027,712 bytes free
Post-Run: 157,870,792,704 bytes free
.
- - End Of File - - A39FFD986E8CE5E4FA12947E2AC28BF4













2011/05/02 13:52:32.0193 66312 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/05/02 13:52:33.0117 66312 ================================================================================
2011/05/02 13:52:33.0117 66312 SystemInfo:
2011/05/02 13:52:33.0117 66312
2011/05/02 13:52:33.0117 66312 OS Version: 6.1.7600 ServicePack: 0.0
2011/05/02 13:52:33.0117 66312 Product type: Workstation
2011/05/02 13:52:33.0117 66312 ComputerName: ELDONDEKAY
2011/05/02 13:52:33.0117 66312 UserName: Eldon DeKay
2011/05/02 13:52:33.0117 66312 Windows directory: C:\Windows
2011/05/02 13:52:33.0117 66312 System windows directory: C:\Windows
2011/05/02 13:52:33.0117 66312 Processor architecture: Intel x86
2011/05/02 13:52:33.0117 66312 Number of processors: 2
2011/05/02 13:52:33.0117 66312 Page size: 0x1000
2011/05/02 13:52:33.0117 66312 Boot type: Normal boot
2011/05/02 13:52:33.0117 66312 ================================================================================
2011/05/02 13:52:40.0180 66312 Initialize success
2011/05/02 13:53:00.0441 64772 ================================================================================
2011/05/02 13:53:00.0441 64772 Scan started
2011/05/02 13:53:00.0441 64772 Mode: Manual;
2011/05/02 13:53:00.0441 64772 ================================================================================
2011/05/02 13:53:03.0397 64772 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
2011/05/02 13:53:03.0612 64772 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
2011/05/02 13:53:03.0784 64772 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
2011/05/02 13:53:03.0939 64772 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
2011/05/02 13:53:04.0095 64772 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
2011/05/02 13:53:04.0225 64772 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
2011/05/02 13:53:04.0468 64772 Afc (fe3ea6e9afc1a78e6edca121e006afb7) C:\Windows\system32\drivers\Afc.sys
2011/05/02 13:53:04.0682 64772 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
2011/05/02 13:53:04.0806 64772 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
2011/05/02 13:53:04.0981 64772 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
2011/05/02 13:53:05.0164 64772 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
2011/05/02 13:53:05.0328 64772 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
2011/05/02 13:53:05.0504 64772 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
2011/05/02 13:53:05.0691 64772 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
2011/05/02 13:53:05.0861 64772 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
2011/05/02 13:53:05.0914 64772 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
2011/05/02 13:53:06.0074 64772 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
2011/05/02 13:53:06.0240 64772 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
2011/05/02 13:53:06.0435 64772 AnyDVD (b8f9d3ae038810c6ea08e123cada765e) C:\Windows\system32\Drivers\AnyDVD.sys
2011/05/02 13:53:06.0661 64772 APLMp50 (1bf91f352d746ad7469fa71783b5fae8) C:\Windows\system32\Drivers\APLMp50.sys
2011/05/02 13:53:06.0923 64772 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
2011/05/02 13:53:07.0138 64772 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
2011/05/02 13:53:07.0290 64772 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
2011/05/02 13:53:07.0597 64772 ASPI (e54e27976e2c5a6465d44c10b1d87ac0) C:\Windows\System32\DRIVERS\ASPI32.sys
2011/05/02 13:53:07.0814 64772 aswMonFlt (3532945daccba83c63a4379eb44b2859) C:\Windows\system32\DRIVERS\aswMonFlt.sys
2011/05/02 13:53:08.0029 64772 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/02 13:53:08.0173 64772 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
2011/05/02 13:53:08.0442 64772 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
2011/05/02 13:53:08.0554 64772 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/05/02 13:53:08.0757 64772 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
2011/05/02 13:53:08.0898 64772 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
2011/05/02 13:53:09.0098 64772 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/02 13:53:09.0313 64772 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2011/05/02 13:53:09.0455 64772 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2011/05/02 13:53:09.0641 64772 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
