<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Virtual Dr Forums-Computer Tech Support - Intensive Care Unit</title>
		<link>http://discussions.virtualdr.com/</link>
		<description><![CDATA[Already have an infection? We'll help you cure it. Removal of all types of malware]]></description>
		<language>en</language>
		<lastBuildDate>Thu, 23 May 2013 23:58:26 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://discussions.virtualdr.com/images/misc/rss.png</url>
			<title>Virtual Dr Forums-Computer Tech Support - Intensive Care Unit</title>
			<link>http://discussions.virtualdr.com/</link>
		</image>
		<item>
			<title>trojans</title>
			<link>http://discussions.virtualdr.com/showthread.php?257021-trojans&amp;goto=newpost</link>
			<pubDate>Thu, 23 May 2013 01:19:15 GMT</pubDate>
			<description><![CDATA[I am on a Toshiba Laptop with Windows 7. I use I.E.10 but do have Firefox installed. This laptop is mainly for my 9 and 7 year old grandsons to play games on and go to You Tube. About a week ago, I updated everything on the administrator profile, then went to John's profile and did the same. When I...]]></description>
			<content:encoded><![CDATA[<div>I am on a Toshiba Laptop with Windows 7. I use I.E.10 but do have Firefox installed. This laptop is mainly for my 9 and 7 year old grandsons to play games on and go to You Tube. About a week ago, I updated everything on the administrator profile, then went to John's profile and did the same. When I went to Tyler's profile to update, all kinds of problems started happening. When the administrator box popped up to give authorization to update, it would not take the password. Two times when I tried to put the password in, the keys were not working at all and yet letters started to appear as if a ghost was typing them. I immediately deleted them both times and restarted the laptop in safe mode where I proceeded to run a virus scan, a malwarebytes scan and a Superantispyware scan. It found 3 Trojans which I quarantined. It ran a bit better but something still was not right. Tonight, I once again updated everything and ran a scan and it found another Trojan. The common denominator seems to be C:\users\verizon\AppData....That is where all these bad things have been found at. I used to use a Verizon modem when on the road with my husband when he drove truck. We have not used that since August of 2012 and I can not get rid of this file. It is almost like it has taken over my grandson Tyler's profile. I am hoping you can help. Thank you in advance.<br />
<br />
Malwarebytes Anti-Malware 1.75.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.05.22.10<br />
<br />
Windows 7 Service Pack 1 x64 NTFS<br />
Internet Explorer 10.0.9200.16576<br />
Kenny :: LINDA-PC [administrator]<br />
<br />
5/22/2013 8:22:21 PM<br />
MBAM-log-2013-05-22 (20-28-55).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 332010<br />
Time elapsed: 6 minute(s), 13 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 1<br />
C:\Users\verizon\AppData\Local\Temp\Diagnostics\mtqprue.dll (Trojan.Tracur.DL) -&gt; No action taken.<br />
<br />
(end)<br />
<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 10.0.9200.16576  BrowserJavaVersion: 1.6.0_37<br />
Run by Kenny at 20:36:46 on 2013-05-22<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3933.2381 [GMT -4:00]<br />
.<br />
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}<br />
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\windows\system32\lsm.exe<br />
C:\windows\system32\svchost.exe -k DcomLaunch<br />
C:\windows\system32\svchost.exe -k RPCSS<br />
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\windows\system32\svchost.exe -k LocalService<br />
C:\windows\system32\svchost.exe -k netsvcs<br />
C:\windows\system32\svchost.exe -k GPSvcGroup<br />
C:\windows\system32\svchost.exe -k NetworkService<br />
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\windows\System32\spoolsv.exe<br />
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe<br />
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE<br />
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe<br />
C:\windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\ThreatFire\TFService.exe<br />
C:\Windows\system32\TODDSrv.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\windows\system32\SearchIndexer.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\windows\system32\SearchProtocolHost.exe<br />
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe<br />
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\windows\system32\taskhost.exe<br />
C:\windows\system32\Dwm.exe<br />
C:\windows\Explorer.EXE<br />
C:\windows\system32\taskeng.exe<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\windows\system32\igfxsrvc.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe<br />
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe<br />
C:\Program Files\Microsoft IntelliPoint\ipoint.exe<br />
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe<br />
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE<br />
C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe<br />
C:\windows\system32\RunDll32.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\windows\system32\igfxext.exe<br />
C:\windows\system32\taskeng.exe<br />
C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe<br />
C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe<br />
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files (x86)\ThreatFire\TFTray.exe<br />
C:\Program Files (x86)\QuickTime\qttask.exe<br />
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe<br />
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\windows\system32\sppsvc.exe<br />
C:\windows\System32\svchost.exe -k secsvcs<br />
C:\windows\system32\Macromed\Flash\FlashUtil64_11_7_700_202_ActiveX.exe<br />
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
C:\windows\servicing\TrustedInstaller.exe<br />
C:\windows\system32\wuauclt.exe<br />
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br />
C:\windows\system32\SearchFilterHost.exe<br />
C:\windows\system32\svchost.exe -k SDRSVC<br />
C:\windows\system32\wbem\wmiprvse.exe<br />
C:\windows\System32\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://my.yahoo.com/<br />
uDefault_Page_URL = hxxp://start.toshiba.com/?cid=C001B2Y<br />
uURLSearchHooks: {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - &lt;orphaned&gt;<br />
mWinlogon: Userinit = userinit.exe,<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
uRun: [NokiaPCInternetAccess] &quot;C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe&quot; /b<br />
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br />
uRun: [HP Deskjet 3520 series (NET)] &quot;C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe&quot; -deviceID &quot;CN2BL1G47G05SY:NW&quot; -scfn &quot;HP Deskjet 3520 series (NET)&quot; -AutoStart 1<br />
mRun: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
mRun: [HWSetup] &quot;C:\Program Files\TOSHIBA\Utilities\HWSetup.exe&quot; hwSetUP<br />
mRun: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe<br />
mRun: [ToshibaServiceStation] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe&quot; /hide:60<br />
mRun: [Desktop Disc Tool] &quot;C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe&quot;<br />
mRun: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe<br />
mRun: [{ABA99F9A-8FE2-E89A-E99B-E8b85B9AE9B9}] &quot;C:\Program Files (x86)\Alltel Broadband Connect\AvqAutoRun.exe&quot; &quot;C:\Program Files (x86)\Alltel Broadband Connect\mphonetools.exe&quot; /OnPlug=%s<br />
mRun: [QuickTime Task] &quot;C:\Program Files (x86)\QuickTime\qttask.exe&quot; -atboottime<br />
mRun: [avgnt] &quot;C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe&quot; /min<br />
mRun: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
StartupFolder: C:\Users\Kenny\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MONITO~1.LNK - C:\windows\System32\RunDll32.exe<br />
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}<br />
.<br />
INFO: HKCU has more than 50 listed domains.<br />
If you wish to scan all of them, select the 'Force scan all domains' option.<br />
.<br />
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab<br />
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab<br />
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
TCP: NameServer = 209.18.47.61 209.18.47.62<br />
TCP: Interfaces\{28E38AD4-7CC4-4434-A69C-4921B273F172} : DHCPNameServer = 209.18.47.61 209.18.47.62<br />
TCP: Interfaces\{4AAC1865-70C9-4D56-A74C-C1609AA0102E} : DHCPNameServer = 192.168.3.1 24.93.41.125 24.93.41.126<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL<br />
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
x64-Run: [IgfxTray] C:\windows\System32\igfxtray.exe<br />
x64-Run: [HotKeysCmds] C:\windows\System32\hkcmd.exe<br />
x64-Run: [Persistence] C:\windows\System32\igfxpers.exe<br />
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe<br />
x64-Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE<br />
x64-Run: [SmoothView] C:\Program Files (x86)\Toshiba\SmoothView\SmoothView.exe<br />
x64-Run: [00TCrdMain] C:\Program Files (x86)\TOSHIBA\FlashCards\TCrdMain.exe<br />
x64-Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe<br />
x64-Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe<br />
x64-Run: [TosNC] C:\Program Files (x86)\Toshiba\BulletinBoard\TosNcCore.exe<br />
x64-Run: [TosReelTimeMonitor] C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe<br />
x64-Run: [IntelliPoint] &quot;c:\Program Files\Microsoft IntelliPoint\ipoint.exe&quot;<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
x64-Notify: igfxcui - igfxdev.dll<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\Kenny\AppData\Roaming\Mozilla\Firefox\Profiles\1basdnn1.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.usatoday.com/<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll<br />
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\8\NP_wtapp.dll<br />
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll<br />
FF - plugin: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll<br />
FF - plugin: C:\Users\Kenny\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll<br />
FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll<br />
FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll<br />
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll<br />
FF - plugin: C:\windows\SysWOW64\npdeployJava1.dll<br />
FF - plugin: C:\windows\SysWOW64\npmproxy.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 PxHlpa64;PxHlpa64;C:\windows\System32\drivers\PxHlpa64.sys [2010-2-2 55280]<br />
R0 TfFsMon;TfFsMon;C:\windows\System32\drivers\TfFsMon.sys [2010-3-8 65072]<br />
R0 TfSysMon;TfSysMon;C:\windows\System32\drivers\TfSysMon.sys [2010-3-8 59880]<br />
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\System32\drivers\tos_sps64.sys [2010-2-2 482384]<br />
R1 avkmgr;avkmgr;C:\windows\System32\drivers\avkmgr.sys [2013-3-28 28600]<br />
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]<br />
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]<br />
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]<br />
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-10-12 86752]<br />
R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-10-12 110816]<br />
R2 avgntflt;avgntflt;C:\windows\System32\drivers\avgntflt.sys [2013-3-28 100712]<br />
R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFIWmxSvcs64.exe [2009-8-10 248688]<br />
R2 ConfigFree Gadget Service;ConfigFree Gadget Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe [2009-7-14 42368]<br />
R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe [2009-3-10 46448]<br />
R2 ThreatFire;ThreatFire;C:\Program Files (x86)\ThreatFire\TFService.exe service --&gt; C:\Program Files (x86)\ThreatFire\TFService.exe service [?]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2010-6-23 344680]<br />
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\windows\System32\drivers\RTL8187B.sys [2010-3-31 450048]<br />
R3 TfNetMon;TfNetMon;C:\windows\System32\drivers\TfNetMon.sys [2010-3-8 41888]<br />
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2010-2-2 54136]<br />
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-9-17 137560]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S3 bcm;WiMAX Network Adapter;C:\windows\System32\drivers\drxvi314_64.sys [2010-2-11 359040]<br />
S3 bcmbusctr;WiMAX Bus Driver;C:\windows\System32\drivers\BcmBusCtr_64.sys [2010-2-11 62976]<br />
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]<br />
S3 NWUSBCDFIL64;Novatel Wireless Installation CD;C:\windows\System32\drivers\NwUsbCdFil64.sys [2010-5-16 25600]<br />
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;C:\windows\System32\drivers\nwusbser2.sys [2010-5-16 213376]<br />
S3 PTDLBus;PANTECH UM175AL Composite Device Driver;C:\windows\System32\drivers\PTDLBus.sys [2010-3-9 66304]<br />
S3 PTDLMdm;PANTECH UM175AL Drivers;C:\windows\System32\drivers\PTDLMdm.sys [2010-3-9 70784]<br />
S3 PTDLVsp;PANTECH UM175AL Diagnostic Port;C:\windows\System32\drivers\PTDLVsp.sys [2010-3-9 66688]<br />
S3 PTDLWWAN;PANTECH UM175AL WWAN Driver;C:\windows\System32\drivers\PTDLWWAN.sys [2010-3-9 84480]<br />
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2012-11-2 19456]<br />
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\System32\drivers\RtsUStor.sys [2010-2-2 222208]<br />
S3 SASENUM;SASENUM;C:\Program Files (x86)\SUPERAntiSpyware\SASENUM.SYS [2010-2-17 12872]<br />
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2012-11-2 57856]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2010-3-8 1255736]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-22 23:51:04	76232	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DDC91698-DC14-4D6F-856E-3633BF4FFF04}\offreg.dll<br />
2013-05-22 23:44:24	9460464	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DDC91698-DC14-4D6F-856E-3633BF4FFF04}\mpengine.dll<br />
2013-05-17 23:10:41	983400	----a-w-	C:\windows\System32\drivers\dxgkrnl.sys<br />
2013-05-17 23:10:41	265064	----a-w-	C:\windows\System32\drivers\dxgmms1.sys<br />
2013-05-17 23:10:41	144384	----a-w-	C:\windows\System32\cdd.dll<br />
2013-05-17 23:10:36	3153920	----a-w-	C:\windows\System32\win32k.sys<br />
2013-05-17 23:10:18	48640	----a-w-	C:\windows\System32\wwanprotdim.dll<br />
2013-05-17 23:10:18	230400	----a-w-	C:\windows\System32\wwansvc.dll<br />
2013-05-17 23:09:57	1930752	----a-w-	C:\windows\System32\authui.dll<br />
2013-05-17 23:09:56	70144	----a-w-	C:\windows\System32\appinfo.dll<br />
2013-05-17 23:09:56	1796096	----a-w-	C:\windows\SysWow64\authui.dll<br />
2013-05-17 23:09:56	111448	----a-w-	C:\windows\System32\consent.exe<br />
2013-05-09 23:32:40	83160	----a-w-	C:\windows\System32\drivers\avnetflt.sys<br />
2013-04-26 06:04:52	1656680	----a-w-	C:\windows\System32\drivers\ntfs.sys<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-18 02:44:43	71048	----a-w-	C:\windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2013-05-18 02:44:43	692104	----a-w-	C:\windows\SysWow64\FlashPlayerApp.exe<br />
2013-05-02 06:06:08	278800	------w-	C:\windows\System32\MpSigStub.exe<br />
2013-04-13 05:49:23	135168	----a-w-	C:\windows\apppatch\AppPatch64\AcXtrnal.dll<br />
2013-04-13 05:49:19	350208	----a-w-	C:\windows\apppatch\AppPatch64\AcLayers.dll<br />
2013-04-13 05:49:19	308736	----a-w-	C:\windows\apppatch\AppPatch64\AcGenral.dll<br />
2013-04-13 05:49:19	111104	----a-w-	C:\windows\apppatch\AppPatch64\acspecfc.dll<br />
2013-04-13 04:45:16	474624	----a-w-	C:\windows\apppatch\AcSpecfc.dll<br />
2013-04-13 04:45:15	2176512	----a-w-	C:\windows\apppatch\AcGenral.dll<br />
2013-04-05 06:52:14	2242048	----a-w-	C:\windows\System32\wininet.dll<br />
2013-04-05 06:50:36	3958784	----a-w-	C:\windows\System32\jscript9.dll<br />
2013-04-05 06:50:31	67072	----a-w-	C:\windows\System32\iesetup.dll<br />
2013-04-05 06:50:31	136704	----a-w-	C:\windows\System32\iesysprep.dll<br />
2013-04-05 05:28:24	1767424	----a-w-	C:\windows\SysWow64\wininet.dll<br />
2013-04-05 05:26:26	2877440	----a-w-	C:\windows\SysWow64\jscript9.dll<br />
2013-04-05 05:26:21	61440	----a-w-	C:\windows\SysWow64\iesetup.dll<br />
2013-04-05 05:26:21	109056	----a-w-	C:\windows\SysWow64\iesysprep.dll<br />
2013-04-05 04:43:00	2706432	----a-w-	C:\windows\System32\mshtml.tlb<br />
2013-04-05 04:29:45	2706432	----a-w-	C:\windows\SysWow64\mshtml.tlb<br />
2013-04-05 03:51:11	89600	----a-w-	C:\windows\System32\RegisterIEPKEYs.exe<br />
2013-04-05 03:38:25	71680	----a-w-	C:\windows\SysWow64\RegisterIEPKEYs.exe<br />
2013-04-04 18:50:32	25928	----a-w-	C:\windows\System32\drivers\mbam.sys<br />
2013-03-29 00:44:59	28600	----a-w-	C:\windows\System32\drivers\avkmgr.sys<br />
2013-03-29 00:44:59	100712	----a-w-	C:\windows\System32\drivers\avgntflt.sys<br />
2013-03-19 06:04:06	5550424	----a-w-	C:\windows\System32\ntoskrnl.exe<br />
2013-03-19 05:46:56	43520	----a-w-	C:\windows\System32\csrsrv.dll<br />
2013-03-19 05:04:13	3968856	----a-w-	C:\windows\SysWow64\ntkrnlpa.exe<br />
2013-03-19 05:04:10	3913560	----a-w-	C:\windows\SysWow64\ntoskrnl.exe<br />
2013-03-19 04:47:50	6656	----a-w-	C:\windows\SysWow64\apisetschema.dll<br />
2013-03-19 03:06:33	112640	----a-w-	C:\windows\System32\smss.exe<br />
.<br />
============= FINISH: 20:39:35.48 ===============<br />
<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 3/8/2010 3:59:09 PM<br />
System Uptime: 5/22/2013 8:30:19 PM (0 hours ago)<br />
.<br />
Motherboard: TOSHIBA |  | NBWAA<br />
Processor: Pentium(R) Dual-Core CPU       T4400  @ 2.20GHz | U2E1 | 2200/mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 288 GiB total, 226.884 GiB free.<br />
D: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP817: 5/19/2013 7:27:36 AM - Windows Update<br />
RP818: 5/19/2013 9:41:22 AM - Windows Update<br />
RP819: 5/19/2013 2:17:39 PM - Windows Update<br />
RP820: 5/19/2013 4:24:57 PM - Windows Update<br />
RP821: 5/22/2013 7:43:30 PM - Windows Update<br />
RP822: 5/22/2013 7:57:38 PM - Windows Backup<br />
.<br />
==== Installed Programs ======================<br />
.<br />
 Update for Microsoft Office 2007 (KB2508958)<br />
3DVIA player 5.0<br />
Adobe AIR<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Shockwave Player 12.0<br />
Apple Software Update<br />
Auslogics Disk Defrag<br />
Auslogics Registry Cleaner<br />
Avira Free Antivirus<br />
Best Buy pc app<br />
CleanUp!<br />
Compatibility Pack for the 2007 Office system<br />
D3DX10<br />
Dora the Explorer - Swiper's Big Adventure<br />
Final Drive Fury<br />
Final Drive: Nitro<br />
Foxit Reader<br />
Google Earth Plug-in<br />
Google Update Helper<br />
HP Deskjet 3520 series Basic Device Software<br />
HP Deskjet 3520 series Help<br />
HP Deskjet 3520 series Product Improvement Study<br />
HP Deskjet 3520 series Setup Guide<br />
HP FWUpdateEDO2<br />
HP Photo Creations<br />
HP Update<br />
HPDiagnosticAlert<br />
Intel(R) Graphics Media Accelerator Driver<br />
Intelï¿½ Matrix Storage Manager<br />
Internet TV for Windows Media Center<br />
Java Auto Updater<br />
Java(TM) 6 Update 37<br />
Junk Mail filter update<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
Mesh Runtime<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft Application Error Reporting<br />
Microsoft IntelliPoint 8.2<br />
Microsoft Office 2007 Service Pack 3 (SP3)<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office File Validation Add-In<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office Office 64-bit Components 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)<br />
Microsoft Office Shared 64-bit MUI (English) 2007<br />
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Suite Activation Assistant<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570<br />
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219<br />
Microsoft Works<br />
Microsoft WSE 3.0 Runtime<br />
Mozilla Firefox 10.0.2 (x86 en-US)<br />
MSVCRT<br />
MSVCRT_amd64<br />
Nokia PC Internet Access<br />
Pirate101<br />
PlayReady PC Runtime amd64<br />
QuickTime<br />
Realtek 8136 8168 8169 Ethernet Driver<br />
Realtek High Definition Audio Driver<br />
Realtek USB 2.0 Card Reader<br />
Realtek WLAN Driver<br />
Roxio Burn<br />
Roxio Express Labeler 3<br />
Roxio Roxio Burn<br />
Roxio Update Manager<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)<br />
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition<br />
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition <br />
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition <br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition<br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition<br />
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition <br />
Slingo Quest (remove only)<br />
SpywareBlaster 5.0<br />
SUPERAntiSpyware<br />
SUPERAntiSpyware Free Edition<br />
swMSM<br />
Synaptics Pointing Device Driver<br />
ThreatFire<br />
TOSHIBA Application Installer<br />
TOSHIBA Assist<br />
TOSHIBA Bulletin Board<br />
TOSHIBA ConfigFree<br />
TOSHIBA Disc Creator<br />
TOSHIBA DVD PLAYER<br />
TOSHIBA Extended Tiles for Windows Mobility Center<br />
TOSHIBA Flash Cards Support Utility<br />
TOSHIBA Hardware Setup<br />
TOSHIBA HDD/SSD Alert<br />
TOSHIBA Media Controller<br />
TOSHIBA Quality Application<br />
TOSHIBA Recovery Media Creator<br />
TOSHIBA ReelTime<br />
TOSHIBA Service Station<br />
TOSHIBA Speech System Applications<br />
TOSHIBA Speech System SR Engine(U.S.) Version1.0<br />
TOSHIBA Speech System TTS Engine(U.S.) Version1.0<br />
TOSHIBA Supervisor Password<br />
TOSHIBA Value Added Package<br />
ToshibaRegistration<br />
Unity Web Player<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Update for Microsoft Office 2007 Help for Common Features (KB963673)<br />
Update for Microsoft Office Excel 2007 Help (KB963678)<br />
Update for Microsoft Office OneNote 2007 Help (KB963670)<br />
Update for Microsoft Office Powerpoint 2007 Help (KB963669)<br />
Update for Microsoft Office Script Editor Help (KB963671)<br />
Update for Microsoft Office Word 2007 Help (KB963665)<br />
Update Installer for WildTangent Games App<br />
Utility Common Driver<br />
Weather<br />
WildTangent Games<br />
WildTangent Games App<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Language Selector<br />
Windows Live Mail<br />
Windows Live Mesh<br />
Windows Live Mesh ActiveX Control for Remote Connections<br />
Windows Live Messenger<br />
Windows Live MIME IFilter<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live Remote Client<br />
Windows Live Remote Client Resources<br />
Windows Live Remote Service<br />
Windows Live Remote Service Resources<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live Sync<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
Windows Media Center Add-in for Flash<br />
Windows Media Center Add-in for Silverlight<br />
Wizard101<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
5/19/2013 7:04:07 AM, Error: volsnap [27]  - The shadow copies of volume C: were aborted during detection because a critical control file could not be opened.<br />
5/19/2013 7:03:29 AM, Error: volsnap [25]  - The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.<br />
5/19/2013 4:25:20 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070663: Security Update for Microsoft Office 2007 suites (KB2687499).<br />
5/19/2013 4:25:19 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070663: Update for Microsoft Office 2007 suites (KB2596660).<br />
5/19/2013 4:25:19 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070663: Security Update for Microsoft Office 2007 suites (KB2687311).<br />
5/19/2013 4:25:18 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070663: Update for Microsoft Office 2007 suites (KB2596848).<br />
5/19/2013 4:25:18 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070663: Security Update for Microsoft Office 2007 suites (KB2596615).<br />
5/19/2013 4:25:17 PM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070663: Security Update for Microsoft Office 2007 suites (KB2760416).<br />
5/18/2013 8:51:56 PM, Error: Service Control Manager [7034]  - The Windows Image Acquisition (WIA) service terminated unexpectedly.  It has done this 1 time(s).<br />
5/17/2013 9:13:11 PM, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/17/2013 8:34:21 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}<br />
5/17/2013 8:34:21 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}<br />
5/17/2013 8:34:21 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1068&quot; attempting to start the service netprofm with arguments &quot;&quot; in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}<br />
5/17/2013 8:34:21 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1068&quot; attempting to start the service netman with arguments &quot;&quot; in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}<br />
5/17/2013 8:34:20 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service EventSystem with arguments &quot;&quot; in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
5/17/2013 8:34:14 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service ShellHWDetection with arguments &quot;&quot; in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}<br />
5/17/2013 8:32:22 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD avipbb avkmgr DfsC discache NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr tdx vwififlt Wanarpv6 WfpLwf<br />
5/17/2013 8:32:22 PM, Error: Service Control Manager [7001]  - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/17/2013 8:32:22 PM, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/17/2013 8:32:22 PM, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/17/2013 8:32:22 PM, Error: Service Control Manager [7001]  - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/17/2013 8:32:19 PM, Error: Service Control Manager [7001]  - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/17/2013 8:32:19 PM, Error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/17/2013 8:32:19 PM, Error: Service Control Manager [7001]  - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/17/2013 8:32:19 PM, Error: Service Control Manager [7001]  - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/17/2013 8:32:19 PM, Error: Service Control Manager [7001]  - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/17/2013 8:32:19 PM, Error: Service Control Manager [7001]  - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
.<br />
==== End Of File ===========================</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>Linda406</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?257021-trojans</guid>
		</item>
		<item>
			<title>IE opening unexpectedly, ad pages appearing</title>
			<link>http://discussions.virtualdr.com/showthread.php?257019-IE-opening-unexpectedly-ad-pages-appearing&amp;goto=newpost</link>
			<pubDate>Wed, 22 May 2013 23:12:51 GMT</pubDate>
			<description><![CDATA[Got a PC where Firefox is the default browser, but IE keeps opening up on its own at random intervals, mostly to MSN's page, but a bunch of ad pages opened up as well when the PC was left on overnight. No sign of anything in Malwarebytes, and I don't think I saw anything in DDS either: 
 