2011/05/02 13:53:09.0761 64772 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
2011/05/02 13:53:09.0940 64772 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
2011/05/02 13:53:10.0020 64772 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
2011/05/02 13:53:10.0152 64772 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
2011/05/02 13:53:10.0655 64772 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/02 13:53:10.0825 64772 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/02 13:53:10.0974 64772 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
2011/05/02 13:53:11.0215 64772 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
2011/05/02 13:53:11.0480 64772 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/05/02 13:53:11.0651 64772 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
2011/05/02 13:53:11.0847 64772 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
2011/05/02 13:53:12.0058 64772 COMMONFX.DLL (1ef05b641e9a67ded74ac8ad40055dbf) C:\Windows\system32\COMMONFX.DLL
2011/05/02 13:53:12.0225 64772 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
2011/05/02 13:53:12.0377 64772 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
2011/05/02 13:53:12.0520 64772 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
2011/05/02 13:53:12.0790 64772 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
2011/05/02 13:53:12.0989 64772 CT20XUT.DLL (6191a973461852a09d643609e1d5f7c6) C:\Windows\system32\CT20XUT.DLL
2011/05/02 13:53:13.0187 64772 ctac32k (8ac5f77e30e37d2d11bd99eff0c53d8c) C:\Windows\system32\drivers\ctac32k.sys
2011/05/02 13:53:13.0461 64772 ctaud2k (673241d314e932f4890509ae8ebf26db) C:\Windows\system32\drivers\ctaud2k.sys
2011/05/02 13:53:13.0852 64772 CTAUDFX.DLL (472b82d7e549e7fab428852e4d16f21d) C:\Windows\system32\CTAUDFX.DLL
2011/05/02 13:53:14.0235 64772 ctdvda2k (ed316d4c3d39c5b6c23de067e275c183) C:\Windows\system32\drivers\ctdvda2k.sys
2011/05/02 13:53:14.0440 64772 CTEAPSFX.DLL (6a57f82009563aee8826f117e1d3c72c) C:\Windows\system32\CTEAPSFX.DLL
2011/05/02 13:53:14.0529 64772 CTEDSPFX.DLL (c8ac1ffaeadd655193d7b1811a572d8d) C:\Windows\system32\CTEDSPFX.DLL
2011/05/02 13:53:14.0638 64772 CTEDSPIO.DLL (44495d9daf675257d00b25b041ee6667) C:\Windows\system32\CTEDSPIO.DLL
2011/05/02 13:53:14.0792 64772 CTEDSPSY.DLL (8e90b1762cb42e2fc76dac9210c83c66) C:\Windows\system32\CTEDSPSY.DLL
2011/05/02 13:53:14.0932 64772 CTERFXFX.DLL (d3fbd9983325435b06795f29cb57ed3d) C:\Windows\system32\CTERFXFX.DLL
2011/05/02 13:53:15.0173 64772 CTEXFIFX.DLL (2c48e9d8ca703964463f27ae341115b7) C:\Windows\system32\CTEXFIFX.DLL
2011/05/02 13:53:15.0318 64772 ctgame (890681ece9d335911746b128616212fe) C:\Windows\system32\DRIVERS\ctgame.sys
2011/05/02 13:53:15.0502 64772 CTHWIUT.DLL (f7657c598e7c29c6683c1e4a8dd68884) C:\Windows\system32\CTHWIUT.DLL
2011/05/02 13:53:15.0754 64772 ctprxy2k (34e7f8a499fd8361df14fedb724c0ad3) C:\Windows\system32\drivers\ctprxy2k.sys
2011/05/02 13:53:15.0897 64772 CTSBLFX.DLL (679ae21eb7f48a08184813aebabdec7c) C:\Windows\system32\CTSBLFX.DLL
2011/05/02 13:53:16.0044 64772 ctsfm2k (32098497cb4dfe9ea7660fa62dd91060) C:\Windows\system32\drivers\ctsfm2k.sys
2011/05/02 13:53:16.0295 64772 dc3d (35a296350649c7f490d3e2a3647445ba) C:\Windows\system32\DRIVERS\dc3d.sys
2011/05/02 13:53:16.0558 64772 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
2011/05/02 13:53:16.0784 64772 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
2011/05/02 13:53:16.0906 64772 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
2011/05/02 13:53:17.0197 64772 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
2011/05/02 13:53:17.0416 64772 DXGKrnl (c94b6c3cc628179cb9b9061c19888b99) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/02 13:53:17.0721 64772 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
2011/05/02 13:53:17.0949 64772 ElbyCDIO (44996a2addd2db7454f2ca40b67d8941) C:\Windows\system32\Drivers\ElbyCDIO.sys
2011/05/02 13:53:18.0171 64772 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
2011/05/02 13:53:18.0391 64772 emupia (2885f72d2daffd0329272f12e16d6579) C:\Windows\system32\drivers\emupia2k.sys
2011/05/02 13:53:18.0572 64772 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
2011/05/02 13:53:18.0699 64772 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
2011/05/02 13:53:18.0860 64772 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
2011/05/02 13:53:19.0332 64772 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/02 13:53:19.0592 64772 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