 
...]]></description>
			<content:encoded><![CDATA[<div>Got a PC where Firefox is the default browser, but IE keeps opening up on its own at random intervals, mostly to MSN's page, but a bunch of ad pages opened up as well when the PC was left on overnight. No sign of anything in Malwarebytes, and I don't think I saw anything in DDS either:<br />
<br />
<br />
<br />
Malwarebytes Anti-Malware 1.75.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.05.16.08<br />
<br />
Windows 7 Service Pack 1 x86 NTFS<br />
Internet Explorer 10.0.9200.16576<br />
John :: JOHNB-PC [administrator]<br />
<br />
5/22/2013 8:16:07 AM<br />
mbam-log-2013-05-22 (08-16-07).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 280867<br />
Time elapsed: 10 minute(s), 29 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 0<br />
(No malicious items detected)<br />
<br />
(end)<br />
<br />
<br />
<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Professional <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 9/28/2011 4:28:44 PM<br />
System Uptime: 5/21/2013 9:04:39 AM (26 hours ago)<br />
.<br />
Motherboard: Intel Corporation |  | DG31PR<br />
Processor: Intel(R) Core(TM)2 Duo CPU     E8500  @ 3.16GHz | J3E1 | 3163/1333mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
A: is Removable<br />
C: is FIXED (NTFS) - 69 GiB total, 7.438 GiB free.<br />
D: is CDROM ()<br />
E: is FIXED (NTFS) - 233 GiB total, 122.793 GiB free.<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}<br />
Description: Officejet 6000 E609n<br />
Device ID: ROOT\MULTIFUNCTION\0000<br />
Manufacturer: HP<br />
Name: Officejet 6000 E609n<br />
PNP Device ID: ROOT\MULTIFUNCTION\0000<br />
Service: <br />
.<br />
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}<br />
Description: hp LaserJet 4250<br />
Device ID: ROOT\MULTIFUNCTION\0001<br />
Manufacturer: Hewlett-Packard<br />
Name: hp LaserJet 4250<br />
PNP Device ID: ROOT\MULTIFUNCTION\0001<br />
Service: <br />
.<br />
==== System Restore Points ===================<br />
.<br />
No restore point in system.<br />
.<br />
==== Installed Programs ======================<br />
.<br />
 Update for Microsoft Office 2007 (KB2508958)<br />
32 Bit HP CIO Components Installer<br />
6000E609_BasicWeb<br />
6000E609_Help_BasicWeb<br />
Active@ KillDisk<br />
Adobe AIR<br />
Adobe Flash Player 11 Plugin<br />
Adobe Reader X (10.1.7)<br />
Allway Sync version 12.0.8<br />
Application Verifier x86 External Package<br />
Bing Bar<br />
BPDSoftware_Ini<br />
BufferChm<br />
Canon ScanGear Starter<br />
CanoScan Toolbox Ver4.9<br />
CDCheck<br />
CPUID CPU-Z 1.60.1<br />
D3DX10<br />
Dell Software Uninstall<br />
DVDx 4.0 Open Edition<br />
Eraser 6.0.10.2620<br />
ESWIN_USB 0.6j<br />
Google Chrome<br />
Google Drive<br />
Google Update Helper<br />
GoToMeeting 5.1.0.880<br />
HandBrake 0.9.5<br />
HP Officejet 6000 E609 Series<br />
ImgBurn<br />
Java 7 Update 21<br />
Java Auto Updater<br />
join.me<br />
Kits Configuration Installer<br />
Lexmark Software Uninstall<br />
LogMeIn<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft .NET Framework 4 Extended<br />
Microsoft Application Error Reporting<br />
Microsoft Office 2007 Service Pack 3 (SP3)<br />
Microsoft Office Access MUI (English) 2007<br />
Microsoft Office Access Setup Metadata MUI (English) 2007<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office File Validation Add-In<br />
Microsoft Office InfoPath MUI (English) 2007<br />
Microsoft Office Outlook MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office Professional Plus 2007<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)<br />
Microsoft Office Publisher MUI (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Security Client<br />
Microsoft Security Essentials<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual J# 2.0 Redistributable Package<br />
Mozilla Firefox 21.0 (x86 en-US)<br />
Mozilla Maintenance Service<br />
MSVCRT<br />
Network<br />
NirSoft ProduKey<br />
NVIDIA Control Panel 307.83<br />
NVIDIA Graphics Driver 307.83<br />
NVIDIA Install Application<br />
NVIDIA Update 1.10.8<br />
NVIDIA Update Components<br />
Outlook Setup Tool<br />
Panda USB Vaccine 1.0.1.4<br />
PrimoPDF -- brought to you by Nitro PDF Software<br />
ScanSnap Manager<br />
SDK Debuggers<br />
SeaTools for Windows<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)<br />
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition<br />
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition <br />
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition <br />
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition <br />
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition <br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition<br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition<br />
Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition <br />
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition <br />
Toolbox<br />
Unity Web Player<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Update for Microsoft .NET Framework 4 Extended (KB2468871)<br />
Update for Microsoft .NET Framework 4 Extended (KB2533523)<br />
Update for Microsoft .NET Framework 4 Extended (KB2600217)<br />
Update for Microsoft Office 2007 Help for Common Features (KB963673)<br />
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition<br />
Update for Microsoft Office Access 2007 Help (KB963663)<br />
Update for Microsoft Office Excel 2007 Help (KB963678)<br />
Update for Microsoft Office Infopath 2007 Help (KB963662)<br />
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition<br />
Update for Microsoft Office Outlook 2007 Help (KB963677)<br />
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817359) 32-Bit Edition<br />
Update for Microsoft Office Powerpoint 2007 Help (KB963669)<br />
Update for Microsoft Office Publisher 2007 Help (KB963667)<br />
Update for Microsoft Office Script Editor Help (KB963671)<br />
Update for Microsoft Office Word 2007 Help (KB963665)<br />
Visual CertExam Suite<br />
VMware Infrastructure Client 2.5<br />
WebReg<br />
Windows App Certification Kit<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Software Development Kit<br />
Windows Software Development Kit DirectX x86 Remote<br />
Windows Software Development Kit for Metro style Apps<br />
Windows Software Development Kit for Metro style Apps DirectX x86 Remote<br />
Windows Software Development Kit Redistributables<br />
WinRAR 4.11 (32-bit)<br />
WPT Redistributables<br />
WPTx86<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
5/22/2013 9:54:05 AM, Error: volsnap [36]  - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.<br />
5/21/2013 9:05:06 AM, Error: Microsoft-Windows-DNS-Client [1012]  - There was an error while attempting to read the local hosts file.<br />
5/21/2013 9:04:49 AM, Error: Microsoft-Windows-Kernel-Processor-Power [34]  - Idle power management features on processor 1 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.<br />
5/21/2013 9:04:49 AM, Error: Microsoft-Windows-Kernel-Processor-Power [34]  - Idle power management features on processor 0 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.<br />
5/21/2013 9:03:11 AM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.<br />
5/21/2013 8:56:24 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}<br />
5/21/2013 8:56:24 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}<br />
5/21/2013 8:56:23 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service EventSystem with arguments &quot;&quot; in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
5/21/2013 8:56:17 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1084&quot; attempting to start the service ShellHWDetection with arguments &quot;&quot; in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}<br />
5/21/2013 8:56:06 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  discache MpFilter spldr Wanarpv6<br />
.<br />
==== End Of File ===========================<br />
<br />
<br />
<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_x86 <br />
Internet Explorer: 10.0.9200.16576  BrowserJavaVersion: 10.21.2<br />
Run by John at 11:15:57 on 2013-05-22<br />
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.2045.829 [GMT -7:00]<br />
.<br />
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}<br />
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}<br />
.<br />
============== Running Processes ================<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Program Files\Microsoft Security Client\MsMpEng.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe<br />
C:\Program Files\LogMeIn\x86\RaMaint.exe<br />
C:\Program Files\LogMeIn\x86\LogMeIn.exe<br />
C:\Windows\system32\lxeccoms.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Google\Update\1.3.21.145\GoogleCrashHandler.exe<br />
C:\Program Files\Microsoft Security Client\msseces.exe<br />
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br />
C:\Program Files\Microsoft Security Client\NisSrv.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Panda USB Vaccine\USBVaccine.exe<br />
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br />
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE<br />
C:\Program Files\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.exe<br />
C:\Program Files\Mozilla Firefox\plugin-container.exe<br />
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe<br />
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Windows Media Player\wmplayer.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Windows\notepad.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k HPService<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\microsoft\bingbar\7.1.361.0\BingExt.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll<br />
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - <br />
uRun: [Macromedia] Rundll32.exe c:\users\john\appdata\local\macromedia\wlskarbl.dll,rwfhojsssifpsripc<br />
mRun: [MSC] &quot;c:\program files\microsoft security client\msseces.exe&quot; -hide -runkey<br />
mRun: [LogMeIn GUI] &quot;c:\program files\logmein\x86\LogMeInSystray.exe&quot;<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\common files\java\java update\jusched.exe&quot;<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe<br />
mPolicies-Explorer: NoWelcomeScreen = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-001021-0002-0021-ABCDEFFEDCBC} - &lt;orphaned&gt;<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
TCP: NameServer = 66.75.164.89 66.75.164.90<br />
TCP: Interfaces\{64FB77B1-6D0D-4842-B331-A569DC71F8B0} : NameServer = 172.16.0.9<br />
TCP: Interfaces\{64FB77B1-6D0D-4842-B331-A569DC71F8B0} : DHCPNameServer = 66.75.164.89 66.75.164.90<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - &quot;c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe&quot; --configure-user-settings --verbose-logging --system-level --multi-install --chrome<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\users\john\appdata\roaming\mozilla\firefox\profiles\ksjcp6a1.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com<br />
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - plugin: c:\users\john\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll<br />
FF - plugin: c:\users\john\appdata\roaming\mozilla\firefox\profiles\ksjcp6a1.default\extensions\logmeinclient@logmein.com\plugins\npLMI64.dll<br />
FF - plugin: c:\users\john\appdata\roaming\mozilla\firefox\profiles\ksjcp6a1.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll<br />
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll<br />
FF - plugin: c:\windows\system32\wat\npWatWeb.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]<br />
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2012-5-2 24328]<br />
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2012-12-18 375296]<br />
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2012-11-29 12856]<br />
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2013-1-24 47640]<br />
R2 lxec_device;lxec_device;c:\windows\system32\lxeccoms.exe -service --&gt; c:\windows\system32\lxeccoms.exe -service [?]<br />
R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 100328]<br />
R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.361.0\SeaPort.EXE [2012-2-10 240408]<br />
R3 dcdbas;System Management Driver;c:\windows\system32\drivers\dcdbas32.sys [2011-12-7 26624]<br />
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232]<br />
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]<br />
S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.361.0\BBSvc.EXE [2012-2-10 193816]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]<br />
S3 BrSerIb;Brother MFC Serial Interface Driver(WDM);c:\windows\system32\drivers\BrSerIb.sys [2009-7-13 265088]<br />
S3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);c:\windows\system32\drivers\BrUsbSIb.sys [2009-7-13 11904]<br />
S3 iscFlash;iscFlash;c:\users\john\appdata\local\temp\7zse83b.tmp\iscflash.sys [2013-5-7 35840]<br />
S3 PortTalk;PortTalk;c:\windows\system32\drivers\PortTalk.sys [2011-11-2 3567]<br />
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]<br />
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-10-20 52224]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-10-20 1343400]<br />
S4 BotkindSyncService;Botkind Service;c:\program files\allway sync\bin\syncservice.exe service --&gt; c:\program files\allway sync\bin\SyncService.exe service [?]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-22 16:16:50	7016152	----a-w-	c:\programdata\microsoft\microsoft antimalware\definition updates\{ea7ad753-97a5-422a-aeed-743fc5193c22}\mpengine.dll<br />
2013-05-21 21:07:12	94112	----a-w-	c:\windows\system32\WindowsAccessBridge.dll<br />
2013-05-21 15:19:46	724464	------w-	c:\programdata\microsoft\microsoft antimalware\definition updates\{b6a2fddf-599f-4f57-8581-e3582e999021}\gapaengine.dll<br />
2013-05-21 15:19:26	7016152	------w-	c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll<br />
2013-05-17 17:25:51	262552	----a-w-	c:\program files\mozilla firefox\browser\components\browsercomps.dll<br />
2013-05-15 08:54:12	40960	----a-w-	c:\windows\system32\wwanprotdim.dll<br />
2013-05-15 08:54:12	186368	----a-w-	c:\windows\system32\wwansvc.dll<br />
2013-05-15 08:54:11	2347520	----a-w-	c:\windows\system32\win32k.sys<br />
2013-05-15 08:54:08	728424	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys<br />
2013-05-15 08:54:07	218984	----a-w-	c:\windows\system32\drivers\dxgmms1.sys<br />
2013-05-15 08:54:02	101720	----a-w-	c:\windows\system32\consent.exe<br />
2013-05-15 08:54:01	1796096	----a-w-	c:\windows\system32\authui.dll<br />
2013-05-15 08:54:00	47104	----a-w-	c:\windows\system32\appinfo.dll<br />
2013-05-07 23:45:24	--------	d-----w-	C:\swsetup<br />
2013-04-23 18:36:55	1211752	----a-w-	c:\windows\system32\drivers\ntfs.sys<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-14 23:26:21	71048	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2013-05-14 23:26:21	692104	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
2013-05-02 15:28:50	238872	------w-	c:\windows\system32\MpSigStub.exe<br />
2013-04-13 04:45:16	474624	----a-w-	c:\windows\apppatch\AcSpecfc.dll<br />
2013-04-13 04:45:15	2176512	----a-w-	c:\windows\apppatch\AcGenral.dll<br />
2013-04-12 19:33:56	861088	----a-w-	c:\windows\system32\npDeployJava1.dll<br />
2013-04-12 19:33:56	782240	----a-w-	c:\windows\system32\deployJava1.dll<br />
2013-04-05 05:28:24	1767424	----a-w-	c:\windows\system32\wininet.dll<br />
2013-04-05 05:26:26	2877440	----a-w-	c:\windows\system32\jscript9.dll<br />
2013-04-05 05:26:21	61440	----a-w-	c:\windows\system32\iesetup.dll<br />
2013-04-05 05:26:21	109056	----a-w-	c:\windows\system32\iesysprep.dll<br />
2013-04-05 04:29:45	2706432	----a-w-	c:\windows\system32\mshtml.tlb<br />
2013-04-05 03:38:25	71680	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe<br />
2013-04-04 21:50:32	22856	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2013-03-19 05:04:13	3968856	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2013-03-19 05:04:10	3913560	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2013-03-19 04:48:45	38912	----a-w-	c:\windows\system32\csrsrv.dll<br />
2013-03-19 02:49:16	69632	----a-w-	c:\windows\system32\smss.exe<br />
.<br />
============= FINISH: 11:16:26.14 ===============</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>shazbot</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?257019-IE-opening-unexpectedly-ad-pages-appearing</guid>
		</item>
		<item>
			<title><![CDATA[[Inactive] ID Stolen from System Even When Scans Says It's Clean ?]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256999-Inactive-ID-Stolen-from-System-Even-When-Scans-Says-It-s-Clean&amp;goto=newpost</link>
			<pubDate>Tue, 21 May 2013 21:22:32 GMT</pubDate>
			<description>I am using a laptop running on XP and IE8. All Windows security releases are up to date as well as my AVG, Super Antispyware, Malwarebytes Anti-Malware and Zone Alarm Firewall programs. Apart from Zone Alarm, all the rest of the programs are run once a day and they always comes up clean except for...</description>
			<content:encoded><![CDATA[<div>I am using a laptop running on XP and IE8. All Windows security releases are up to date as well as my AVG, Super Antispyware, Malwarebytes Anti-Malware and Zone Alarm Firewall programs. Apart from Zone Alarm, all the rest of the programs are run once a day and they always comes up clean except for tracking cookies (usually picked up by Super Antispyware) which are then deleted.<br />
<br />
Two days ago, I got a SMS text on my mobile phone from my mobile phone company to say that my order will be delivered by a certain date. As I didn't placed any order, I phoned to find out more and discovered that someone has changed my home address with my phone supplier via the mobile phone company's website and has ordered a new mobile phone to be delivered to that new address. Effectively, this meant that my login password is compromised and I am wondering how could this be when all the Antivirus and Malware scans didn't picked up any &quot;invaders&quot;. Besides my login password are only hints to remind me and is not actually stated right out in any folder.<br />
<br />
I am hoping some light could be shed on here to solve this puzzle. I post the 3logs as advised by the guidelines for this forum (the two DD log here and the AntiMalware report separately). Any comments and help to clarify this mystery and to reassure my system is clean will be greatly appreciated. Many thanks.<br />
<br />
<b>DDS</b> (Ver_2012-11-20.01) - NTFS_x86 <br />
Internet Explorer: 8.0.6001.18702<br />
Run by Richard at 21:21:10 on 2013-05-21<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2038.1043 [GMT 1:00]<br />
.<br />
AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}<br />
FW: ZoneAlarm Free Firewall Firewall *Enabled* <br />
.<br />
============== Running Processes ================<br />
.<br />
C:\Program Files\Thomson SpeedTouch\ST330\service\st330service.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe<br />
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE<br />
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\WINDOWS\system32\ifxspmgt.exe<br />
C:\WINDOWS\system32\IFXTCS.exe<br />
C:\WINDOWS\system32\IfxPsdSv.exe<br />
C:\Program Files\Macrium\Reflect\ReflectService.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\WINDOWS\system32\locator.exe<br />
C:\Program Files\Fighters\SPAMfighter\sfus.exe<br />
C:\Program Files\Fighters\FighterSuiteService.exe<br />
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe<br />
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe<br />
C:\WINDOWS\system32\vmnat.exe<br />
C:\WINDOWS\system32\vmnetdhcp.exe<br />
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe<br />
C:\WINDOWS\system32\igfxext.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\VMware\VMware Player\vmware-authd.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\vsnpstd2.exe<br />
C:\Program Files\Fighters\SPAMfighter\s***ent.exe<br />
C:\Program Files\Magitime\magitime.exe<br />
C:\Program Files\Thomson SpeedTouch\ST330\diagnostics\diagnostics.exe<br />
C:\Program Files\Real\RealPlayer\update\realsched.exe<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\FastStone Capture\FSCapture.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k NetworkService<br />
C:\WINDOWS\system32\svchost.exe -k LocalService<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://uk.yahoo.com/?p=us<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll<br />
BHO: DivX Plus Web Player HTML5 &lt;video&gt;: {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll<br />
BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll<br />
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: EpsonToolBandKicker Class: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll<br />
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll<br />
TB: EPSON Web-To-Page: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll<br />
TB: EPSON Web-To-Page: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll<br />
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [Messenger (Yahoo!)] &quot;c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE&quot; -quiet<br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /minimized /regrun<br />
mRun: [ZoneAlarm] &quot;c:\program files\checkpoint\zonealarm\zatray.exe&quot;<br />
mRun: [ISW] &quot;c:\program files\checkpoint\zaforcefield\ForceField.exe&quot; /icon=&quot;hidden&quot;<br />
mRun: [SNPSTD2] c:\windows\vsnpstd2.exe<br />
mRun: [s***ent] c:\program files\fighters\spamfighter\s***ent.exe<br />
mRun: [Magitime] c:\program files\magitime\magitime.exe<br />
mRun: [diagnostics] &quot;C:\Program Files/Thomson SpeedTouch/ST330/diagnostics/diagnostics.exe&quot; /icon -l:en<br />
mRun: [AVG_UI] &quot;c:\program files\avg\avg2013\avgui.exe&quot; /TRAYONLY<br />
mRun: [Apoint] c:\program files\apoint\Apoint.exe<br />
mRun: [TkBellExe] &quot;c:\program files\real\realplayer\update\realsched.exe&quot;  -osboot<br />
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe<br />
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe<br />
mRun: [Persistence] c:\windows\system32\igfxpers.exe<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe<br />
StartupFolder: c:\docume~1\richard\startm~1\programs\startup\fastst~1.lnk - c:\program files\faststone capture\FSCapture.exe<br />
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\SysRestorePoint.exe<br />
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
LSP: %windir%\system32\vsocklib.dll<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab<br />
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab<br />
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350240650597<br />
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - <br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - &lt;orphaned&gt;<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll<br />
Notify: igfxcui - igfxdev.dll<br />
Notify: psfus - c:\windows\system32\psqlpwd.dll<br />
Notify: VESWinlogon - VESWinlogon.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL<br />
LSA: Notification Packages =  scecli psqlpwd<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\richard\application data\mozilla\firefox\profiles\782gmubq.default\<br />
FF - prefs.js: browser.startup.homepage - about<b></b>:home<br />
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll<br />
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\npdlplugin.dll<br />
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll<br />
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll<br />
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll<br />
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\nprpplugin.dll<br />
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1168638.dll<br />
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_146.dll<br />
FF - ExtSQL: 2013-04-20 20:31; {FFB96CC1-7EB3-449D-B827-DB661701C6BB}; c:\program files\checkpoint\zaforcefield\TrustChecker<br />
.<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: extensions.delta.tlbrSrchUrl - <br />
FF - user.js: extensions.delta.id - 00081a90000000000000000e50f38aef<br />
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}<br />
FF - user.js: extensions.delta.instlDay - 15785<br />
FF - user.js: extensions.delta.vrsn - 1.8.10.0<br />
FF - user.js: extensions.delta.vrsni - 1.8.10.0<br />
FF - user.js: extensions.delta.vrsnTs - 1.8.10.08:38:38<br />
FF - user.js: extensions.delta.prtnrId - delta<br />
FF - user.js: extensions.delta.prdct - delta<br />
FF - user.js: extensions.delta.aflt - babsst<br />
FF - user.js: extensions.delta.smplGrp - none<br />
FF - user.js: extensions.delta.tlbrId - base<br />
FF - user.js: extensions.delta.instlRef - sst<br />
FF - user.js: extensions.delta.dfltLng - en<br />
FF - user.js: extensions.delta.excTlbr - false<br />
FF - user.js: extensions.delta.admin - false<br />
FF - user.js: extensions.delta.autoRvrt - false<br />
FF - user.js: extensions.delta.rvrt - false<br />
FF - user.js: extensions.delta.newTab - false<br />
user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);user_pref('extensions.blocklist.enabled', false);<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 60216]<br />
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 245048]<br />
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-12-23 96568]<br />
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-1-31 39224]<br />
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2013-4-16 16504]<br />
R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2012-10-14 9216]<br />
R0 vididr;Acronis Virtual Disk;c:\windows\system32\drivers\vididr.sys [2012-10-14 125472]<br />
R0 vidsflt53;Acronis Disk Storage Filter (53);c:\windows\system32\drivers\vsflt53.sys [2012-10-14 83392]<br />
R0 vmci;VMware VMCI Bus Driver;c:\windows\system32\drivers\vmci.sys [2012-7-6 71152]<br />
R0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys [2013-1-12 61296]<br />
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2011-12-23 208184]<br />
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 22328]<br />
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-7-26 170808]<br />
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-8-24 182072]<br />
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2007-9-19 38816]<br />
R1 RapportCerberus_51755;RapportCerberus_51755;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\baseline\RapportCerberus32_51755.sys [2013-3-29 317112]<br />
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2013-4-30 103120]<br />
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2013-4-30 174320]<br />
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]<br />
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]<br />
R1 Vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2013-1-29 527848]<br />
R1 xlkfs;xlkfs;c:\windows\system32\drivers\xlkfs.sys [2011-9-10 18432]<br />
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-8-12 116608]<br />
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2013-5-14 4937264]<br />
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2013-4-18 283136]<br />
R2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2012-7-14 27056]<br />
R2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2012-7-14 497320]<br />
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2013-4-30 1124632]<br />
R2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\macrium\reflect\ReflectService.exe [2013-4-16 254072]<br />
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\fighters\spamfighter\sfus.exe [2013-1-15 216608]<br />
R2 Suite Service;Suite Service;c:\program files\fighters\FighterSuiteService.exe [2012-11-12 1270376]<br />
R2 VMUSBArbService;VMware USB Arbitration Service;c:\program files\common files\vmware\usb\vmware-usbarbitrator.exe [2012-8-1 719512]<br />
R2 vsmon;TrueVector Internet Monitor;c:\program files\checkpoint\zonealarm\vsmon.exe -service --&gt; c:\program files\checkpoint\zonealarm\vsmon.exe -service [?]<br />
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [2013-1-11 4096]<br />
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2012-10-14 41216]<br />
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2012-10-14 71961]<br />
R3 STETH;SpeedTouch Ethernet Adapter NT Driver;c:\windows\system32\drivers\steth.sys [2013-1-12 40320]<br />
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2012-10-14 812544]<br />
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2013-1-11 11520]<br />
S1 Uim_Vim;UIM Virtual Image Plugin;c:\windows\system32\drivers\Uim_Vim.sys [2013-2-18 283600]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-2-28 161384]<br />
S3 5U870UVC;Sony Visual Communication Camera VGP-VCC7;c:\windows\system32\drivers\5U870UVCx86.sys [2012-10-14 70144]<br />
S3 DCamUSBTP10;Qmax Webcam;c:\windows\system32\drivers\TP6810.SYS [2013-1-11 241704]<br />
S3 PSMounterEx;Macrium Reflect Image Explorer Driver;c:\windows\system32\drivers\psmounterex.sys [2013-4-16 55416]<br />
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2013-4-26 15576]<br />
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2013-4-26 10200]<br />
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2012-10-14 30976]<br />
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2013-1-12 30464]<br />
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2013-1-12 12672]<br />
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]<br />
S3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [2013-4-9 16640]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-20 09:56:05	--------	d--h--w-	c:\windows\PIF<br />
2013-05-18 21:58:07	5888	------w-	c:\windows\system32\drivers\imagedrv.sys<br />
2013-05-18 21:58:07	127488	------w-	c:\windows\system32\drivers\imagesrv.sys<br />
2013-05-18 21:57:52	476320	------w-	c:\windows\system32\ImagXpr7.dll<br />
2013-05-18 21:57:52	471040	------w-	c:\windows\system32\ImagXRA7.dll<br />
2013-05-18 21:57:52	364544	------w-	c:\windows\system32\TwnLib4.dll<br />
2013-05-18 21:57:52	262144	------w-	c:\windows\system32\ImagXR7.dll<br />
2013-05-18 21:57:52	1568768	------w-	c:\windows\system32\ImagX7.dll<br />
2013-05-18 21:57:52	106496	----a-w-	c:\windows\system32\TwnLib20.dll<br />
2013-05-18 21:57:49	155648	----a-w-	c:\windows\system32\NeroCheck.exe<br />
2013-05-18 09:03:47	--------	d--h--w-	c:\windows\system32\GroupPolicy<br />
2013-05-15 21:01:30	--------	d-----w-	c:\program files\BBC iPlayer Desktop<br />
2013-05-15 20:17:56	--------	d-----w-	c:\documents and settings\richard\application data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1<br />
2013-05-12 08:26:45	--------	d-----w-	c:\windows\system32\wbem\repository\FS<br />
2013-05-12 08:26:45	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2013-05-11 15:37:40	--------	d-----w-	c:\documents and settings\richard\local settings\application data\Wondershare<br />
2013-05-11 15:37:38	--------	d-----w-	c:\program files\common files\Wondershare<br />
2013-05-11 10:37:28	209472	----a-w-	c:\program files\mozilla firefox\plugins\nppdf32.dll<br />
2013-05-09 17:37:07	1414440	----a-w-	c:\windows\system32\ShellManager310E2D762.dll<br />
2013-05-09 17:14:22	--------	d-----w-	c:\documents and settings\richard\local settings\application data\Nero<br />
2013-05-09 16:53:28	--------	d-----w-	c:\documents and settings\all users\application data\Nero<br />
2013-05-06 17:11:47	--------	d-----w-	C:\CruzerLock2_setup<br />
2013-05-06 10:35:46	--------	d-----w-	c:\documents and settings\richard\local settings\application data\PC_Drivers_Headquarters<br />
2013-05-06 09:56:15	--------	d-----w-	C:\My Files<br />
2013-05-06 08:57:32	--------	d-----w-	c:\documents and settings\richard\application data\SanDisk SecureAccess<br />
2013-05-06 08:44:31	1208320	----a-w-	c:\windows\system32\PTxSCP.ocx<br />
2013-05-06 08:44:30	389120	----a-w-	c:\windows\system32\actskn43.ocx<br />
2013-05-05 13:43:54	--------	d-----w-	c:\documents and settings\richard\application data\AVG<br />
2013-05-05 13:42:55	--------	d-----w-	c:\documents and settings\all users\application data\AVG<br />
2013-05-05 13:42:42	--------	d-sh--w-	c:\documents and settings\all users\application data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}<br />
2013-05-05 11:59:23	--------	d-----w-	c:\documents and settings\all users\application data\ErrorEND<br />
2013-05-03 19:02:58	--------	d-----w-	c:\documents and settings\richard\application data\DriverCure<br />
2013-05-03 19:02:57	--------	d-----w-	c:\documents and settings\richard\application data\SpeedMaxPc<br />
2013-05-03 19:02:40	--------	d-----w-	c:\program files\common files\SpeedMaxPc<br />
2013-05-03 19:02:39	--------	d-----w-	c:\program files\SpeedMaxPc<br />
2013-05-03 19:02:39	--------	d-----w-	c:\documents and settings\all users\application data\SpeedMaxPc<br />
2013-05-02 18:45:10	--------	d-----w-	c:\documents and settings\richard\My Vaults<br />
2013-05-02 16:55:05	--------	d-----w-	c:\documents and settings\richard\application data\SanDisk<br />
2013-05-02 16:53:47	--------	d-----w-	c:\documents and settings\all users\application data\ClubSanDisk<br />
2013-04-30 20:59:06	172032	----a-w-	c:\windows\system32\igfxres.dll<br />
2013-04-30 20:20:09	--------	d-----w-	c:\program files\Defraggler<br />
2013-04-30 00:28:50	102448	----a-w-	c:\windows\system32\drivers\RapportKELL.sys<br />
2013-04-29 11:21:45	--------	d-----w-	c:\documents and settings\richard\application data\Glarysoft<br />
2013-04-28 13:33:34	--------	d-----w-	c:\windows\pss<br />
2013-04-26 10:41:29	2888384	----a-w-	c:\windows\system32\pwNative.exe<br />
2013-04-26 10:41:28	15576	------w-	c:\windows\system32\pwdrvio.sys<br />
2013-04-26 10:41:27	10200	------w-	c:\windows\system32\pwdspio.sys<br />
2013-04-26 10:04:59	2560	----a-w-	c:\windows\_MSRSTRT.EXE<br />
2013-04-24 08:30:58	--------	d-----w-	C:\boot<br />
2013-04-22 20:13:44	--------	d-----w-	c:\program files\DivX<br />
2013-04-22 18:35:43	237088	------w-	c:\windows\system32\MpSigStub.exe<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-21 11:05:27	23552	----a-w-	c:\windows\xlkfs.dll<br />
2013-05-19 13:02:16	71048	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2013-05-19 13:02:16	692104	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
2013-04-16 16:11:54	13432	----a-w-	c:\windows\system32\drivers\PSVolAcc.sys<br />
2013-04-16 16:11:26	16504	----a-w-	c:\windows\system32\drivers\pssnap.sys<br />
2013-04-16 16:11:14	55416	----a-w-	c:\windows\system32\drivers\psmounterex.sys<br />
2013-04-05 10:49:20	499712	----a-w-	c:\windows\system32\msvcp71.dll<br />
2013-04-05 10:49:20	348160	----a-w-	c:\windows\system32\msvcr71.dll<br />
2013-04-04 13:50:32	22856	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2013-03-29 19:49:01	4608	----a-w-	c:\windows\system32\bbchlp.dll<br />
2013-03-29 19:49:01	4096	----a-w-	c:\windows\system32\drivers\bbcap.sys<br />
2013-03-29 19:49:01	30720	----a-w-	c:\windows\system32\bbcap.dll<br />
2013-03-29 01:53:48	208184	----a-w-	c:\windows\system32\drivers\avgidsdriverx.sys<br />
2013-03-23 01:09:28	354656	----a-w-	c:\windows\system32\DivXControlPanelApplet.cpl<br />
2013-03-21 02:08:24	182072	----a-w-	c:\windows\system32\drivers\avgtdix.sys<br />
2013-03-01 10:32:20	22328	----a-w-	c:\windows\system32\drivers\avgidsshimx.sys<br />
.<br />
============ FINISH: 21:26:55.89 ===============<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; <b>ATTACH</b> IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows XP Professional<br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 10/14/2012 12:43:31 PM<br />
System Uptime: 5/21/2013 7:04:39 PM (2 hours ago)<br />
.<br />
Motherboard: Sony Corporation |  | VAIO                            <br />
Processor: Intel(R) Core(TM)2 Duo CPU     T7700  @ 2.40GHz | N/A | 2394/200mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 60 GiB total, 29.725 GiB free.<br />
D: is FIXED (NTFS) - 406 GiB total, 98.976 GiB free.<br />
E: is CDROM ()<br />
F: is Removable<br />
G: is FIXED (NTFS) - 931 GiB total, 273.981 GiB free.<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}<br />
Description: Sony Visual Communication Camera VGP-VCC7<br />
Device ID: USB\VID_05CA&amp;PID_183A\5&amp;28FE086C&amp;0&amp;2<br />
Manufacturer: Ricoh<br />
Name: Sony Visual Communication Camera VGP-VCC7<br />
PNP Device ID: USB\VID_05CA&amp;PID_183A\5&amp;28FE086C&amp;0&amp;2<br />
Service: 5U870UVC<br />
.<br />
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}<br />
Description: Alps Pointing-device for VAIO<br />
Device ID: ACPI\SNY9001\4&amp;2FFE84EA&amp;0<br />
Manufacturer: Alps Electric<br />
Name: Alps Pointing-device for VAIO<br />
PNP Device ID: ACPI\SNY9001\4&amp;2FFE84EA&amp;0<br />
Service: i8042prt<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP760: 5/6/2013 8:36:55 PM - Automatic Restore Point<br />
RP761: 5/7/2013 1:16:18 AM - Automatic Restore Point<br />
RP762: 5/7/2013 9:57:55 AM - Automatic Restore Point<br />
RP763: 5/7/2013 11:58:40 AM - Automatic Restore Point<br />
RP764: 5/7/2013 3:15:24 PM - Automatic Restore Point<br />
RP765: 5/7/2013 7:21:15 PM - Automatic Restore Point<br />
RP766: 5/8/2013 6:53:47 AM - Automatic Restore Point<br />
RP767: 5/8/2013 8:40:01 AM - Automatic Restore Point<br />
RP768: 5/8/2013 3:04:30 PM - Automatic Restore Point<br />
RP769: 5/8/2013 5:57:53 PM - Automatic Restore Point<br />
RP770: 5/9/2013 8:00:32 AM - Automatic Restore Point<br />
RP771: 5/9/2013 9:58:53 AM - Automatic Restore Point<br />
RP772: 5/9/2013 3:13:24 PM - Automatic Restore Point<br />
RP773: 5/9/2013 5:44:20 PM - Automatic Restore Point<br />
RP774: 5/9/2013 5:51:01 PM - Installed DirectX<br />
RP775: 5/9/2013 5:53:16 PM - Installed Nero 8 Essentials<br />
RP776: 5/9/2013 6:04:17 PM - Automatic Restore Point<br />
RP777: 5/9/2013 6:07:39 PM - Automatic Restore Point<br />
RP778: 5/9/2013 6:33:48 PM - Revo Uninstaller's restore point - Nero 8 Essentials<br />
RP779: 5/9/2013 6:36:01 PM - Removed Nero 8 Essentials<br />
RP780: 5/9/2013 6:42:22 PM - Automatic Restore Point<br />
RP781: 5/9/2013 6:42:52 PM - Installed Rapport<br />
RP782: 5/9/2013 6:58:06 PM - Automatic Restore Point<br />
RP783: 5/10/2013 4:08:48 AM - Automatic Restore Point<br />