2011/05/02 13:53:19.0769 64772 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
2011/05/02 13:53:20.0000 64772 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/02 13:53:20.0228 64772 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
2011/05/02 13:53:20.0399 64772 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
2011/05/02 13:53:20.0633 64772 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/02 13:53:20.0798 64772 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys
2011/05/02 13:53:20.0904 64772 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
2011/05/02 13:53:21.0239 64772 ha10kx2k (da2c735b66d2e7b739f9a46146581a9d) C:\Windows\system32\drivers\ha10kx2k.sys
2011/05/02 13:53:21.0430 64772 hamachi (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys
2011/05/02 13:53:21.0559 64772 hap16v2k (5c7d6d68796e4621b4168c879908dae0) C:\Windows\system32\drivers\hap16v2k.sys
2011/05/02 13:53:21.0674 64772 hap17v2k (a595b88ad16d8b5693ddf08113caf30e) C:\Windows\system32\drivers\hap17v2k.sys
2011/05/02 13:53:21.0835 64772 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
2011/05/02 13:53:21.0988 64772 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/02 13:53:22.0116 64772 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
2011/05/02 13:53:22.0287 64772 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
2011/05/02 13:53:22.0402 64772 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
2011/05/02 13:53:22.0533 64772 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/02 13:53:22.0629 64772 hotcore3 (1f6599e68de2d3c46f4c096d9706ba7c) C:\Windows\system32\drivers\hotcore3.sys
2011/05/02 13:53:22.0774 64772 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
2011/05/02 13:53:22.0921 64772 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
2011/05/02 13:53:23.0079 64772 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
2011/05/02 13:53:23.0204 64772 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/02 13:53:23.0395 64772 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
2011/05/02 13:53:23.0645 64772 IDMWFP (8f504e0e8010b2419a6b8fab75afd02f) C:\Windows\system32\DRIVERS\idmwfp.sys
2011/05/02 13:53:23.0891 64772 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
2011/05/02 13:53:24.0105 64772 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
2011/05/02 13:53:24.0234 64772 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/02 13:53:24.0481 64772 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/02 13:53:24.0822 64772 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2011/05/02 13:53:24.0996 64772 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
2011/05/02 13:53:25.0143 64772 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
2011/05/02 13:53:25.0323 64772 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
2011/05/02 13:53:25.0486 64772 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/02 13:53:25.0670 64772 iTurns (0888d59ea42532ab68810608acd6cf8a) C:\Windows\system32\drivers\iTurns.sys
2011/05/02 13:53:25.0927 64772 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/02 13:53:26.0082 64772 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/02 13:53:26.0259 64772 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/02 13:53:26.0459 64772 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
2011/05/02 13:53:26.0749 64772 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/02 13:53:26.0903 64772 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
2011/05/02 13:53:27.0010 64772 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
2011/05/02 13:53:27.0141 64772 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2011/05/02 13:53:27.0361 64772 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2011/05/02 13:53:27.0597 64772 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
2011/05/02 13:53:27.0759 64772 MBAMProtector (836e0e09ca9869be7eb39ef2cf3602c7) C:\Windows\system32\drivers\mbam.sys
2011/05/02 13:53:27.0894 64772 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
2011/05/02 13:53:28.0061 64772 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
2011/05/02 13:53:28.0265 64772 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
2011/05/02 13:53:28.0435 64772 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/02 13:53:28.0554 64772 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/02 13:53:28.0714 64772 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/02 13:53:28.0932 64772 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
2011/05/02 13:53:29.0068 64772 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