RP784: 5/10/2013 4:13:04 AM - Automatic Restore Point<br />
RP785: 5/10/2013 8:48:13 AM - Automatic Restore Point<br />
RP786: 5/10/2013 11:12:42 AM - Automatic Restore Point<br />
RP787: 5/10/2013 1:25:36 PM - Automatic Restore Point<br />
RP788: 5/10/2013 7:15:39 PM - Automatic Restore Point<br />
RP789: 5/11/2013 12:18:18 AM - Automatic Restore Point<br />
RP790: 5/11/2013 1:38:27 AM - Automatic Restore Point<br />
RP791: 5/11/2013 1:43:52 AM - Automatic Restore Point<br />
RP792: 5/11/2013 2:13:15 AM - Automatic Restore Point<br />
RP793: 5/11/2013 2:22:12 AM - Automatic Restore Point<br />
RP794: 5/11/2013 7:21:07 AM - Automatic Restore Point<br />
RP795: 5/11/2013 7:35:47 AM - Installed Nero 8 Essentials<br />
RP796: 5/11/2013 7:50:52 AM - Automatic Restore Point<br />
RP797: 5/11/2013 10:04:44 AM - Revo Uninstaller's restore point - Nero 8 Essentials<br />
RP798: 5/11/2013 10:06:37 AM - Removed Nero 8 Essentials<br />
RP799: 5/11/2013 11:39:58 AM - Automatic Restore Point<br />
RP800: 5/11/2013 2:22:37 PM - Automatic Restore Point<br />
RP801: 5/11/2013 4:42:08 PM - Revo Uninstaller's restore point - Wondershare Streaming Audio Recorder(Build 2.1.0.0)<br />
RP802: 5/11/2013 5:00:54 PM - Automatic Restore Point<br />
RP803: 5/11/2013 9:52:30 PM - Automatic Restore Point<br />
RP804: 5/12/2013 7:24:28 AM - Automatic Restore Point<br />
RP805: 5/12/2013 8:41:10 AM - Automatic Restore Point<br />
RP806: 5/12/2013 8:46:18 AM - Restore Operation<br />
RP807: 5/12/2013 8:52:42 AM - Automatic Restore Point<br />
RP808: 5/12/2013 9:00:53 AM - Restore Operation<br />
RP809: 5/12/2013 9:02:30 AM - Automatic Restore Point<br />
RP810: 5/12/2013 9:06:32 AM - Restore Operation<br />
RP811: 5/12/2013 9:08:02 AM - Automatic Restore Point<br />
RP812: 5/12/2013 9:12:46 AM - Restore Operation<br />
RP813: 5/12/2013 9:32:01 AM - Automatic Restore Point<br />
RP814: 5/12/2013 10:02:28 AM - Automatic Restore Point<br />
RP815: 5/12/2013 12:37:51 PM - Automatic Restore Point<br />
RP816: 5/12/2013 2:00:13 PM - Automatic Restore Point<br />
RP817: 5/12/2013 4:23:47 PM - Automatic Restore Point<br />
RP818: 5/12/2013 9:25:59 PM - Automatic Restore Point<br />
RP819: 5/13/2013 2:27:17 AM - Automatic Restore Point<br />
RP820: 5/13/2013 6:35:55 AM - Automatic Restore Point<br />
RP821: 5/13/2013 11:29:16 AM - Automatic Restore Point<br />
RP822: 5/13/2013 8:13:18 PM - Automatic Restore Point<br />
RP823: 5/14/2013 1:30:49 AM - Automatic Restore Point<br />
RP824: 5/14/2013 4:19:20 AM - Automatic Restore Point<br />
RP825: 5/14/2013 6:53:53 AM - Automatic Restore Point<br />
RP826: 5/14/2013 10:57:29 AM - Automatic Restore Point<br />
RP827: 5/14/2013 1:48:45 PM - Automatic Restore Point<br />
RP828: 5/14/2013 7:33:38 PM - Automatic Restore Point<br />
RP829: 5/15/2013 3:46:04 AM - Automatic Restore Point<br />
RP830: 5/15/2013 7:24:44 AM - Automatic Restore Point<br />
RP831: 5/15/2013 9:12:10 AM - Automatic Restore Point<br />
RP832: 5/15/2013 10:20:59 AM - Automatic Restore Point<br />
RP833: 5/15/2013 1:23:21 PM - Automatic Restore Point<br />
RP834: 5/15/2013 5:37:43 PM - Automatic Restore Point<br />
RP835: 5/15/2013 8:32:48 PM - Automatic Restore Point<br />
RP836: 5/15/2013 8:38:34 PM - Automatic Restore Point<br />
RP837: 5/15/2013 8:56:35 PM - Removed BBC iPlayer Desktop<br />
RP838: 5/15/2013 9:12:22 PM - Removed BBC iPlayer Desktop<br />
RP839: 5/15/2013 9:16:03 PM - Automatic Restore Point<br />
RP840: 5/16/2013 2:52:02 AM - Automatic Restore Point<br />
RP841: 5/16/2013 4:09:51 AM - Revo Uninstaller's restore point - Any Video Converter 5.0.5<br />
RP842: 5/16/2013 6:47:36 AM - Automatic Restore Point<br />
RP843: 5/16/2013 6:50:48 AM - Automatic Restore Point<br />
RP844: 5/16/2013 9:26:15 AM - Automatic Restore Point<br />
RP845: 5/16/2013 9:39:30 AM - Installed WD SmartWare<br />
RP846: 5/16/2013 10:05:15 AM - Removed WD SmartWare<br />
RP847: 5/16/2013 10:11:44 AM - Automatic Restore Point<br />
RP848: 5/16/2013 2:24:18 PM - Automatic Restore Point<br />
RP849: 5/16/2013 6:34:35 PM - Automatic Restore Point<br />
RP850: 5/16/2013 8:41:29 PM - Automatic Restore Point<br />
RP851: 5/16/2013 9:06:21 PM - Automatic Restore Point<br />
RP852: 5/17/2013 8:29:00 AM - Automatic Restore Point<br />
RP853: 5/17/2013 8:33:12 AM - Automatic Restore Point<br />
RP854: 5/17/2013 2:15:44 PM - Automatic Restore Point<br />
RP855: 5/17/2013 6:05:16 PM - Automatic Restore Point<br />
RP856: 5/17/2013 8:23:12 PM - Automatic Restore Point<br />
RP857: 5/17/2013 8:51:00 PM - Automatic Restore Point<br />
RP858: 5/17/2013 8:58:40 PM - Automatic Restore Point<br />
RP859: 5/17/2013 10:19:02 PM - Automatic Restore Point<br />
RP860: 5/18/2013 2:13:57 AM - Automatic Restore Point<br />
RP861: 5/18/2013 7:32:53 AM - Automatic Restore Point<br />
RP862: 5/18/2013 7:45:48 AM - Automatic Restore Point<br />
RP863: 5/18/2013 3:54:49 PM - Automatic Restore Point<br />
RP864: 5/18/2013 9:25:19 PM - Automatic Restore Point<br />
RP865: 5/18/2013 9:33:14 PM - Automatic Restore Point<br />
RP866: 5/18/2013 10:13:15 PM - Revo Uninstaller's restore point - Nero 6 Ultra Edition<br />
RP867: 5/18/2013 10:18:02 PM - Automatic Restore Point<br />
RP868: 5/18/2013 10:27:14 PM - Software Distribution Service 3.0<br />
RP869: 5/18/2013 10:31:33 PM - Automatic Restore Point<br />
RP870: 5/18/2013 10:38:59 PM - Automatic Restore Point<br />
RP871: 5/18/2013 10:53:55 PM - Automatic Restore Point<br />
RP872: 5/18/2013 11:24:37 PM - Automatic Restore Point<br />
RP873: 5/19/2013 1:15:21 AM - Automatic Restore Point<br />
RP874: 5/19/2013 4:05:02 AM - Automatic Restore Point<br />
RP875: 5/19/2013 5:16:08 AM - Automatic Restore Point<br />
RP876: 5/19/2013 8:42:46 AM - Automatic Restore Point<br />
RP877: 5/19/2013 9:57:54 AM - Automatic Restore Point<br />
RP878: 5/19/2013 1:59:27 PM - Automatic Restore Point<br />
RP879: 5/19/2013 4:43:13 PM - Automatic Restore Point<br />
RP880: 5/19/2013 8:17:28 PM - Automatic Restore Point<br />
RP881: 5/19/2013 8:21:42 PM - Automatic Restore Point<br />
RP882: 5/20/2013 12:12:33 AM - Automatic Restore Point<br />
RP883: 5/20/2013 8:38:06 AM - Automatic Restore Point<br />
RP884: 5/20/2013 11:26:27 AM - Automatic Restore Point<br />
RP885: 5/20/2013 10:07:56 PM - Automatic Restore Point<br />
RP886: 5/21/2013 2:09:32 AM - Automatic Restore Point<br />
RP887: 5/21/2013 9:01:09 AM - Automatic Restore Point<br />
RP888: 5/21/2013 7:06:45 PM - Automatic Restore Point<br />
.<br />
==== Installed Programs ======================<br />
.<br />
 Qmax Webcam Driver<br />
ABBYY FineReader 6.0 Sprint<br />
Acronis True Image WD*Edition<br />
Adobe AIR<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Reader XI (11.0.03)<br />
Adobe Shockwave Player 11.6<br />
Any Video Converter 3.5.8<br />
AVG 2013<br />
AxCrypt 1.7.2976.0<br />
Battery Care Function<br />
BB FlashBack Express<br />
BBC iPlayer Desktop<br />
Bluetooth Stack for Windows by Toshiba<br />
Camera RAW Plug-In for EPSON Creativity Suite<br />
CCleaner<br />
Defraggler<br />
DivX Setup<br />
Easy File Locker 1.3<br />
EPSON Attach To Email<br />
EPSON Copy Utility 3<br />
EPSON Easy Photo Print<br />
EPSON File Manager<br />
EPSON Printer Software<br />
EPSON Scan<br />
EPSON Scan Assistant<br />
EPSON Stylus CX7300_CX8300_DX7400_DX8400 Manual<br />
EPSON Web-To-Page<br />
Eraser 5.82<br />
FastStone Capture 5.3<br />
HDDProtection<br />
High Definition Audio Driver Package - KB835221<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
Hotfix for Windows XP (KB2779562)<br />
Hotfix for Windows XP (KB952287)<br />
Hotfix for Windows XP (KB954550-v5)<br />
Hotfix for Windows XP (KB954708)<br />
Hotfix for Windows XP (KB961118)<br />
Hotfix for Windows XP (KB976002-v5)<br />
Infineon TPM Professional Package<br />
Intel(R) Graphics Media Accelerator Driver<br />
Intel(R) PROSet/Wireless Software<br />
Junk Mail filter update<br />
Macrium Reflect Free Edition<br />
Magitime<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
mCore<br />
mDriver<br />
Microsoft .NET Framework 2.0 Service Pack 2<br />
Microsoft .NET Framework 3.0 Service Pack 2<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft Application Error Reporting<br />
Microsoft Choice Guard<br />
Microsoft Compression Client Pack 1.0 for Windows XP<br />
Microsoft Internationalized Domain Names Mitigation APIs<br />
Microsoft National Language Support Downlevel APIs<br />
Microsoft Office 97, Professional Edition<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft User-Mode Driver Framework Feature Pack 1.0<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219<br />
mMHouse<br />
Mozilla Firefox 12.0 (x86 en-US)<br />
Mozilla Maintenance Service<br />
mPfMgr<br />
mProSafe<br />
MSIcon<br />
MSVCRT<br />
MSXML 6.0 Parser<br />
mWlsSafe<br />
Nero 6 Ultra Edition<br />
neroxml<br />
Protector Suite QL 5.6<br />
Rapport<br />
RealDownloader<br />
RealNetworks - Microsoft Visual C++ 2008 Runtime<br />
RealNetworks - Microsoft Visual C++ 2010 Runtime<br />
RealPlayer<br />
RealUpgrade 1.1<br />
Recuva<br />
Revo Uninstaller 1.94<br />
SanDiskSecureAccess_Manager.exe<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)<br />
Security Update for Microsoft Windows (KB2564958)<br />
Security Update for Windows Internet Explorer 7 (KB2544521)<br />
Security Update for Windows Internet Explorer 7 (KB2761465)<br />
Security Update for Windows Internet Explorer 8 (KB2510531)<br />
Security Update for Windows Internet Explorer 8 (KB2544521)<br />
Security Update for Windows Internet Explorer 8 (KB2618444)<br />
Security Update for Windows Internet Explorer 8 (KB2744842)<br />
Security Update for Windows Internet Explorer 8 (KB2761465)<br />
Security Update for Windows Internet Explorer 8 (KB2792100)<br />
Security Update for Windows Internet Explorer 8 (KB2797052)<br />
Security Update for Windows Internet Explorer 8 (KB2799329)<br />
Security Update for Windows Internet Explorer 8 (KB2809289)<br />
Security Update for Windows Internet Explorer 8 (KB982381)<br />
Security Update for Windows Media Player (KB2378111)<br />
Security Update for Windows Media Player (KB952069)<br />
Security Update for Windows Media Player (KB954155)<br />
Security Update for Windows Media Player (KB973540)<br />
Security Update for Windows Media Player (KB975558)<br />
Security Update for Windows Media Player (KB978695)<br />
Security Update for Windows XP (KB2115168)<br />
Security Update for Windows XP (KB2229593)<br />
Security Update for Windows XP (KB2296011)<br />
Security Update for Windows XP (KB2347290)<br />
Security Update for Windows XP (KB2360937)<br />
Security Update for Windows XP (KB2387149)<br />
Security Update for Windows XP (KB2393802)<br />
Security Update for Windows XP (KB2419632)<br />
Security Update for Windows XP (KB2423089)<br />
Security Update for Windows XP (KB2440591)<br />
Security Update for Windows XP (KB2443105)<br />
Security Update for Windows XP (KB2476490)<br />
Security Update for Windows XP (KB2478960)<br />
Security Update for Windows XP (KB2478971)<br />
Security Update for Windows XP (KB2479943)<br />
Security Update for Windows XP (KB2481109)<br />
Security Update for Windows XP (KB2483185)<br />
Security Update for Windows XP (KB2485663)<br />
Security Update for Windows XP (KB2506212)<br />
Security Update for Windows XP (KB2507938)<br />
Security Update for Windows XP (KB2508429)<br />
Security Update for Windows XP (KB2509553)<br />
Security Update for Windows XP (KB2510581)<br />
Security Update for Windows XP (KB2535512)<br />
Security Update for Windows XP (KB2536276-v2)<br />
Security Update for Windows XP (KB2544893-v2)<br />
Security Update for Windows XP (KB2566454)<br />
Security Update for Windows XP (KB2570947)<br />
Security Update for Windows XP (KB2584146)<br />
Security Update for Windows XP (KB2585542)<br />
Security Update for Windows XP (KB2592799)<br />
Security Update for Windows XP (KB2598479)<br />
Security Update for Windows XP (KB2603381)<br />
Security Update for Windows XP (KB2618451)<br />
Security Update for Windows XP (KB2619339)<br />
Security Update for Windows XP (KB2620712)<br />
Security Update for Windows XP (KB2624667)<br />
Security Update for Windows XP (KB2631813)<br />
Security Update for Windows XP (KB2646524)<br />
Security Update for Windows XP (KB2653956)<br />
Security Update for Windows XP (KB2655992)<br />
Security Update for Windows XP (KB2659262)<br />
Security Update for Windows XP (KB2661637)<br />
Security Update for Windows XP (KB2676562)<br />
Security Update for Windows XP (KB2686509)<br />
Security Update for Windows XP (KB2691442)<br />
Security Update for Windows XP (KB2698365)<br />
Security Update for Windows XP (KB2705219-v2)<br />
Security Update for Windows XP (KB2712808)<br />
Security Update for Windows XP (KB2719985)<br />
Security Update for Windows XP (KB2723135-v2)<br />
Security Update for Windows XP (KB2724197)<br />
Security Update for Windows XP (KB2727528)<br />
Security Update for Windows XP (KB2753842-v2)<br />
Security Update for Windows XP (KB2757638)<br />
Security Update for Windows XP (KB2758857)<br />
Security Update for Windows XP (KB2770660)<br />
Security Update for Windows XP (KB2778344)<br />
Security Update for Windows XP (KB2779030)<br />
Security Update for Windows XP (KB2780091)<br />
Security Update for Windows XP (KB2799494)<br />
Security Update for Windows XP (KB2802968)<br />
Security Update for Windows XP (KB2807986)<br />
Security Update for Windows XP (KB923561)<br />
Security Update for Windows XP (KB946648)<br />
Security Update for Windows XP (KB950762)<br />
Security Update for Windows XP (KB950974)<br />
Security Update for Windows XP (KB951376-v2)<br />
Security Update for Windows XP (KB952004)<br />
Security Update for Windows XP (KB952954)<br />
Security Update for Windows XP (KB956572)<br />
Security Update for Windows XP (KB956744)<br />
Security Update for Windows XP (KB956802)<br />
Security Update for Windows XP (KB956844)<br />
Security Update for Windows XP (KB959426)<br />
Security Update for Windows XP (KB960803)<br />
Security Update for Windows XP (KB960859)<br />
Security Update for Windows XP (KB969059)<br />
Security Update for Windows XP (KB970430)<br />
Security Update for Windows XP (KB971657)<br />
Security Update for Windows XP (KB972270)<br />
Security Update for Windows XP (KB973507)<br />
Security Update for Windows XP (KB973869)<br />
Security Update for Windows XP (KB973904)<br />
Security Update for Windows XP (KB974112)<br />
Security Update for Windows XP (KB974318)<br />
Security Update for Windows XP (KB974392)<br />
Security Update for Windows XP (KB974571)<br />
Security Update for Windows XP (KB975025)<br />
Security Update for Windows XP (KB975467)<br />
Security Update for Windows XP (KB975560)<br />
Security Update for Windows XP (KB975713)<br />
Security Update for Windows XP (KB977816)<br />
Security Update for Windows XP (KB977914)<br />
Security Update for Windows XP (KB978338)<br />
Security Update for Windows XP (KB978542)<br />
Security Update for Windows XP (KB978706)<br />
Security Update for Windows XP (KB979309)<br />
Security Update for Windows XP (KB979482)<br />
Security Update for Windows XP (KB979687)<br />
Security Update for Windows XP (KB981322)<br />
Security Update for Windows XP (KB981997)<br />
Security Update for Windows XP (KB982132)<br />
Security Update for Windows XP (KB982665)<br />
Segoe UI<br />
SES Driver<br />
Setting Utility Series<br />
SigmaTel Audio<br />
Skype™ 6.3<br />
SmartCamera Ver 2.1<br />
Soft Data Fax Modem with SmartCP<br />
Sony Utilities DLL<br />
SonyImgF<br />
SPAMfighter<br />
SpeedTouch 330<br />
Spell Checker For OE 2.1<br />
Startup Cop<br />
SUPERAntiSpyware<br />
swMSM<br />
tools-windows<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Windows Internet Explorer 8 (KB2598845)<br />
Update for Windows XP (KB2345886)<br />
Update for Windows XP (KB2467659)<br />
Update for Windows XP (KB2661254-v2)<br />
Update for Windows XP (KB2736233)<br />
Update for Windows XP (KB2749655)<br />
Update for Windows XP (KB898461)<br />
Update for Windows XP (KB951978)<br />
Update for Windows XP (KB955759)<br />
Update for Windows XP (KB961503)<br />
Update for Windows XP (KB968389)<br />
Update for Windows XP (KB971029)<br />
Update for Windows XP (KB973815)<br />
USB File Transfer 02.106A<br />
USB File Transfer 1.11A<br />
USB PC Camera (SN9C103)<br />
VAIO Control Center<br />
VAIO Event Service<br />
VAIO HDD Protection<br />
VAIO Power Management<br />
VC 9.0 Runtime<br />
VC80CRTRedist - 8.0.50727.6195<br />
Visual C++ 8.0 CRT (x86) WinSXS MSM<br />
Visual C++ 8.0 CRT.Policy (x86) WinSXS MSM<br />
VMware Player<br />
VMwarePlayer_x86<br />
WebFldrs XP<br />
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray<br />
Windows Genuine Advantage Notifications (KB905474)<br />
Windows Internet Explorer 8<br />
Windows Live Call<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Mail<br />
Windows Live Messenger<br />
Windows Live Photo Gallery<br />
Windows Live Sign-in Assistant<br />
Windows Live Sync<br />
Windows Live Upload Tool<br />
Windows Live Writer<br />
Windows Media Format 11 runtime<br />
Windows Media Player 11<br />
WinZip<br />
Wireless Switch Setting Utility<br />
Xvid Video Codec<br />
Yahoo! Messenger<br />
ZoneAlarm Firewall<br />
ZoneAlarm Free Firewall<br />
ZoneAlarm Security<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
5/21/2013 9:12:35 PM, error: PlugPlayManager [12]  - The device 'SpeedTouch Ethernet Adapter' (STBUS\STETHID\7&amp;3b4bc5a3&amp;0&amp;0000) disappeared from the system without first being prepared for removal.<br />
5/21/2013 7:05:13 PM, error: sr [1]  - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'.  It has stopped monitoring the volume.<br />
5/20/2013 9:20:13 PM, error: W32Time [17]  - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)<br />
5/20/2013 8:50:11 PM, error: W32Time [17]  - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)<br />
5/20/2013 8:35:10 PM, error: W32Time [17]  - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)<br />
5/18/2013 7:45:05 AM, error: Service Control Manager [7000]  - The SupportSoft RemoteAssist service failed to start due to the following error:  The system cannot find the file specified.<br />
5/17/2013 2:14:50 PM, error: Service Control Manager [7006]  - The ScRegSetValueExW call failed for FailureActions with the following error:  Access is denied.<br />
5/15/2013 8:31:13 PM, error: Dhcp [1002]  - The IP address lease 192.168.1.65 for the Network Card with network address 001CBF5D04A5 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).<br />
.<br />
==== End Of File ===========================</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>slickcondo</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256999-Inactive-ID-Stolen-from-System-Even-When-Scans-Says-It-s-Clean</guid>
		</item>
		<item>
			<title>Win32/Sirefef.gen!C  Please help</title>
			<link>http://discussions.virtualdr.com/showthread.php?256963-Win32-Sirefef.gen!C-Please-help&amp;goto=newpost</link>
			<pubDate>Sat, 18 May 2013 13:08:05 GMT</pubDate>
			<description>Good day,  
 