2011/05/02 13:53:29.0253 64772 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/02 13:53:29.0406 64772 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
2011/05/02 13:53:29.0652 64772 mrxsmb (b4c76ef46322a9711c7b0f4e21ef6ea5) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/02 13:53:30.0042 64772 mrxsmb10 (e593d45024a3fdd11e93cc4a6ca91101) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/02 13:53:30.0186 64772 mrxsmb20 (a9f86c82c9cc3b679cc3957e1183a30f) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/02 13:53:30.0356 64772 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
2011/05/02 13:53:30.0507 64772 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
2011/05/02 13:53:30.0692 64772 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
2011/05/02 13:53:30.0842 64772 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
2011/05/02 13:53:30.0980 64772 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
2011/05/02 13:53:31.0114 64772 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/02 13:53:31.0340 64772 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/02 13:53:31.0569 64772 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
2011/05/02 13:53:31.0811 64772 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
2011/05/02 13:53:31.0964 64772 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/02 13:53:32.0185 64772 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
2011/05/02 13:53:32.0339 64772 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
2011/05/02 13:53:32.0574 64772 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
2011/05/02 13:53:32.0689 64772 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/02 13:53:32.0823 64772 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
2011/05/02 13:53:32.0928 64772 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
2011/05/02 13:53:33.0328 64772 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/02 13:53:33.0450 64772 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/02 13:53:33.0550 64772 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/02 13:53:33.0623 64772 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
2011/05/02 13:53:33.0738 64772 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/02 13:53:33.0901 64772 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/02 13:53:34.0188 64772 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
2011/05/02 13:53:34.0377 64772 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
2011/05/02 13:53:34.0558 64772 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/02 13:53:34.0794 64772 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
2011/05/02 13:53:35.0020 64772 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys
2011/05/02 13:53:35.0208 64772 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
2011/05/02 13:53:35.0526 64772 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys
2011/05/02 13:53:36.0087 64772 nvlddmkm (b0881dda5a8160422561ffab7f0008b1) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2011/05/02 13:53:36.0486 64772 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
2011/05/02 13:53:36.0724 64772 nvrd32 (ca4cceff1d43f48a289536451fd39d04) C:\Windows\system32\DRIVERS\nvrd32.sys
2011/05/02 13:53:36.0846 64772 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
2011/05/02 13:53:36.0952 64772 nvstor32 (f2d7ccd75132f19119108e07a4fd0a12) C:\Windows\system32\DRIVERS\nvstor32.sys
2011/05/02 13:53:37.0069 64772 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
2011/05/02 13:53:37.0293 64772 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/02 13:53:37.0539 64772 ossrv (61c85afeaa6ef0c1b32d43f84f7bfbcf) C:\Windows\system32\drivers\ctoss2k.sys
2011/05/02 13:53:37.0745 64772 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
2011/05/02 13:53:37.0908 64772 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
2011/05/02 13:53:38.0138 64772 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
2011/05/02 13:53:38.0286 64772 pbfilter (4dfe4cef1aeec1025380d7ebf40e8e2b) C:\Program Files\Peerblock\pbfilter.sys
2011/05/02 13:53:38.0514 64772 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
2011/05/02 13:53:38.0719 64772 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
2011/05/02 13:53:38.0856 64772 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/05/02 13:53:39.0083 64772 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\Windows\system32\Drivers\pcouffin.sys
2011/05/02 13:53:39.0233 64772 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