I picked up this error this morning and came across this site. Please may you be of assistance. I have followed the rules and done all as suggested. The logs are below as requested. 
 
Thank you in advance. 
 
Malwarebytes Anti-Malware (Trial) 1.75.0.1300 
www.malwarebytes.org 
...</description>
			<content:encoded><![CDATA[<div>Good day, <br />
<br />
I picked up this error this morning and came across this site. Please may you be of assistance. I have followed the rules and done all as suggested. The logs are below as requested.<br />
<br />
Thank you in advance.<br />
<br />
Malwarebytes Anti-Malware (Trial) 1.75.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.05.18.02<br />
<br />
Windows 7 Service Pack 1 x86 NTFS<br />
Internet Explorer 10.0.9200.16521<br />
Ian James :: SHAUNPEARCE-PC [administrator]<br />
<br />
Protection: Enabled<br />
<br />
18/05/2013 04:27:45 PM<br />
mbam-log-2013-05-18 (16-27-45).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 276966<br />
Time elapsed: 13 minute(s), 56 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 1<br />
C:\ProgramData\Bcool\bhoclass.dll (PUP.DownloadnSave) -&gt; Quarantined and deleted successfully.<br />
<br />
(end)<br />
-----------------------------------------------------------------<br />
DDS (Ver_2012-11-20.01) - NTFS_x86 <br />
Internet Explorer: 10.0.9200.16521  BrowserJavaVersion: 10.21.2<br />
Run by Ian James at 16:54:24 on 2013-05-18<br />
Microsoft Windows 7 Professional   6.1.7601.1.1252.27.1033.18.3062.1614 [GMT 4:00]<br />
.<br />
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}<br />
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}<br />
.<br />
============== Running Processes ================<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files\LSI SoftModem\agrsmsvc.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\firebird\firebird_2_1\bin\fbguard.exe<br />
C:\Windows\system32\hasplms.exe<br />
C:\Program Files\Hola\app\hola_updater.exe<br />
C:\Windows\system32\klpnm.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files\MPICH2\bin\smpd.exe<br />
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe<br />
C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe<br />
C:\Program Files\Norton 360\Engine\20.3.1.22\ccSvcHst.exe<br />
C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe<br />
C:\Windows\system32\NLSSRV32.EXE<br />
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe<br />
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe<br />
C:\Program Files\SoundPLAN 7.2\SPUpdateService.exe<br />
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br />
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\firebird\firebird_2_1\bin\fbserver.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Norton 360\Engine\20.3.1.22\ccSvcHst.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\LG Software\LG OSD\HotKey.exe<br />
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe<br />
C:\Program Files\lg_swupdate\GiljabiStart.exe<br />
C:\Program Files\LG Software\LG Magnifier\Maglev.exe<br />
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br />
C:\Program Files\FreePDF_XP\fpassist.exe<br />
C:\Program Files\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE<br />
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe<br />
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe<br />
C:\Users\Ian James\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe<br />
C:\Program Files\Skype\Phone\Skype.exe<br />
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe<br />
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Users\Ian James\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Ian James\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Ian James\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Windows\System32\WUDFHost.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k GPSvcGroup<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\System32\svchost.exe -k HPZ12<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&amp;pid=N360&amp;pvid=20.3.1.22<br />
uDefault_Page_URL = <a rel="nofollow" href="http://www.google.com/ig/redirectdomain?brand=LGEL&amp;bmod=LGEL" target="_blank">http://www.google.com/ig/redirectdom...LGEL&amp;bmod=LGEL</a><br />
mStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&amp;pid=N360&amp;pvid=20.3.1.22<br />
mSearch Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/<br />
mDefault_Page_URL = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/<br />
mDefault_Search_URL = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/<br />
uURLSearchHooks: {ba14329e-9550-4989-b3f2-9732e92d17cc} - &lt;orphaned&gt;<br />
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\program files\norton 360\engine\20.3.1.22\coieplg.dll<br />
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - c:\program files\norton 360\engine\20.3.1.22\ips\ipsbho.dll<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll<br />
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll<br />
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\program files\norton 360\engine\20.3.1.22\coieplg.dll<br />
EB: &lt;No Name&gt;: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - &lt;no file&gt;<br />
EB: &lt;No Name&gt;: {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 - &lt;no file&gt;<br />
uRun: [RegistryBooster] &quot;c:\program files\uniblue\registrybooster\launcher.exe&quot; delay 20000<br />
uRun: [Google Update] &quot;c:\users\ian james\appdata\local\google\update\GoogleUpdate.exe&quot; /c<br />
uRun: [OfficeSyncProcess] &quot;c:\program files\microsoft office\office14\MSOSYNC.EXE&quot;<br />
uRun: [ISUSPM] &quot;c:\programdata\macrovision\flexnet connect\6\ISUSPM.exe&quot; -scheduler<br />
uRun: [SkyDrive] &quot;c:\users\ian james\appdata\local\microsoft\skydrive\SkyDrive.exe&quot; /background<br />
uRun: [Skype] &quot;c:\program files\skype\phone\Skype.exe&quot; /minimized /regrun<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [zOSD] c:\program files\lg software\lg osd\HotKey.exe<br />
mRun: [KeybdUtility] c:\program files\lg software\lg osd\HotKey.exe<br />
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe<br />
mRun: [LG Magnifier] c:\program files\lg software\lg magnifier\MagnifyingGlass.exe<br />
mRun: [LGSR_Menu] &quot;c:\program files\lg software\lg smart recovery\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\lg software\lg smart recovery&quot; updatewithcreateonce  software\cyberlink\PowerRecover<br />
mRun: [LG Intelligent Update] &quot;c:\program files\lg_swupdate\giljabistart.exe&quot; Gilautouc<br />
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s<br />
mRun: [FreePDF Assistant] c:\program files\freepdf_xp\fpassist.exe<br />
mRun: [APSDaemon] &quot;c:\program files\common files\apple\apple application support\APSDaemon.exe&quot;<br />
mRun: [UCam_Menu] &quot;c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe&quot; &quot;c:\program files\cyberlink\youcam&quot; updatewithcreateonce &quot;software\cyberlink\youcam\2.0&quot;<br />
mRun: [HPUsageTrackingLEDM] &quot;c:\program files\hp\hp ut ledm\bin\hppusg.exe&quot; &quot;c:\program files\hp\hp ut ledm\&quot;<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [Adobe ARM] &quot;c:\program files\common files\adobe\arm\1.0\AdobeARM.exe&quot;<br />
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe<br />
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe<br />
mRun: [SunJavaUpdateSched] &quot;c:\program files\common files\java\java update\jusched.exe&quot;<br />
mRun: [Yahoo Messenger] &lt;no file&gt;<br />
StartupFolder: c:\users\ianjam~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\bbcipl~1.lnk - c:\program files\bbc iplayer desktop\BBC iPlayer Desktop.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe<br />
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\password.lnk - c:\windows\temp\Password.exe<br />
uPolicies-Explorer: NoDriveTypeAutoRun = dword:0<br />
uPolicies-Explorer: NoDrives = dword:16777216<br />
uPolicies-Explorer: NoViewOnDrive = dword:16777216<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
mPolicies-System: PromptOnSecureDesktop = dword:0<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~1\office14\EXCEL.EXE/3000<br />
IE: Se&amp;nd to OneNote - c:\progra~1\micros~1\office14\ONBttnIE.dll/105<br />
IE: Send image to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm<br />
IE: Send page to &amp;Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll<br />
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - c:\program files\hewlett-packard\smartprint\smartprintsetup.exe<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll<br />
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm<br />
LSP: mswsock.dll<br />
TCP: NameServer = 213.42.20.20 195.229.241.222<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB} : DHCPNameServer = 213.42.20.20 195.229.241.222<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB}\241425 : DHCPNameServer = 41.66.150.82 168.210.2.2<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB}\25943484142544 : DHCPNameServer = 192.168.0.1<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB}\34C4149425 : DHCPNameServer = 213.42.20.20 195.229.241.222<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB}\75B434 : DHCPNameServer = 192.168.1.1<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB}\84167656D65696765627D275962756C6563737 : DHCPNameServer = 192.168.1.1<br />
TCP: Interfaces\{2297E5B5-E00F-404E-9B79-6AC09BBBC7AB}\A41697E214E6E69656 : DHCPNameServer = 192.168.2.1<br />
TCP: Interfaces\{6215427E-E3AB-4AA3-A1C3-79FC4AE4FAF8} : NameServer = 127.0.0.1<br />
TCP: Interfaces\{6B76ED32-C9D9-4A44-9CC1-7FB7BD16BBC7} : DHCPNameServer = 197.84.84.84 196.28.75.200<br />
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL<br />
Handler: osf-roaming - {C57E9882-B128-4E07-BA2D-FF83B8989C76} - c:\users\ian james\microsoft office 15\root\office15\MSOSB.DLL<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\users\ian james\appdata\roaming\mozilla\firefox\profiles\axt9qb5g.default\<br />
FF - plugin: c:\progra~1\micros~1\office14\NPAUTHZ.DLL<br />
FF - plugin: c:\progra~1\micros~1\office14\NPSPWRAP.DLL<br />
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\battlelog web plugins\1.122.0\npesnlaunch.dll<br />
FF - plugin: c:\program files\battlelog web plugins\2.1.2\npesnlaunch.dll<br />
FF - plugin: c:\program files\battlelog web plugins\sonar\0.70.4\npesnsonar.dll<br />
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll<br />
FF - plugin: c:\program files\microsoft\office live\npOLW.dll<br />
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll<br />
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll<br />
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll<br />
FF - plugin: c:\users\ian james\appdata\local\citrix\plugins\104\npappdetector.dll<br />
FF - plugin: c:\users\ian james\appdata\local\google\update\1.3.21.145\npGoogleUpdate3.dll<br />
FF - plugin: c:\users\ian james\appdata\local\microsoft\internet explorer\downloaded program files\microsoft office 15\npofficeondemand.dll<br />
FF - ExtSQL: 2013-04-20 08:40; {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}; c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2013-4-30 102448]<br />
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\1403010.016\symds.sys [2013-4-16 367704]<br />
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\1403010.016\symefa.sys [2013-4-16 934488]<br />
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.2.0.19\definitions\bashdefs\20130502.001\BHDrvx86.sys [2013-5-8 1000024]<br />
R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\1403010.016\ccsetx86.sys [2013-4-16 134304]<br />
R1 hola-drv;Hola Driver;c:\windows\system32\drivers\hola_drv.sys [2013-2-18 465216]<br />
R1 hola-mon-drv;Hola Monitor Driver;c:\windows\system32\drivers\hola_mon_drv.sys [2013-2-18 71360]<br />
R1 hola_net;Hola Fast Internet Adapter;c:\windows\system32\drivers\hola_net.sys [2013-2-18 72688]<br />
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.2.0.19\definitions\ipsdefs\20130517.001\IDSvix86.sys [2013-5-18 386720]<br />
R1 RapportCerberus_51755;RapportCerberus_51755;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\baseline\RapportCerberus32_51755.sys [2013-3-30 317112]<br />
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2013-4-30 103120]<br />
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2013-4-30 174320]<br />
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\1403010.016\ironx86.sys [2013-4-16 175264]<br />
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\1403010.016\symnets.sys [2013-4-16 338592]<br />
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_2_1\bin\fbguard.exe [2009-7-22 81920]<br />
R2 hasplms;Sentinel Local License Manager;c:\windows\system32\hasplms.exe  -run --&gt; c:\windows\system32\hasplms.exe  -run [?]<br />
R2 hola_updater;Hola Internet Acceleration Updater;c:\program files\hola\app\hola_updater.exe [2013-2-18 4279408]<br />
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2010-1-21 13336]<br />
R2 instdt;dtchk service;c:\windows\system32\klpnm.exe [2012-4-24 20480]<br />
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-5-18 418376]<br />
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-5-18 701512]<br />
R2 mpich2_smpd;MPICH2 Process Manager, Argonne National Lab;c:\program files\mpich2\bin\smpd.exe [2009-11-18 458752]<br />
R2 N360;Norton 360;c:\program files\norton 360\engine\20.3.1.22\ccsvchst.exe [2013-4-16 144520]<br />
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\nitro pdf\professional\NitroPDFDriverService.exe [2011-3-21 196928]<br />
R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2011-3-21 68928]<br />
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2013-4-30 1124632]<br />
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\common files\safenet sentinel\sentinel keys server\sntlkeyssrvr.exe [2009-9-17 369952]<br />
R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2013-4-15 3289208]<br />
R2 SPUpdService;SoundPLAN UpdateService;c:\program files\soundplan 7.2\SPUpdateService.exe [2012-12-14 530432]<br />
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-10-15 381248]<br />
R2 TeamViewer8;TeamViewer 8;c:\program files\teamviewer\version8\TeamViewer_Service.exe [2013-2-21 3560800]<br />
R3 Blackberry Device Manager;Blackberry Device Manager;c:\program files\common files\research in motion\usb drivers\BbDevMgr.exe [2013-1-18 577536]<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-11-5 106656]<br />
R3 FirebirdServerDefaultInstance;Firebird Super Server 2.1.3 - DefaultInstance;c:\program files\firebird\firebird_2_1\bin\fbserver.exe [2009-7-22 2736128]<br />
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2010-1-21 58368]<br />
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-5-18 22856]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 hola_svc;Hola Internet Acceleration Service;c:\program files\hola\app\hola_svc.exe [2013-2-18 4593728]<br />
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\hp\hplaserjetservice\HPLaserJetService.exe [2009-10-15 136192]<br />
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-2-28 161384]<br />
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2011-6-18 84832]<br />
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]<br />
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [2008-5-13 100096]<br />
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-11-15 279592]<br />
S3 camdrv41;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [2011-6-26 1347584]<br />
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-12 39272]<br />
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]<br />
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-2-20 14848]<br />
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-1-21 171520]<br />
S3 RTCore32;RTCore32;c:\program files\msi afterburner\RTCore32.sys [2011-9-6 5632]<br />
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2010-4-1 1009184]<br />
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]<br />
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-2-20 49664]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-7-30 1343400]<br />
S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-7-14 20480]<br />
S3 wsvd;wsvd;c:\windows\system32\drivers\wsvd.sys [2009-6-5 81704]<br />
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-23 47128]<br />
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]<br />
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]<br />
.<br />
=============== File Associations ===============<br />
.<br />
FileExt: .scr: ext1.File=&quot;c:\program files\lakes\screen view\Screen_View.exe&quot;  &quot;%1&quot;<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-18 12:24:48	--------	d-----w-	c:\users\ian james\appdata\roaming\Malwarebytes<br />
2013-05-18 12:24:33	--------	d-----w-	c:\programdata\Malwarebytes<br />
2013-05-18 12:24:32	22856	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2013-05-18 12:24:32	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2013-05-18 06:06:31	--------	d-----w-	c:\program files\x264 Video Codec<br />
2013-05-15 12:05:08	--------	d-----w-	c:\users\ian james\appdata\local\Temporary Projects<br />
2013-05-15 11:46:39	--------	d-----w-	c:\users\ian james\appdata\roaming\com.johnwu.ora.7C6CA62034ECEF7F45C524416D6FEE987A4E8AAB.1<br />
2013-05-15 11:46:33	--------	d-----w-	c:\program files\Ora Time and Expense<br />
2013-05-15 11:31:05	50200	----a-w-	c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll<br />
2013-05-15 11:30:57	79896	----a-w-	c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.1.2531.0.dll<br />
2013-05-15 11:30:00	--------	d-----w-	c:\windows\system32\RsFx<br />
2013-05-15 11:28:44	--------	d-----w-	c:\windows\system32\1033<br />
2013-05-15 11:25:01	--------	d-----w-	c:\program files\Microsoft SQL Server<br />
2013-05-15 11:24:53	--------	d-----w-	c:\program files\Microsoft Synchronization Services<br />
2013-05-15 11:24:06	188128	----a-w-	c:\programdata\microsoft\vcsexpress\10.0\1033\ResourceCache.dll<br />
2013-05-15 11:21:58	--------	d-----w-	c:\program files\Microsoft Visual Studio 10.0<br />
2013-05-15 11:21:58	--------	d-----w-	c:\program files\Microsoft Help Viewer<br />
2013-05-14 11:26:44	--------	d-----w-	c:\program files\Time &amp; Expense Sheet Manager V4.1<br />
2013-05-11 10:37:28	209472	----a-w-	c:\program files\mozilla firefox\plugins\nppdf32.dll<br />
2013-05-11 10:37:28	209472	----a-w-	c:\program files\internet explorer\plugins\nppdf32.dll<br />
2013-05-09 12:52:44	--------	d-----w-	c:\users\ian james\appdata\local\{2932E683-2E14-42AB-8AD4-56741D509516}<br />
2013-05-06 13:20:17	452440	----a-w-	c:\windows\system32\d3dx10_40.dll<br />
2013-05-06 13:20:17	2036576	----a-w-	c:\windows\system32\D3DCompiler_40.dll<br />
2013-05-06 13:20:16	4379984	----a-w-	c:\windows\system32\D3DX9_40.dll<br />
2013-05-06 10:21:57	--------	d-----w-	c:\program files\dumps<br />
2013-05-06 10:20:39	--------	d-----w-	c:\program files\common files\Steam<br />
2013-05-06 10:20:28	--------	d-----w-	c:\program files\Steam<br />
2013-05-06 04:41:50	--------	d-----w-	c:\users\ian james\appdata\roaming\inkscape<br />
2013-05-06 04:31:05	--------	d-----w-	c:\program files\Inkscape<br />
2013-05-05 06:25:43	--------	d-----w-	c:\users\ian james\appdata\roaming\Softland<br />
2013-05-05 06:25:34	1700352	----a-w-	c:\windows\system32\GdiPlus.dll<br />
2013-05-05 06:25:30	--------	d-----w-	c:\users\ian james\appdata\local\PDF Annotator<br />
2013-05-01 05:55:11	--------	d-----w-	c:\programdata\Intergraph CAS<br />
2013-05-01 05:55:11	--------	d-----w-	c:\program files\Intergraph CAS<br />
2013-05-01 05:55:11	--------	d-----w-	c:\program files\common files\Autodesk Shared<br />
2013-05-01 05:55:11	--------	d-----w-	c:\program files\common files\Alias<br />
2013-04-30 07:07:44	--------	d-----w-	c:\users\ian james\appdata\roaming\Kyocera<br />
2013-04-29 21:28:50	102448	----a-w-	c:\windows\system32\drivers\RapportKELL.sys<br />
2013-04-25 08:05:45	--------	d-----w-	C:\J3035 SEP<br />
2013-04-25 06:05:50	--------	d-----w-	c:\program files\Any PDF to DWG Converter<br />
2013-04-25 05:11:10	94112	----a-w-	c:\windows\system32\WindowsAccessBridge.dll<br />
2013-04-24 09:27:08	--------	d-----w-	c:\program files\Citrix<br />
2013-04-24 09:26:50	--------	d-----w-	c:\users\ian james\appdata\local\Citrix<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-07 09:50:19	71360	----a-w-	c:\windows\system32\drivers\hola_mon_drv.sys<br />
2013-05-07 09:50:19	465216	----a-w-	c:\windows\system32\drivers\hola_drv.sys<br />
2013-03-24 07:27:31	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll<br />
2013-03-20 06:55:52	861088	----a-w-	c:\windows\system32\npDeployJava1.dll<br />
2013-03-20 06:55:52	782240	----a-w-	c:\windows\system32\deployJava1.dll<br />
2013-03-15 08:52:10	608136	----a-w-	c:\windows\system32\drivers\hardlock.sys<br />
2013-03-15 08:52:10	53192	----a-w-	c:\windows\system32\drivers\akshhl.sys<br />
2013-03-15 08:52:10	46536	----a-w-	c:\windows\system32\aksusb4.dll<br />
2013-03-15 08:52:10	4466120	----a-w-	c:\windows\system32\hasplms.exe<br />
2013-03-15 08:52:10	4466120	----a-w-	c:\windows\system32\aksllmtp.exe<br />
2013-03-15 08:52:10	43976	----a-w-	c:\windows\system32\akshhl30.dll<br />
2013-03-15 08:52:10	376200	----a-w-	c:\windows\system32\drivers\aksfridge.sys<br />
2013-03-15 08:52:10	295944	----a-w-	c:\windows\system32\drivers\aksusb.sys<br />
2013-03-15 08:52:10	244040	----a-w-	c:\windows\system32\drivers\akshasp.sys<br />
2013-03-15 08:52:10	17992	----a-w-	c:\windows\system32\drivers\aksclass.sys<br />
2013-03-15 08:52:10	15816	----a-w-	c:\windows\system32\akshsp52.dll<br />
2013-03-13 07:31:40	2269184	----a-w-	c:\windows\system32\WindRose1.dll<br />
2013-03-07 11:55:28	507904	----a-r-	c:\windows\system32\btwapi.dll<br />
2013-02-19 18:24:22	72688	----a-w-	c:\windows\system32\drivers\hola_net.sys<br />
2013-02-19 10:41:36	1447892	----a-w-	c:\windows\system32\WindRose2.dll<br />
2013-02-18 05:22:18	884072	----a-w-	c:\windows\system32\nvhdagenco3220103.dll<br />
2013-02-18 05:22:18	28008	----a-w-	c:\windows\system32\nvhdap32.dll<br />
2013-02-18 05:22:18	149352	----a-w-	c:\windows\system32\drivers\nvhda32v.sys<br />
.<br />
============= FINISH: 16:55:11.84 ===============<br />
---------------------------------------------------------------------------------------------------------<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Professional <br />
Boot Device: \Device\HarddiskVolume2<br />
Install Date: 29/07/2010 01:49:28 PM<br />
System Uptime: 18/05/2013 04:44:54 PM (0 hours ago)<br />
.<br />
Motherboard: Intel Corp. |  | Base Board Product Name<br />
Processor: Intel(R) Core(TM) i3 CPU       M 350  @ 2.27GHz | CPU | 1994/1066mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 148 GiB total, 12.342 GiB free.<br />
D: is FIXED (NTFS) - 139 GiB total, 109.707 GiB free.<br />
E: is CDROM ()<br />
F: is Removable<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}<br />
Description: Officejet Pro 8500 A909g<br />
Device ID: ROOT\MULTIFUNCTION\0000<br />
Manufacturer: HP<br />
Name: Officejet Pro 8500 A909g<br />
PNP Device ID: ROOT\MULTIFUNCTION\0000<br />
Service: <br />
.<br />
Class GUID: <br />
Description: HP LaserJet Professional M1217nfw MFP<br />
Device ID: ROOT\MULTIFUNCTION\0001<br />
Manufacturer: <br />
Name: HP LaserJet Professional M1217nfw MFP<br />
PNP Device ID: ROOT\MULTIFUNCTION\0001<br />
Service: <br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP401: 18/05/2013 10:37:07 AM - Removed Network Recording Player<br />
RP402: 18/05/2013 11:44:36 AM - Norton 360 Registry Clean<br />
.<br />
==== Installed Programs ======================<br />
.<br />
32 Bit HP CIO Components Installer<br />
Adobe AIR<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Reader XI (11.0.03)<br />
Adobe Shockwave Player 11.6<br />
ALTools Update<br />
ALZip 8.51<br />
Any DWG DXF Converter 2013<br />
Any PDF to DWG Converter 2013<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver<br />
Battlelog Web Plugins<br />
BitTorrent<br />
BlackBerry Desktop Software 7.1<br />
bpd_scan<br />
bpd_scan_Carrier<br />
BREEZE 3D Analyst<br />
BREEZE AERMOD-ISC<br />
CAESAR II 2011-Demo<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
CyberLink YouCam<br />
D-Link AirPlus Xtreme G AP Manager for DWL-2100AP<br />
D3DX10<br />
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition<br />
Dishonored<br />
Dropbox<br />
ESN Sonar<br />
Extended Asian Language font pack for Adobe Reader XI<br />
EzManual<br />
Feedback Tool<br />
Google Chrome<br />
Google Earth<br />
Google Update Helper<br />
GPL Ghostscript 8.71<br />
Greenshot<br />
Hola™ 1.1.26 - Better Internet<br />
HP Update<br />
hppLaserJetService<br />
hppM1130M1210SeriesLaserJetService<br />
hppusgM1130M1210Series<br />
Inkscape 0.48.4<br />
Intel(R) Control Center<br />
Intel(R) Rapid Storage Technology<br />
Java 7 Update 21<br />
Java Auto Updater<br />
Junk Mail filter update<br />
Kyocera Product Library<br />
Kyocera TWAIN Driver<br />
Lakes Environmental AERMOD View V.7.6.1<br />
Lakes Environmental Screen View V.3.0.0<br />
LG Intelligent Update<br />
LG Magnifier<br />
LG OSD<br />
LG Smart Care<br />
LG Smart Indicator<br />
LG Smart Recovery<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft .NET Framework 4 Extended<br />
Microsoft .NET Framework 4 Multi-Targeting Pack<br />
Microsoft Application Error Reporting<br />
Microsoft Help Viewer 1.0<br />
Microsoft Office 2010 Service Pack 1 (SP1)<br />
Microsoft Office Access MUI (English) 2010<br />
Microsoft Office Access Setup Metadata MUI (English) 2010<br />
Microsoft Office Excel MUI (English) 2010<br />
Microsoft Office Home and Student 2010<br />
Microsoft Office Live Add-in 1.3<br />
Microsoft Office on Demand Browser Add-ons<br />
Microsoft Office OneNote MUI (English) 2010<br />
Microsoft Office Outlook MUI (English) 2010<br />
Microsoft Office PowerPoint MUI (English) 2010<br />
Microsoft Office Proof (English) 2010<br />
Microsoft Office Proof (French) 2010<br />
Microsoft Office Proof (Spanish) 2010<br />
Microsoft Office Proofing (English) 2010<br />
Microsoft Office Publisher MUI (English) 2010<br />
Microsoft Office Shared MUI (English) 2010<br />
Microsoft Office Shared Setup Metadata MUI (English) 2010<br />
Microsoft Office Single Image 2010<br />
Microsoft Office Word MUI (English) 2010<br />
Microsoft Silverlight<br />
Microsoft SkyDrive<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft SQL Server 2008<br />
Microsoft SQL Server 2008 Browser<br />
Microsoft SQL Server 2008 Common Files<br />
Microsoft SQL Server 2008 Database Engine Services<br />
Microsoft SQL Server 2008 Database Engine Shared<br />
Microsoft SQL Server 2008 Native Client<br />
Microsoft SQL Server 2008 R2 Management Objects<br />
Microsoft SQL Server 2008 RsFx Driver<br />
Microsoft SQL Server 2008 Setup Support Files <br />
Microsoft SQL Server Compact 3.5 SP2 ENU<br />
Microsoft SQL Server System CLR Types<br />
Microsoft SQL Server VSS Writer<br />
Microsoft Visual C# 2010 Express - ENU<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools<br />
MozBackup 1.5.1<br />
Mozilla Firefox 14.0.1 (x86 en-US)<br />
Mozilla Maintenance Service<br />
Mozilla Thunderbird 17.0.6 (x86 en-GB)<br />
MPICH2<br />
MSI Afterburner 2.3.1<br />
MSVCRT<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
Mumble 1.2.3<br />
MySQL Server 5.5<br />
Nitro PDF Professional<br />
Nitro PDF Professional 6.2<br />
Norton 360<br />
Norton Internet Security<br />
NVIDIA 3D Vision Driver 285.62<br />
NVIDIA Control Panel 285.62<br />
NVIDIA Display Control Panel<br />
NVIDIA Graphics Driver 285.62<br />
NVIDIA HD Audio Driver 1.3.18.0<br />
NVIDIA Install Application<br />
NVIDIA PhysX<br />
NVIDIA Stereoscopic 3D Driver<br />
NVIDIA Update 1.5.20<br />
NVIDIA Update Components<br />
Ora Time and Expense<br />
QuickTime<br />
Rapport<br />
Realtek High Definition Audio Driver<br />
Realtek USB 2.0 Card Reader<br />
REALTEK Wireless LAN Driver<br />
RedMon - Redirection Port Monitor<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)<br />
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition<br />
Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition<br />
Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2553091)<br />
Security Update for Microsoft Office 2010 (KB2553096)<br />
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition<br />
Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition<br />
Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition<br />
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition<br />
Service Pack 1 for SQL Server 2008 (KB968369)<br />
Skype Click to Call<br />
Skype™ 6.3<br />
SolidWorks eDrawings 2012<br />
SoundPLAN 7.2 (remove only)<br />
Sql Server Customer Experience Improvement Program<br />
Steam<br />
Striata Reader<br />
swMSM<br />
Synaptics Pointing Device Driver<br />
Tanks409d<br />
TeamSpeak 3 Client<br />
TeamViewer 8<br />
Time &amp; Expense Sheet Manager V4.1<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Update for Microsoft .NET Framework 4 Extended (KB2468871)<br />
Update for Microsoft .NET Framework 4 Extended (KB2533523)<br />
Update for Microsoft .NET Framework 4 Extended (KB2600217)<br />
Update for Microsoft Office 2010 (KB2494150)<br />
Update for Microsoft Office 2010 (KB2553065)<br />
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2566458)<br />
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition<br />
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition<br />
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition<br />
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition<br />
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition<br />
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition<br />
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU<br />
VLC media player 2.0.6<br />
Vodafone Mobile Connect Lite<br />
WIDCOMM Bluetooth Software<br />
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800)<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Family Safety<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Mail<br />
Windows Live Messenger<br />
Windows Live MIME IFilter<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live Sync<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
Windows Media Player Firefox Plugin<br />
WindRose ver.4.15-6.08<br />
WinDust Pro<br />
WinRAR 4.20 (32-bit)<br />
WinZip 14.5<br />
Yahoo! Detect<br />
.</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>shaunwkc</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256963-Win32-Sirefef.gen!C-Please-help</guid>
		</item>
		<item>
			<title><![CDATA[[RESOLVED] UPDATECHECKER.EXE]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256915-RESOLVED-UPDATECHECKER.EXE&amp;goto=newpost</link>
			<pubDate>Tue, 14 May 2013 14:48:27 GMT</pubDate>
			<description>Using: 
Windows 7 Premium--64 bit 
SuperAntiSpyware--Professional 
Malwarebites--free 
Avast--free 
 
For the last 2 mornings every time I turn on my computer, SuperAntiSpyware always tells me I have a Trojan. It listed as: SYSWOW64\C2\UPDATECHECKER.EXE    
 
I have checked this file with all my...</description>
			<content:encoded><![CDATA[<div>Using:<br />
Windows 7 Premium--64 bit<br />
SuperAntiSpyware--Professional<br />
Malwarebites--free<br />
Avast--free<br />
<br />
For the last 2 mornings every time I turn on my computer, SuperAntiSpyware always tells me I have a Trojan. It listed as: SYSWOW64\C2\UPDATECHECKER.EXE   <br />
<br />
I have checked this file with all my other security ware and none of them seem to think anything is wrong with this file. The only reason I have hesitated about doing anything with this file is because I suspect it has something to do with C-Net's TechTracker. I have use TechTracker for years with no problems. It keeps track of all the software I download from C-Net and lets me know whenever they are out of date and needs to be updated--also provides me with the ability to download the updates right from the TechTracker. I have used C-Net for over 10 years to download most of my programs and have never received any thing nasty from them--considered a safe site to download from. Once a long time ago C-net warned that when you downloaded something from their site that your security ware would tell you that their downloader was a virus/Trojan but that it was not. So it was only after I updated some of my software, using TechTracker, that I started getting a notice from SuperAntiSpyware that I had a Trojan. So do you know if this really is a Trojan, or if it probably has something to do with the TechTracker, and thus, would not really be harmful? <br />
Thanks,<br />
  Sheila</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>gypsy63</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256915-RESOLVED-UPDATECHECKER.EXE</guid>
		</item>
		<item>
			<title><![CDATA[[RESOLVED] Internet Security Virus]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256883-RESOLVED-Internet-Security-Virus&amp;goto=newpost</link>
			<pubDate>Sat, 11 May 2013 03:41:23 GMT</pubDate>
			<description>A virus keeps popping up called Internet Security that performs a fake scan. 
 
Here are the scans: 
 
Malwarebytes Anti-Malware 1.75.0.1300 
www.malwarebytes.org 
 
Database version: v2013.05.06.01 
 
Windows 7 x64 NTFS (Safe Mode)</description>
			<content:encoded><![CDATA[<div>A virus keeps popping up called Internet Security that performs a fake scan.<br />
<br />
Here are the scans:<br />
<br />
Malwarebytes Anti-Malware 1.75.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.05.06.01<br />
<br />
Windows 7 x64 NTFS (Safe Mode)<br />
Internet Explorer 9.0.8112.16421<br />
Clare :: CLARE-PC [administrator]<br />
<br />
5/9/2013 11:01:50 AM<br />
mbam-log-2013-05-09 (11-01-50).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 241327<br />
Time elapsed: 5 minute(s), 46 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 1<br />
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Internet Security (Trojan.FakeAV) -&gt; Data: C:\ProgramData\amsecure.exe -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 2<br />
C:\conhost.exe (Trojan.FakeMS) -&gt; Quarantined and deleted successfully.<br />
C:\ProgramData\amsecure.exe (Trojan.FakeAV) -&gt; Quarantined and deleted successfully.<br />
<br />
(end)</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>merle211</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256883-RESOLVED-Internet-Security-Virus</guid>
		</item>
		<item>
			<title><![CDATA[[RESOLVED] Help with MixDJ and search.conduit]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256855-RESOLVED-Help-with-MixDJ-and-search.conduit&amp;goto=newpost</link>
			<pubDate>Wed, 08 May 2013 21:57:19 GMT</pubDate>
			<description>I downloaded these as add-ons by mistake.  Not sure if they are the same or separate malware. 
 
Running a malwarebytes scan now and will post the log. 
 