2011/05/02 13:53:39.0416 64772 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
2011/05/02 13:53:39.0609 64772 pfc (957b82ec80ad7ead64e5e47df6b0dc40) C:\Windows\system32\drivers\pfc.sys
2011/05/02 13:53:39.0878 64772 Point32 (04df0452fbededf9297fd2e5440cb3c9) C:\Windows\system32\DRIVERS\point32k.sys
2011/05/02 13:53:40.0107 64772 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/02 13:53:40.0567 64772 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
2011/05/02 13:53:40.0801 64772 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/02 13:53:41.0058 64772 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\Windows\system32\Drivers\PxHelp20.sys
2011/05/02 13:53:41.0217 64772 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
2011/05/02 13:53:41.0392 64772 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
2011/05/02 13:53:41.0584 64772 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/02 13:53:41.0752 64772 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/02 13:53:41.0974 64772 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
2011/05/02 13:53:42.0169 64772 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/02 13:53:42.0352 64772 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/02 13:53:42.0513 64772 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/02 13:53:42.0675 64772 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/02 13:53:42.0827 64772 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
2011/05/02 13:53:42.0986 64772 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/02 13:53:43.0233 64772 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
2011/05/02 13:53:43.0502 64772 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/02 13:53:43.0723 64772 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
2011/05/02 13:53:43.0970 64772 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
2011/05/02 13:53:44.0184 64772 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
2011/05/02 13:53:44.0484 64772 Revoflt (b9bb8e2093c1615ad6ea55ad96214354) C:\Windows\system32\DRIVERS\revoflt.sys
2011/05/02 13:53:44.0758 64772 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/02 13:53:45.0010 64772 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
2011/05/02 13:53:45.0259 64772 SANDRA (a9fdd67fd92006b3ee89449ffaa0cd53) C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009\WNt500x86\Sandra.sys
2011/05/02 13:53:45.0631 64772 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
2011/05/02 13:53:45.0817 64772 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
2011/05/02 13:53:45.0990 64772 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/05/02 13:53:46.0233 64772 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
2011/05/02 13:53:46.0336 64772 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
2011/05/02 13:53:46.0474 64772 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
2011/05/02 13:53:46.0672 64772 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
2011/05/02 13:53:46.0789 64772 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2011/05/02 13:53:46.0956 64772 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
2011/05/02 13:53:47.0162 64772 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
2011/05/02 13:53:47.0346 64772 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
2011/05/02 13:53:47.0562 64772 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2011/05/02 13:53:47.0702 64772 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
2011/05/02 13:53:47.0911 64772 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
2011/05/02 13:53:48.0040 64772 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
2011/05/02 13:53:48.0309 64772 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\Windows\System32\Drivers\sptd.sys
2011/05/02 13:53:48.0582 64772 srv (4a9b0f215de2519e2363f91df25c1e97) C:\Windows\system32\DRIVERS\srv.sys
2011/05/02 13:53:48.0769 64772 srv2 (14c44875518ae1c982e54ea8c5f7fe28) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/02 13:53:48.0927 64772 srvnet (07a14223b0a50e76ade003fdf95d4fec) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/02 13:53:49.0170 64772 SSPORT (5f77725ec309de1242d8efc8e9259a9f) C:\Windows\system32\Drivers\SSPORT.sys
2011/05/02 13:53:49.0381 64772 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
2011/05/02 13:53:49.0604 64772 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
2011/05/02 13:53:49.0758 64772 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
2011/05/02 13:53:49.0984 64772 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/02 13:53:50.0350 64772 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\drivers\tcpip.sys
2011/05/02 13:53:50.0550 64772 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/02 13:53:50.0746 64772 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/02 13:53:50.0880 64772 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
2011/05/02 13:53:51.0003 64772 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
2011/05/02 13:53:51.0130 64772 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/02 13:53:51.0279 64772 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/02 13:53:51.0518 64772 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/02 13:53:51.0642 64772 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/02 13:53:51.0863 64772 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
2011/05/02 13:53:52.0015 64772 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/02 13:53:52.0211 64772 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
2011/05/02 13:53:52.0486 64772 UltraMonUtility (5a5bd0f66e84eb039cb227520d49908c) C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys
2011/05/02 13:53:52.0720 64772 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/02 13:53:52.0875 64772 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
2011/05/02 13:53:53.0098 64772 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\Windows\system32\Drivers\usbaapl.sys
2011/05/02 13:53:53.0310 64772 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/02 13:53:53.0511 64772 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
2011/05/02 13:53:53.0655 64772 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/02 13:53:53.0784 64772 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/02 13:53:53.0937 64772 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
2011/05/02 13:53:54.0091 64772 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/02 13:53:54.0243 64772 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/02 13:53:54.0412 64772 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/02 13:53:54.0509 64772 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
2011/05/02 13:53:54.0630 64772 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/02 13:53:54.0681 64772 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
2011/05/02 13:53:54.0838 64772 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
2011/05/02 13:53:54.0979 64772 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
2011/05/02 13:53:55.0113 64772 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
2011/05/02 13:53:55.0272 64772 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
2011/05/02 13:53:55.0449 64772 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
2011/05/02 13:53:55.0632 64772 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
2011/05/02 13:53:55.0797 64772 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
2011/05/02 13:53:56.0023 64772 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
2011/05/02 13:53:56.0157 64772 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
2011/05/02 13:53:56.0391 64772 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
2011/05/02 13:53:56.0547 64772 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
2011/05/02 13:53:56.0685 64772 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
2011/05/02 13:53:56.0782 64772 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/02 13:53:56.0854 64772 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/02 13:53:57.0064 64772 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
2011/05/02 13:53:57.0266 64772 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/02 13:53:57.0464 64772 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
2011/05/02 13:53:57.0701 64772 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
2011/05/02 13:53:57.0927 64772 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
2011/05/02 13:53:58.0094 64772 WMDrive (50557ed84a2696e96c1837183892738e) C:\Windows\system32\drivers\WMDrive.sys
2011/05/02 13:53:58.0258 64772 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/05/02 13:53:58.0495 64772 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/02 13:53:58.0645 64772 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
2011/05/02 13:53:58.0762 64772 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/02 13:53:58.0886 64772 ================================================================================
2011/05/02 13:53:58.0886 64772 Scan finished
2011/05/02 13:53:58.0886 64772 ================================================================================