Any help is appreciated.  Thank you.</description>
			<content:encoded><![CDATA[<div>I downloaded these as add-ons by mistake.  Not sure if they are the same or separate malware.<br />
<br />
Running a malwarebytes scan now and will post the log.<br />
<br />
Any help is appreciated.  Thank you.</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>kanstar</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256855-RESOLVED-Help-with-MixDJ-and-search.conduit</guid>
		</item>
		<item>
			<title><![CDATA[[RESOLVED] System Care AV Virus?]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256821-RESOLVED-System-Care-AV-Virus&amp;goto=newpost</link>
			<pubDate>Mon, 06 May 2013 16:12:11 GMT</pubDate>
			<description>I was surfing a website and all of a sudden my firefox browser closed and a program called system care antivirus began scanning my system and it was finding a number of files.  I never installed this system care AV on my system but when I went to start/all prgrams, the program was listed in there. ...</description>
			<content:encoded><![CDATA[<div>I was surfing a website and all of a sudden my firefox browser closed and a program called system care antivirus began scanning my system and it was finding a number of files.  I never installed this system care AV on my system but when I went to start/all prgrams, the program was listed in there.  I can't even access some of my files.  I couldn't run my av that I had installed on my computer which was microsoft security essentials or my Malwarebytes.  I even tried unistalling microsoft SE using revo uninstaller and it gave me an error message when I first attempted to uninstall it.  I couldn't access many of my files.  I tried doing a system restore and it wouldn't open that either.  What I did before posting here was I went into safe mode and tried to do a system restore from there and then it coculdn't restore it and asked to try again after rebooting back into windows.  I tried again and then system restore was successful.  This system care AV is not showing up in the list under start/all programs anymore since I was finally able to do a system restore successfully.  But, I still can't access some programs.  <br />
<br />
I had to install Avast since microsoft security essentials won't open and run on my computer.  I tried to reinstall microsoft SE but it said there already is a version on my computer.  After I ran Avast AV, it found a good number of files which I quarantined after the scan.  When I tried to run malwarebytes which was already on my system as well, it won't open that program either and it asked me to reinstall the program which I did so I could run it.  Below is the logs of malwarebytes and DDS runs.<br />
<br />
<br />
<br />
Malwarebytes Anti-Malware 1.70.0.1100<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.05.06.06<br />
<br />
Windows XP Service Pack 3 x86 NTFS<br />
Internet Explorer 8.0.6001.18702<br />
Dave :: DAVE-835A839979 [administrator]<br />
<br />
5/6/2013 11:30:36 AM<br />
mbam-log-2013-05-06 (11-30-36).txt<br />
<br />
Scan type: Full scan (C:\|D:\|E:\|)<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 238473<br />
Time elapsed: 12 minute(s), 21 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 1<br />
C:\RECYCLER\S-1-5-18\$2f7a1e352a1def77d5e33ef0c48bef8e\U\00000001.@ (Trojan.0Access) -&gt; Quarantined and deleted successfully.<br />
<br />
(end)<br />
<br />
<br />
<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_x86 <br />
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.17.2<br />
Run by Dave at 11:53:06 on 2013-05-06<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3326.2109 [GMT -4:00]<br />
.<br />
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}<br />
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}<br />
.<br />
============== Running Processes ================<br />
.<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\Ati2evxx.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Google\Update\1.3.21.145\GoogleCrashHandler.exe<br />
C:\WINDOWS\StartupMonitor.exe<br />
C:\Documents and Settings\Dave\Local Settings\Apps\F.lux\flux.exe<br />
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe<br />
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe<br />
C:\Program Files\Java\jre7\bin\jqs.exe<br />
C:\Program Files\Secunia\PSI\PSIA.exe<br />
C:\WINDOWS\wanmpsvc.exe<br />
C:\Program Files\Raxco\PerfectDisk\PDSched.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\Program Files\Secunia\PSI\sua.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Program Files\Google\Drive\googledrivesync.exe<br />
C:\Program Files\Google\Drive\googledrivesync.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\Program Files\Google\Chrome\Application\chrome.exe<br />
C:\WINDOWS\notepad.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k NetworkService<br />
C:\WINDOWS\system32\svchost.exe -k LocalService<br />
C:\WINDOWS\system32\svchost.exe -k LocalService<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll<br />
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll<br />
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL<br />
BHO: Tracker Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll<br />
TB: Tracker Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
TB: Tracker Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll<br />
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll<br />
EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll<br />
uRun: [MonitorES] e:\saved files before backup and reformat\downloads programs\MonitorES_Lite.exe<br />
uRun: [F.lux] &quot;c:\documents and settings\dave\local settings\apps\f.lux\flux.exe&quot; /noshow<br />
mRun: [Run StartupMonitor] StartupMonitor.exe<br />
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000<br />
IE: Se&amp;nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll<br />
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}<br />
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1358593450468<br />
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1358616107265<br />
TCP: NameServer = 192.168.1.1<br />
TCP: Interfaces\{2BBD3C98-3D2B-402E-88F1-062F42B8286F} : DHCPNameServer = 192.168.1.1<br />
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL<br />
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll<br />
Notify: AtiExtEvent - Ati2evxx.dll<br />
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll<br />
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL<br />
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - &quot;c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe&quot; --configure-user-settings --verbose-logging --system-level --multi-install --chrome<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\dave\application data\mozilla\firefox\profiles\nvlxhlns.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://slickdeals.net/forums/forumdisplay.php?f=9|<a rel="nofollow" href="http://www.fatwallet.com/forums/hot-deals/|http://www.afullcup.com/forums/index.php|http://onefrugalchick.com/|http://www.whosaidnothinginlifeisfree.com/|http://www.cuckooforcoupondeals.com/" target="_blank">http://www.fatwallet.com/forums/hot-...upondeals.com/</a><br />
FF - plugin: c:\docume~1\dave\applic~1\catali~2\npBcsKtTcHW.dll<br />
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL<br />
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll<br />
FF - plugin: c:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll<br />
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll<br />
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll<br />
FF - plugin: c:\windows\system32\npDeployJava1.dll<br />
FF - plugin: c:\windows\system32\npptools.dll<br />
FF - plugin: c:\windows\system32\npwmsdrm.dll<br />
FF - ExtSQL: 2013-05-05 13:11; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension<br />
FF - ExtSQL: 2013-05-06 11:09; <a href="mailto:wrc@avast.com">wrc@avast.com</a>; c:\program files\avast software\avast\webrep\FF<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-5-6 174664]<br />
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 195296]<br />
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-5-6 368944]<br />
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-5-6 29816]<br />
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-5-6 66336]<br />
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-5-6 46808]<br />
R2 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2013-1-18 68136]<br />
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2013-1-19 12184]<br />
R2 PDSched;PDScheduler;c:\program files\raxco\perfectdisk\PDSched.exe [2004-2-11 200771]<br />
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2012-11-26 1225312]<br />
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2012-11-26 659040]<br />
R3 jakndisMP;jakndisMP;c:\windows\system32\drivers\jakndis.sys [2013-1-21 30016]<br />
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [2011-9-2 42648]<br />
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [2011-9-2 12184]<br />
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-5-6 40776]<br />
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]<br />
S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-5-6 49376]<br />
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-5-6 765736]<br />
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-2-28 161384]<br />
S3 jakndis;Jaksta Service;c:\windows\system32\drivers\jakndis.sys [2013-1-21 30016]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-06 15:43:35	54016	----a-w-	c:\windows\system32\drivers\chfgfd.sys<br />
2013-05-06 15:09:18	765736	----a-w-	c:\windows\system32\drivers\aswSnx.sys<br />
2013-05-06 15:09:18	174664	----a-w-	c:\windows\system32\drivers\aswVmm.sys<br />
2013-05-06 15:09:17	49376	----a-w-	c:\windows\system32\drivers\aswRvrt.sys<br />
2013-05-06 15:09:16	66336	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys<br />
2013-05-06 15:08:54	41664	----a-w-	c:\windows\avastSS.scr<br />
2013-05-06 15:08:40	--------	d-----w-	c:\program files\AVAST Software<br />
2013-05-06 15:07:24	--------	d-----w-	c:\documents and settings\all users\application data\AVAST Software<br />
2013-05-06 14:03:59	40776	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys<br />
2013-05-06 13:43:33	--------	d-----w-	c:\windows\system32\wbem\repository\FS<br />
2013-05-06 13:43:32	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2013-05-06 12:06:14	--------	d-----w-	c:\documents and settings\all users\application data\105FA8A4779130F00000105F984A3647<br />
2013-05-05 17:17:29	--------	d-----w-	c:\program files\MSXML 4.0<br />
2013-05-05 17:09:55	12928	-c----w-	c:\windows\system32\dllcache\usb8023x.sys<br />
2013-05-05 15:49:24	--------	d-----w-	c:\windows\system32\XPSViewer<br />
2013-05-05 15:49:05	89088	----a-w-	c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll<br />
2013-05-05 15:48:55	89088	-c----w-	c:\windows\system32\dllcache\filterpipelineprintproc.dll<br />
2013-05-05 15:48:55	597504	-c----w-	c:\windows\system32\dllcache\printfilterpipelinesvc.exe<br />
2013-05-05 15:48:55	597504	------w-	c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe<br />
2013-05-05 15:48:55	575488	-c----w-	c:\windows\system32\dllcache\xpsshhdr.dll<br />
2013-05-05 15:48:55	575488	------w-	c:\windows\system32\xpsshhdr.dll<br />
2013-05-05 15:48:55	1676288	-c----w-	c:\windows\system32\dllcache\xpssvcs.dll<br />
2013-05-05 15:48:55	1676288	------w-	c:\windows\system32\xpssvcs.dll<br />
2013-05-05 15:48:55	117760	------w-	c:\windows\system32\prntvpt.dll<br />
2013-05-05 02:57:15	6906960	----a-w-	c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{56c65cb1-863d-4b72-84f8-592386c76709}\mpengine.dll<br />
2013-05-04 02:57:27	6906960	----a-w-	c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-06 14:58:28	17488	----a-w-	c:\windows\gdrv.sys<br />
2013-05-02 15:28:50	238872	------w-	c:\windows\system32\MpSigStub.exe<br />
2013-03-18 19:56:28	693976	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
2013-03-18 19:56:27	73432	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2013-03-10 10:20:53	94112	----a-w-	c:\windows\system32\WindowsAccessBridge.dll<br />
2013-03-10 10:20:52	861088	----a-w-	c:\windows\system32\npDeployJava1.dll<br />
2013-03-10 10:20:52	782240	----a-w-	c:\windows\system32\deployJava1.dll<br />
2013-03-10 10:20:52	143872	----a-w-	c:\windows\system32\javacpl.cpl<br />
2013-03-08 08:36:22	293376	----a-w-	c:\windows\system32\winsrv.dll<br />
2013-03-07 01:32:25	2149888	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2013-03-07 00:50:30	2028544	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2013-03-02 02:06:31	916480	----a-w-	c:\windows\system32\wininet.dll<br />
2013-03-02 02:06:30	43520	----a-w-	c:\windows\system32\licmgr10.dll<br />
2013-03-02 02:06:30	1469440	----a-w-	c:\windows\system32\inetcpl.cpl<br />
2013-03-02 01:25:02	1867264	----a-w-	c:\windows\system32\win32k.sys<br />
2013-03-02 01:08:47	385024	----a-w-	c:\windows\system32\html.iec<br />
2013-02-27 07:56:51	2067456	----a-w-	c:\windows\system32\mstscax.dll<br />
2013-02-14 07:30:19	465280	----a-r-	c:\windows\system32\cpnprt2win32.cid<br />
2013-02-12 00:32:23	12928	----a-w-	c:\windows\system32\drivers\usb8023.sys<br />
.<br />
============= FINISH: 11:53:18.64 ===============<br />
<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows XP Professional<br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 1/18/2013 7:32:38 PM<br />
System Uptime: 5/6/2013 10:57:45 AM (1 hours ago)<br />
.<br />
Motherboard: Gigabyte Technology Co., Ltd. |  | EP45-UD3P<br />
Processor: Intel Pentium III Xeon processor | Socket 775 | 2999/333mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
A: is Removable<br />
C: is FIXED (NTFS) - 98 GiB total, 80.322 GiB free.<br />
D: is FIXED (NTFS) - 195 GiB total, 194.838 GiB free.<br />
E: is FIXED (NTFS) - 639 GiB total, 637.601 GiB free.<br />
F: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP152: 5/5/2013 2:02:24 PM - Software Distribution Service 3.0<br />
RP153: 5/6/2013 9:06:49 AM - Restore Operation<br />
RP154: 5/6/2013 9:08:08 AM - Restore Operation<br />
RP155: 5/6/2013 9:22:42 AM - Revo Uninstaller's restore point - Microsoft Security Essentials<br />
RP156: 5/6/2013 9:23:22 AM - Revo Uninstaller's restore point - Microsoft Security Essentials<br />
RP157: 5/6/2013 9:23:34 AM - Revo Uninstaller's restore point - Microsoft Security Essentials<br />
RP158: 5/6/2013 9:23:43 AM - Revo Uninstaller's restore point - Microsoft Security Essentials<br />
RP159: 5/6/2013 9:25:04 AM - Before Microsoft Security Essentials Revo Uninstall<br />
RP160: 5/6/2013 9:25:50 AM - Revo Uninstaller's restore point - Microsoft Security Essentials<br />
RP161: 5/6/2013 9:25:59 AM - Revo Uninstaller's restore point - Microsoft Security Essentials<br />
RP162: 5/6/2013 9:41:44 AM - Restore Operation<br />
RP163: 5/6/2013 11:08:40 AM - avast! Free Antivirus Setup<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
America Online (Choose which version to remove)<br />
AOL Coach Version 1.0(Build:20030807.3)<br />
Ask Toolbar<br />
ATI - Software Uninstall Utility<br />
ATI Catalyst Control Center<br />
ATI Display Driver<br />
ATI HYDRAVISION<br />
ATI Problem Report Wizard<br />
avast! Free Antivirus<br />
Belarc Advisor 8.3<br />
BufferChm<br />
CaptureWizPro 4.50<br />
Catalina Savings Printer<br />
Catalyst Control Center - Branding<br />
Catalyst Control Center Core Implementation<br />
Catalyst Control Center Graphics Full Existing<br />
Catalyst Control Center Graphics Full New<br />
Catalyst Control Center Graphics Light<br />
Catalyst Control Center Graphics Previews Common<br />
Catalyst Control Center HydraVision Full<br />
Catalyst Control Center Localization All<br />
ccc-core-preinstall<br />
ccc-core-static<br />
ccc-utility<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
CCleaner<br />
Coupon Printer for Windows<br />
Daum PotPlayer 1.5.29795<br />
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition<br />
Destinations<br />
DeviceManagementQFolder<br />
Dropbox<br />
Energy Saver Advance B9.0316.1<br />
eReg<br />
eSupportQFolder<br />
F.lux<br />
FileHippo.com Update Checker<br />
Free Mp3 Wma Converter V 2.2<br />
Gigabyte Raid Configurer<br />
Google Chrome<br />
Google Drive<br />
Google Earth<br />
Google Update Helper<br />
H&amp;R Block Deluxe + Efile + State 2012<br />
H&amp;R Block Pennsylvania 2012<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
Hotfix for Windows XP (KB2779562)<br />
Hotfix for Windows XP (KB952287)<br />
Hotfix for Windows XP (KB954550-v5)<br />
Hotfix for Windows XP (KB961118)<br />
HP Imaging Device Functions 7.0<br />
HP Scanjet G4000 series 8.0<br />
HP Solution Center 7.0<br />
hpG4000<br />
hpg4000QFolder<br />
HPProductAssistant<br />
ImgBurn<br />
Jaksta Streaming Media Recorder (4.4.3)<br />
Java 7 Update 17<br />
Java Auto Updater<br />
Learn2 Player (Uninstall Only)<br />
Logitech SetPoint 6.32<br />
Malwarebytes Anti-Malware version 1.70.0.1100<br />
Microsoft .NET Framework 2.0 Service Pack 2<br />
Microsoft .NET Framework 3.0 Service Pack 2<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Application Error Reporting<br />
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9<br />
Microsoft Office 2010 Service Pack 1 (SP1)<br />
Microsoft Office Access MUI (English) 2010<br />
Microsoft Office Access Setup Metadata MUI (English) 2010<br />
Microsoft Office Excel MUI (English) 2010<br />
Microsoft Office Groove MUI (English) 2010<br />
Microsoft Office InfoPath MUI (English) 2010<br />
Microsoft Office OneNote 2003<br />
Microsoft Office OneNote MUI (English) 2010<br />
Microsoft Office Outlook MUI (English) 2010<br />
Microsoft Office PowerPoint MUI (English) 2010<br />
Microsoft Office Professional Plus 2010<br />
Microsoft Office Proof (English) 2010<br />
Microsoft Office Proof (French) 2010<br />
Microsoft Office Proof (Spanish) 2010<br />
Microsoft Office Proofing (English) 2010<br />
Microsoft Office Publisher MUI (English) 2010<br />
Microsoft Office Shared MUI (English) 2010<br />
Microsoft Office Shared Setup Metadata MUI (English) 2010<br />
Microsoft Office Word MUI (English) 2010<br />
Microsoft Security Client<br />
Microsoft Security Essentials<br />
Microsoft Software Update for Web Folders  (English) 14<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Mozilla Firefox 20.0.1 (x86 en-US)<br />
MSXML 4.0 SP2 (KB954430)<br />
PanoStandAlone<br />
PDF-Viewer<br />
PerfectDisk<br />
QuickTime<br />
RealPlayer Basic<br />
REALTEK GbE &amp; FE Ethernet PCI-E NIC Driver<br />
Realtek High Definition Audio Driver<br />
Replay Telecorder for Skype 1.3.0.12<br />
Revo Uninstaller 1.94<br />
Scan<br />
ScannerCopy<br />
Secunia PSI (3.0.0.6001)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)<br />
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition<br />
Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition<br />
Security Update for Microsoft InfoPath 2010 (KB2687422) 32-Bit Edition<br />
Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2553091)<br />
Security Update for Microsoft Office 2010 (KB2553096)<br />
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2589337) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition<br />
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition<br />
Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition<br />
Security Update for Microsoft Visio 2010 (KB2760762) 32-Bit Edition<br />
Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition<br />
Security Update for Microsoft Windows (KB2564958)<br />
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition<br />
Security Update for Windows Internet Explorer 8 (KB2510531)<br />
Security Update for Windows Internet Explorer 8 (KB2817183)<br />
Security Update for Windows Media Player (KB2378111)<br />
Security Update for Windows Media Player (KB952069)<br />
Security Update for Windows Media Player (KB954155)<br />
Security Update for Windows Media Player (KB973540)<br />
Security Update for Windows Media Player (KB975558)<br />
Security Update for Windows Media Player (KB978695)<br />
Security Update for Windows XP (KB2115168)<br />
Security Update for Windows XP (KB2229593)<br />
Security Update for Windows XP (KB2296011)<br />
Security Update for Windows XP (KB2347290)<br />
Security Update for Windows XP (KB2360937)<br />
Security Update for Windows XP (KB2387149)<br />
Security Update for Windows XP (KB2393802)<br />
Security Update for Windows XP (KB2419632)<br />
Security Update for Windows XP (KB2423089)<br />
Security Update for Windows XP (KB2440591)<br />
Security Update for Windows XP (KB2443105)<br />
Security Update for Windows XP (KB2476490)<br />
Security Update for Windows XP (KB2478960)<br />
Security Update for Windows XP (KB2478971)<br />
Security Update for Windows XP (KB2479943)<br />
Security Update for Windows XP (KB2481109)<br />
Security Update for Windows XP (KB2483185)<br />
Security Update for Windows XP (KB2485663)<br />
Security Update for Windows XP (KB2506212)<br />
Security Update for Windows XP (KB2507938)<br />
Security Update for Windows XP (KB2508429)<br />
Security Update for Windows XP (KB2509553)<br />
Security Update for Windows XP (KB2510581)<br />
Security Update for Windows XP (KB2535512)<br />
Security Update for Windows XP (KB2536276-v2)<br />
Security Update for Windows XP (KB2544521)<br />
Security Update for Windows XP (KB2544893-v2)<br />
Security Update for Windows XP (KB2566454)<br />
Security Update for Windows XP (KB2570947)<br />
Security Update for Windows XP (KB2584146)<br />
Security Update for Windows XP (KB2585542)<br />
Security Update for Windows XP (KB2592799)<br />
Security Update for Windows XP (KB2598479)<br />
Security Update for Windows XP (KB2603381)<br />
Security Update for Windows XP (KB2618451)<br />
Security Update for Windows XP (KB2619339)<br />
Security Update for Windows XP (KB2620712)<br />
Security Update for Windows XP (KB2624667)<br />
Security Update for Windows XP (KB2631813)<br />
Security Update for Windows XP (KB2646524)<br />
Security Update for Windows XP (KB2653956)<br />
Security Update for Windows XP (KB2655992)<br />
Security Update for Windows XP (KB2659262)<br />
Security Update for Windows XP (KB2661637)<br />
Security Update for Windows XP (KB2676562)<br />
Security Update for Windows XP (KB2686509)<br />
Security Update for Windows XP (KB2691442)<br />
Security Update for Windows XP (KB2698365)<br />
Security Update for Windows XP (KB2705219-v2)<br />
Security Update for Windows XP (KB2712808)<br />
Security Update for Windows XP (KB2719985)<br />
Security Update for Windows XP (KB2723135-v2)<br />
Security Update for Windows XP (KB2724197)<br />
Security Update for Windows XP (KB2727528)<br />
Security Update for Windows XP (KB2753842-v2)<br />
Security Update for Windows XP (KB2757638)<br />
Security Update for Windows XP (KB2758857)<br />
Security Update for Windows XP (KB2761465)<br />
Security Update for Windows XP (KB2770660)<br />
Security Update for Windows XP (KB2779030)<br />
Security Update for Windows XP (KB2780091)<br />
Security Update for Windows XP (KB2799329)<br />
Security Update for Windows XP (KB2802968)<br />
Security Update for Windows XP (KB2807986)<br />
Security Update for Windows XP (KB2808735)<br />
Security Update for Windows XP (KB2813170)<br />
Security Update for Windows XP (KB2813345)<br />
Security Update for Windows XP (KB2820917)<br />
Security Update for Windows XP (KB923561)<br />
Security Update for Windows XP (KB923789)<br />
Security Update for Windows XP (KB946648)<br />
Security Update for Windows XP (KB950762)<br />
Security Update for Windows XP (KB950974)<br />
Security Update for Windows XP (KB951376-v2)<br />
Security Update for Windows XP (KB952004)<br />
Security Update for Windows XP (KB952954)<br />
Security Update for Windows XP (KB956572)<br />
Security Update for Windows XP (KB956744)<br />
Security Update for Windows XP (KB956802)<br />
Security Update for Windows XP (KB956844)<br />
Security Update for Windows XP (KB959426)<br />
Security Update for Windows XP (KB960803)<br />
Security Update for Windows XP (KB960859)<br />
Security Update for Windows XP (KB969059)<br />
Security Update for Windows XP (KB970430)<br />
Security Update for Windows XP (KB971657)<br />
Security Update for Windows XP (KB972270)<br />
Security Update for Windows XP (KB973507)<br />
Security Update for Windows XP (KB973869)<br />
Security Update for Windows XP (KB973904)<br />
Security Update for Windows XP (KB974112)<br />
Security Update for Windows XP (KB974318)<br />
Security Update for Windows XP (KB974392)<br />
Security Update for Windows XP (KB974571)<br />
Security Update for Windows XP (KB975025)<br />
Security Update for Windows XP (KB975467)<br />
Security Update for Windows XP (KB975560)<br />
Security Update for Windows XP (KB975713)<br />
Security Update for Windows XP (KB977816)<br />
Security Update for Windows XP (KB977914)<br />
Security Update for Windows XP (KB978338)<br />
Security Update for Windows XP (KB978542)<br />
Security Update for Windows XP (KB978706)<br />
Security Update for Windows XP (KB979309)<br />
Security Update for Windows XP (KB979482)<br />
Security Update for Windows XP (KB979687)<br />
Security Update for Windows XP (KB981322)<br />
Security Update for Windows XP (KB981997)<br />
Security Update for Windows XP (KB982132)<br />
Security Update for Windows XP (KB982665)<br />
Skype™ 6.3<br />
SolutionCenter<br />
StartupMonitor<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Microsoft Office 2010 (KB2553065)<br />
Update for Microsoft Office 2010 (KB2553092)<br />
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2566458)<br />
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition<br />
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition<br />
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition<br />
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition<br />
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition<br />
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition<br />
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition<br />
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition<br />
Update for Windows XP (KB2345886)<br />
Update for Windows XP (KB2467659)<br />
Update for Windows XP (KB2661254-v2)<br />
Update for Windows XP (KB2736233)<br />
Update for Windows XP (KB2749655)<br />
Update for Windows XP (KB898461)<br />
Update for Windows XP (KB951978)<br />
Update for Windows XP (KB955759)<br />
Update for Windows XP (KB968389)<br />
Update for Windows XP (KB971029)<br />
Update for Windows XP (KB973815)<br />
Viewpoint Media Player<br />
VuePrint<br />
WebFldrs XP<br />
WebReg<br />
Windows Genuine Advantage Notifications (KB905474)<br />
Windows Genuine Advantage Validation Tool (KB892130)<br />
Windows Internet Explorer 8<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
5/6/2013 9:12:40 AM, error: Service Control Manager [7031]  - The .NET Runtime Optimization Service v2.0.50727_X86 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/6/2013 8:38:19 AM, error: DCOM [10005]  - DCOM got error &quot;%1084&quot; attempting to start the service MSIServer with arguments &quot;&quot; in order to run the server: {000C101C-0000-0000-C000-000000000046}<br />
5/6/2013 8:27:01 AM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD BANTExt Fips intelppm IPSec MpFilter MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip<br />
5/6/2013 8:27:01 AM, error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/6/2013 8:27:01 AM, error: Service Control Manager [7001]  - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/6/2013 8:27:01 AM, error: Service Control Manager [7001]  - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/6/2013 8:27:01 AM, error: Service Control Manager [7001]  - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:  A device attached to the system is not functioning.<br />
5/6/2013 8:26:20 AM, error: DCOM [10005]  - DCOM got error &quot;%1084&quot; attempting to start the service StiSvc with arguments &quot;&quot; in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}<br />
5/6/2013 8:26:14 AM, error: DCOM [10005]  - DCOM got error &quot;%1084&quot; attempting to start the service EventSystem with arguments &quot;&quot; in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
5/6/2013 8:26:09 AM, error: DCOM [10005]  - DCOM got error &quot;%1084&quot; attempting to start the service netman with arguments &quot;&quot; in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}<br />
5/6/2013 8:22:07 AM, error: Service Control Manager [7034]  - The Skype Updater service terminated unexpectedly.  It has done this 1 time(s).<br />
5/6/2013 8:22:07 AM, error: Service Control Manager [7034]  - The PDEngine service terminated unexpectedly.  It has done this 2 time(s).<br />
5/6/2013 8:22:07 AM, error: Service Control Manager [7034]  - The PDEngine service terminated unexpectedly.  It has done this 1 time(s).<br />
5/6/2013 8:22:07 AM, error: Service Control Manager [7034]  - The IMAPI CD-Burning COM Service service terminated unexpectedly.  It has done this 1 time(s).<br />
5/6/2013 8:20:58 AM, error: Service Control Manager [7023]  - The Computer Browser service terminated with the following error:  The specified service does not exist as an installed service.<br />
5/6/2013 8:20:58 AM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the Secunia Update Agent service to connect.<br />
5/6/2013 8:20:58 AM, error: Service Control Manager [7000]  - The Secunia Update Agent service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
5/6/2013 8:12:16 AM, error: Service Control Manager [7034]  - The Office Software Protection Platform service terminated unexpectedly.  It has done this 1 time(s).<br />
5/6/2013 8:05:15 AM, error: Service Control Manager [7000]  - The Microsoft Antimalware Service service failed to start due to the following error:  The file can not be accessed by the system.<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The WAN Miniport (ATW) Service service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The Secunia Update Agent service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The Secunia PSI Agent service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The PDScheduler service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The Java Quick Starter service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The GEST Service for program management. service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The Ati HotKey Poller service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7034]  - The AOL Connectivity Service service terminated unexpectedly.  It has done this 1 time(s).<br />
5/2/2013 10:44:53 PM, error: Service Control Manager [7031]  - The Microsoft Antimalware Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 15000 milliseconds: Restart the service.<br />
4/30/2013 6:00:21 AM, error: SideBySide [59]  - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .<br />
4/30/2013 6:00:21 AM, error: SideBySide [59]  - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\MFC80.DLL. Reference error message: The operation completed successfully. .<br />
4/30/2013 6:00:21 AM, error: SideBySide [32]  - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.<br />
.<br />
==== End Of File ===========================</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>JLS</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256821-RESOLVED-System-Care-AV-Virus</guid>
		</item>
		<item>
			<title><![CDATA[[Inactive] can't open  home page, foxnews]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256817-Inactive-can-t-open-home-page-foxnews&amp;goto=newpost</link>
			<pubDate>Mon, 06 May 2013 15:55:10 GMT</pubDate>
			<description><![CDATA[I can't open with home page, Foxnews. I keep getting a page like http:start.sweetpacks.com. I think it is part of Microsoft.]]></description>
			<content:encoded><![CDATA[<div>I can't open with home page, Foxnews. I keep getting a page like http:start.sweetpacks.com. I think it is part of Microsoft.</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>townpump1</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256817-Inactive-can-t-open-home-page-foxnews</guid>
		</item>
		<item>
			<title>Google tells me Sirefef.gen!c</title>
			<link>http://discussions.virtualdr.com/showthread.php?256757-Google-tells-me-Sirefef.gen!c&amp;goto=newpost</link>
			<pubDate>Tue, 30 Apr 2013 11:46:28 GMT</pubDate>
			<description>Hey,    How are ya 
 