#6 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,779 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:04:12 PM

Posted 03 May 2011 - 09:53 AM

Hi,

no those logs are fine, I just wanted to know what, if at all, was deleted by the tools.

Please run a scan with aswMBR next:
Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#7 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 03 May 2011 - 03:12 PM

OK. Here's the aswMBR log. Thanks again.


aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-03 12:03:16
-----------------------------
12:03:16.597 OS Version: Windows 6.1.7600
12:03:16.598 Number of processors: 2 586 0x4B02
12:03:16.602 ComputerName: ELDONDEKAY UserName:
12:03:24.782 Initialize success
12:03:36.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007c
12:03:36.175 Disk 0 Vendor: NVIDIA__ Size: 715404MB BusType: 8
12:03:38.212 Disk 0 MBR read successfully
12:03:38.215 Disk 0 MBR scan
12:03:38.219 Disk 0 Windows 7 default MBR code
12:03:40.223 Disk 0 scanning sectors +1465145344
12:03:40.300 Disk 0 scanning C:\Windows\system32\drivers
12:04:01.117 Service scanning
12:04:02.432 Disk 0 trace - called modules:
12:04:02.471 ntkrnlpa.exe CLASSPNP.SYS disk.sys nvraid.sys halmacpi.dll ACPI.sys storport.sys nvstor.sys
12:04:02.476 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x867ba8e8]
12:04:02.480 3 CLASSPNP.SYS[8b30a59e] -> nt!IofCallDriver -> \Device\0000007c[0x866e4d68]
12:04:02.485 5 nvraid.sys[8b2f1ccb] -> nt!IofCallDriver -> [0x857be750]
12:04:02.491 7 ACPI.sys[8b2203b2] -> nt!IofCallDriver -> \Device\00000078[0x860af8f8]
12:04:02.500 Scan finished successfully
12:04:49.026 Disk 0 MBR has been saved successfully to "C:\Users\Eldon DeKay\Desktop\MBR.dat"
12:04:49.034 The log file has been saved successfully to "C:\Users\Eldon DeKay\Desktop\aswMBR.txt"

#8 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,779 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:04:12 PM

Posted 03 May 2011 - 04:51 PM

Hi,

just to verify you are still getting redirected?

Do you use a router?

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#9 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 03 May 2011 - 08:53 PM

Funny you should ask....
I tried several searches on the instance of Firefox that has been running for several days and no redirects. I restarted Firefox and every Google entry is redirected. Malwarebytes does catch some, but the link is killed and though the redirect doesn't happen, I don't get to the linked page either.

I am using a router which is password protected. 6 other computers are on the same network and have no redirection.

It is annoying that I can't start the Security Service or Defender either. Early on, I thought it might be a permissions problem, so I used a MS tool and reset all permissions to default and then reallocated them. There is a login password for the computer and the shared drives require a password and the permissions on all computers are set for my Username only with my password.

When the original infection occurred, I found several processes that were running that were no kosher, so I traced them back to the exe's and dll's that were generating them and deleted them all,as well as references to them in the registry. Several other malware were found in files not in use and all were deleted. Every tool I have run for a week or so has come up clean.

Thanks again for your help.
Eldon

#10 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,779 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:04:12 PM

Posted 04 May 2011 - 03:59 AM

Hi,

ok that sounds like we still have some residues.

Do you use a router?

reagrds myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#11 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 04 May 2011 - 07:59 AM

I am using a router which is password protected. 6 other computers are on the same network and have no redirection.
Eldon

#12 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,779 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:04:12 PM

Posted 04 May 2011 - 09:08 AM

Hi,

I'm not really seeing the cause at the moment. But I think we can rule out the router.

Do you only get redirected on Firefox or also on other browser?

what is the exact error message you get when you try to start the security center service?

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

 

Follow BleepingComputer on: Facebook | Twitter | Google+


#13 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 04 May 2011 - 09:32 AM

IE9 and Firefox get redirected. Opera and Chrome do not.

Security Center: No error. It is disabled. I enable it to manual, automatic, or delayed start and apply, it starts. Within 45 seconds, it is disabled again.


Windows defender won't start. The error is: The Windows Defender service on Local Computer started and then stopped. some services stop automatically if they are not in use by other services or programs.

Eldon

#14 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 04 May 2011 - 09:35 AM

During the short time Security Center is running, the icon message says I need antivirus (Malwarebytes is running), then it says that Security Service is stopped, click here to start. Click. Action Center flag says :The Windows Security Center service can't be started.

#15 Smedlow

Smedlow
  • Topic Starter

  • Members
  • 40 posts
  • OFFLINE
  •  
  • Local time:05:12 AM

Posted 05 May 2011 - 11:34 PM

Myrti,

I will be out of town and away from my computer till about May 21, starting tomorrow, May 6. I hope I won't lose my place in line and that, if it is OK with you, if I PM you when I return and we can pick up where we left off. The computer will be off, so I guess nothing will propagate in my absence. Thanks for your help.
Eldon




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users