 
Google chrome just told me i have sirefef.gen!c  and refuses certain sites..    funny enough AVG antivirus doesnt tell me anything. 
After some quick google searching it seems to be hard to remove  and people keep referring(or reposting the same article) to removing it...</description>
			<content:encoded><![CDATA[<div>Hey,    How are ya<br />
<br />
<br />
Google chrome just told me i have sirefef.gen!c  and refuses certain sites..    funny enough AVG antivirus doesnt tell me anything.<br />
After some quick google searching it seems to be hard to remove  and people keep referring(or reposting the same article) to removing it manually and then provide a guide that doesnt add up.  <br />
<br />
Im hoping to get some help with this.<br />
<br />
ive read this <a rel="nofollow" href="http://discussions.virtualdr.com/showthread.php?167915-ALL-MEMBERS-PLEASE-READ-Rules-for-this-forum-%28Updated-4-28-2013%29" target="_blank">http://discussions.virtualdr.com/sho...d-4-28-2013%29</a> <br />
<br />
So im gonna proceed and download the malware  and the dds tool and  report back in the evening and post the logs. <br />
I also read a topic with a simmilar virus however i cant verify if i should jsut do what he did so i decided to open up a new topic and get advice from people who do know. <br />
<br />
Some quick questions,  can it steal my hotmail  password   and can it get my paypal password out of my cache or something like that? do i need to be worried about my paypal account?   <br />
im afraid to login because it might steal my password.<br />
<br />
thanks for the help so far.</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>Obsession</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256757-Google-tells-me-Sirefef.gen!c</guid>
		</item>
		<item>
			<title><![CDATA[[Inactive] Unknown Problem]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256751-Inactive-Unknown-Problem&amp;goto=newpost</link>
			<pubDate>Tue, 30 Apr 2013 03:44:10 GMT</pubDate>
			<description><![CDATA[I've been noticing for a while that my computer just doesn't feel right. Something went wrong with Firefox and everything was loading really slow and it was like it was constantly thinking in the background. So I uninstalled EVERYTHING having to do with Firefox. Every temp and cookie file, anything...]]></description>
			<content:encoded><![CDATA[<div>I've been noticing for a while that my computer just doesn't feel right. Something went wrong with Firefox and everything was loading really slow and it was like it was constantly thinking in the background. So I uninstalled EVERYTHING having to do with Firefox. Every temp and cookie file, anything related to it. Scanned with Adaware and Malwarebytes, then reinstalled. Its working fabulous now, but something's still not right. I tried playing Dead Frontier, and I am having constant loading and connection problems. They swear they're not having any problems with the servers, and a &quot;Security Error&quot; where the game disconnects from the server is always on the user's side. That's what they told me. I've also noticed my machine isn't as fast as it used to be. I've seen other people complaining about this, but most people have no problems at all. This is what an admin said:<br />
<br />
<div class="bbcode_container">
	<div class="bbcode_description">Quote:</div>
	<div class="bbcode_quote printable">
		<hr />
		
			Randomly not responding to the keyboard is usually graphic lag resulting in input lag(browser can cause those issues also, which can be caused by not enough CPU/RAM available).<br />
<br />
Security errors are usually caused by connection &quot;issues&quot; from the player to the server, as in data packets are being lost/super slow to arrive to the server or in some cases having Cheat Engine installed on your computer.
			
		<hr />
	</div>
</div> Like I said, I searched it with several programs. I only found a few of the usually minor things you get from typical web browsing, but nothing major. And that's whats worrying me. If there is something on my PC, its sneaky and that probably means its bad news. Can anyone help me figure out what's on my PC and help me find it... if its there? Please?</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>Judaeus Apella</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256751-Inactive-Unknown-Problem</guid>
		</item>
		<item>
			<title><![CDATA[[RESOLVED] WIN XP "Issues"]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256745-RESOLVED-WIN-XP-quot-Issues-quot&amp;goto=newpost</link>
			<pubDate>Mon, 29 Apr 2013 22:18:28 GMT</pubDate>
			<description>My friends WIN XP is suffering from severe slowness issues. I have ran MBAM and DDS and have copied here in an attempt to get some of the very helpful people at VirtualDr to take a look. 
 
Malwarebytes Anti-Malware (Trial) 1.75.0.1300 
www.malwarebytes.org 
 
Database version: v2013.04.29.09 
...</description>
			<content:encoded><![CDATA[<div>My friends WIN XP is suffering from severe slowness issues. I have ran MBAM and DDS and have copied here in an attempt to get some of the very helpful people at VirtualDr to take a look.<br />
<br />
Malwarebytes Anti-Malware (Trial) 1.75.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.04.29.09<br />
<br />
Windows XP Service Pack 3 x86 NTFS<br />
Internet Explorer 8.0.6001.18702<br />
Jim Salvo :: LAPTOP [administrator]<br />
<br />
Protection: Enabled<br />
<br />
4/29/2013 4:23:50 PM<br />
mbam-log-2013-04-29 (16-23-50).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 243355<br />
Time elapsed: 32 minute(s), 21 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 0<br />
(No malicious items detected)<br />
<br />
(end)<br />
<br />
<br />
<br />
DDS<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_x86 <br />
Internet Explorer: 8.0.6001.18702<br />
Run by Jim Salvo at 16:59:13 on 2013-04-29<br />
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.767.377 [GMT -5:00]<br />
.<br />
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}<br />
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}<br />
.<br />
============== Running Processes ================<br />
.<br />
c:\Program Files\Microsoft Security Client\MsMpEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br />
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br />
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe<br />
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe<br />
C:\Program Files\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\WINDOWS\system32\nvsvc32.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe<br />
C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe<br />
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br />
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy 2\SDUpdate.exe<br />
C:\Program Files\Common Files\Search Protection\spHost.exe<br />
C:\WINDOWS\wanmpsvc.exe<br />
C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe<br />
C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe<br />
C:\Program Files\Microsoft Security Client\msseces.exe<br />
C:\WINDOWS\system32\dla\tfswctrl.exe<br />
C:\WINDOWS\system32\BacsTray.exe<br />
C:\Program Files\Apoint\Apoint.exe<br />
C:\WINDOWS\system32\fxssvc.exe<br />
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe<br />
C:\program files\real\realplayer\update\realsched.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy 2\SDUpdSvc.exe<br />
C:\Program Files\QuickTime\QTTask.exe<br />
C:\Program Files\iTunes\iTunesHelper.exe<br />
C:\Program Files\Spybot - Search &amp; Destroy 2\SDTray.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\Apoint\Apntex.exe<br />
C:\Program Files\Digital Line Detect\DLG.exe<br />
C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe<br />
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\WINDOWS\System32\alg.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\WINDOWS\system32\wbem\wmiprvse.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup<br />
C:\WINDOWS\system32\svchost.exe -k NetworkService<br />
C:\WINDOWS\system32\svchost.exe -k LocalService<br />
C:\WINDOWS\system32\svchost.exe -k LocalService<br />
C:\WINDOWS\system32\svchost.exe -k imgsvc<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uWindow Title = Internet Explorer, optimized for Bing and MSN<br />
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&amp;sourceid=ie7&amp;rls=com.microsoft:en-US&amp;ie=utf8&amp;oe=utf8<br />
uProxyOverride = &lt;local&gt;;*.local<br />
uSearchAssistant = hxxp://www.google.com/ie<br />
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br />
uURLSearchHooks: Search Protection Class: {DEE1F01A-E6A8-4740-B420-3C521F234F74} - c:\program files\common files\search protection\sp.dll<br />
uURLSearchHooks: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - &lt;orphaned&gt;<br />
uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
dURLSearchHooks: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - &lt;orphaned&gt;<br />
BHO: Yahoo! Toolbar Helper: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll<br />
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - c:\program files\mcafee security scan\3.0.318\McAfeeMSS_IE.dll<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search &amp; destroy 2\SDHelper.dll<br />
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\tfswshx.dll<br />
BHO: BrowserHelper Class: {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - c:\program files\sgpsa\SearchAssistant.dll<br />
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll<br />
BHO: Search Protection Class: {DEE1F01A-E6A8-4740-B420-3C521F234F74} - c:\program files\common files\search protection\sp.dll<br />
BHO: {FB9FFB4B-9680-4256-8178-5ECDB2C19B23} - &lt;orphaned&gt;<br />
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll<br />
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [swg] &quot;c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe&quot;<br />
mRun: [nwiz] nwiz.exe /installquiet<br />
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup<br />
mRun: [MSC] &quot;c:\program files\microsoft security client\msseces.exe&quot; -hide -runkey<br />
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe  startup<br />
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe<br />
mRun: [Conime] c:\windows\system32\conime.exe<br />
mRun: [bacstray] BacsTray.exe<br />
mRun: [Apoint] c:\program files\apoint\Apoint.exe<br />
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe<br />
mRun: [APSDaemon] &quot;c:\program files\common files\apple\apple application support\APSDaemon.exe&quot;<br />
mRun: [TkBellExe] &quot;c:\program files\real\realplayer\update\realsched.exe&quot;  -osboot<br />
mRun: [QuickTime Task] &quot;c:\program files\quicktime\QTTask.exe&quot; -atboottime<br />
mRun: [iTunesHelper] &quot;c:\program files\itunes\iTunesHelper.exe&quot;<br />
mRun: [SDTray] &quot;c:\program files\spybot - search &amp; destroy 2\SDTray.exe&quot;<br />
dRun: [DWQueuedReporting] &quot;c:\progra~1\common~1\micros~1\dw\dwtrig20.exe&quot; -t<br />
dRunOnce: [KodakHomeCenter] &quot;c:\program files\kodak\aio\center\AiOHomeCenter.exe&quot;<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\intuit~1.lnk - c:\program files\common files\intuit\dataprotect\IntuitDataProtect.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.318\SSScheduler.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~2.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe<br />
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1<br />
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - LocalServer32 - &lt;no file&gt;<br />
IE: {B1C5B118-8240-47a6-AE84-103B05FB5AEF} - c:\program files\common files\search protection\spControl.exe<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search &amp; destroy 2\SDHelper.dll<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
.<br />
INFO: HKCU has more than 50 listed domains.<br />
If you wish to scan all of them, select the 'Force scan all domains' option.<br />
.<br />
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB<br />
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll<br />
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab<br />
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
TCP: NameServer = 68.105.28.12 68.105.29.12 68.105.28.11<br />
TCP: Interfaces\{BB9D49DE-6BB7-4D85-A707-12A362451B13} : NameServer = 8.8.8.8,8.8.4.4<br />
TCP: Interfaces\{BB9D49DE-6BB7-4D85-A707-12A362451B13} : DHCPNameServer = 68.105.28.12 68.105.29.12 68.105.28.11<br />
Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks 2011\HelpAsyncPluggableProtocol.dll<br />
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - <br />
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll<br />
Notify: SDWinLogon - SDWinLogon.dll<br />
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll<br />
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - &quot;c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe&quot; --configure-user-settings --verbose-logging --system-level --multi-install --chrome<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\jim salvo\application data\mozilla\firefox\profiles\7whe40qw.default\<br />
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?q={searchTerms}&amp;s_it=adknowledgeaol-ff&amp;s_qt=sb&amp;tb_uuid=20130420124627796&amp;tb_oid=20-04-2013&amp;tb_mrud=22-04-2013<br />
FF - prefs.js: browser.search.selectedEngine - Google<br />
FF - prefs.js: browser.startup.homepage - hxxps://my.screenname.aol.com/_cqr/login/login.psp?mcState=initialized&amp;seamless=novl&amp;sitedomain=sns.webmail.aol.com&amp;lang=en&amp;locale=us&amp;authLev=2&amp;siteState=ver%3a1%252c0%26ld%3awebmail.aol.com%26pv%3aAOL%26lc%3aen-us<br />
FF - component: c:\documents and settings\jim salvo\application data\mozilla\firefox\profiles\7whe40qw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll<br />
FF - component: c:\documents and settings\jim salvo\application data\mozilla\firefox\profiles\7whe40qw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll<br />
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlpepperflashvideoshim.dll<br />
FF - plugin: c:\documents and settings\all users\application data\realnetworks\realdownloader\browserplugins\npdlplugin.dll<br />
FF - plugin: c:\documents and settings\jim salvo\application data\mozilla\firefox\profiles\7whe40qw.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll<br />
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll<br />
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll<br />
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll<br />
FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll<br />
FF - plugin: c:\program files\mcafee security scan\3.0.318\npMcAfeeMSS.dll<br />
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll<br />
FF - plugin: c:\program files\mozilla firefox\plugins\nprpplugin.dll<br />
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll<br />
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll<br />
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll<br />
FF - ExtSQL: 2013-04-20 18:13; <a href="mailto:addon@defaulttab.com">addon@defaulttab.com</a>; c:\documents and settings\jim salvo\application data\mozilla\firefox\profiles\7whe40qw.default\extensions\addon@defaulttab.com.xpi<br />
FF - ExtSQL: 1969-12-31 18:00; {7affbfae-c4e2-4915-8c0f-00fa3ec610a1}; c:\documents and settings\jim salvo\application data\mozilla\firefox\profiles\7whe40qw.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}<br />
FF - ExtSQL: !HIDDEN! 2008-07-07 18:20; {3112ca9c-de6d-4884-a869-9855de68056c}; c:\program files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}<br />
FF - ExtSQL: !HIDDEN! 2008-12-01 21:23; {3112ca9c-de6d-4884-a869-9855de68056c}; c:\documents and settings\all users\application data\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}<br />
FF - ExtSQL: !HIDDEN! 2009-09-01 17:17; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension<br />
.<br />
---- FIREFOX POLICIES ----<br />
FF - user.js: network.protocol-handler.warn-external.dnupdate - false<br />
FF - user.js: browser.sessionstore.resume_from_crash - false<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 195296]<br />
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\EKAiOHostService.exe [2012-10-19 395200]<br />
R2 Kodak AiO Status Monitor Service;Kodak AiO Status Monitor Service;c:\program files\kodak\aio\statusmonitor\EKPrinterSDK.exe [2012-10-15 779200]<br />
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-4-22 418376]<br />
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-4-22 701512]<br />
R2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2011-6-30 1248256]<br />
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2012-11-29 38608]<br />
R2 SDUpdateService;Spybot-S&amp;D 2 Updating Service;c:\program files\spybot - search &amp; destroy 2\SDUpdSvc.exe [2013-4-29 1369624]<br />
R2 SPHost;SPHost;c:\program files\common files\search protection\spHost.exe [2009-6-24 107816]<br />
R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\WDDMService.exe [2011-12-15 265624]<br />
R2 WDDriveService;WD Drive Manager;c:\program files\western digital\wd drive manager\WDDriveService.exe [2011-12-16 246688]<br />
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-4-22 22856]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 SDScannerService;Spybot-S&amp;D 2 Scanner Service;c:\program files\spybot - search &amp; destroy 2\SDFSSvc.exe [2013-4-29 1103392]<br />
S2 SDWSCService;Spybot-S&amp;D 2 Security Center Service;c:\program files\spybot - search &amp; destroy 2\SDWSCSvc.exe [2013-4-29 168384]<br />
S2 WDFMEService;WDFME;c:\program files\western digital\wd smartware\WDFME.exe [2011-12-15 1591176]<br />
S2 WDRulesService;WDRules;c:\program files\western digital\wd smartware\WDRulesEngine.exe [2011-12-15 1091992]<br />
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\3.0.318\McCHSvc.exe [2013-2-5 235216]<br />
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2012-4-11 11520]<br />
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]<br />
.<br />
=============== File Associations ===============<br />
.<br />
FileExt: .txt: Applications\WINWORD.EXE=&quot;c:\program files\microsoft office\office\WINWORD.EXE&quot; /n [UserChoice] [default=edit - 'Open' doesn't exist]<br />
FileExt: .ini: Applications\POWERPNT.EXE=&quot;c:\program files\microsoft office\office\POWERPNT.EXE&quot; /s &quot;%1&quot; [UserChoice]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-04-29 20:41:30	388096	----a-r-	c:\documents and settings\jim salvo\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe<br />
2013-04-29 20:40:31	--------	d-----w-	c:\program files\Trend Micro<br />
2013-04-29 18:15:23	6906960	----a-w-	c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cce27a9e-cb27-4fbc-bf68-6481a60b7222}\mpengine.dll<br />
2013-04-29 16:02:54	--------	d-----w-	c:\documents and settings\all users\application data\Spybot - Search &amp; Destroy<br />
2013-04-29 16:02:08	15224	----a-w-	c:\windows\system32\sdnclean.exe<br />
2013-04-29 16:01:51	--------	d-----w-	c:\program files\Spybot - Search &amp; Destroy 2<br />
2013-04-29 14:04:29	6906960	------w-	c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll<br />
2013-04-28 03:56:30	26520	----a-w-	c:\program files\mozilla firefox\plugin-hang-ui.exe<br />
2013-04-23 00:36:33	--------	d-----w-	c:\documents and settings\jim salvo\application data\Malwarebytes<br />
2013-04-23 00:36:00	--------	d-----w-	c:\documents and settings\all users\application data\Malwarebytes<br />
2013-04-23 00:35:52	22856	----a-w-	c:\windows\system32\drivers\mbam.sys<br />
2013-04-23 00:35:52	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware<br />
2013-04-21 02:05:36	--------	d-----w-	c:\windows\system32\wbem\repository\FS<br />
2013-04-21 02:05:36	--------	d-----w-	c:\windows\system32\wbem\Repository<br />
2013-04-21 02:03:05	--------	d-----w-	c:\program files\Aerial Apparatus Driver Operator Study Guide<br />
2013-04-21 02:03:03	--------	d-----w-	c:\program files\common files\Software Update Utility<br />
2013-04-20 16:52:56	--------	d-----w-	c:\program files\DefaultTab<br />
2013-04-20 16:52:27	--------	d-----w-	c:\documents and settings\jim salvo\application data\DefaultTab<br />
2013-04-20 16:51:03	--------	d-----w-	c:\program files\MyPC Backup<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-04-02 10:33:22	237088	------w-	c:\windows\system32\MpSigStub.exe<br />
2013-03-13 18:40:08	73432	----a-w-	c:\windows\system32\FlashPlayerCPLApp.cpl<br />
2013-03-13 18:40:08	693976	----a-w-	c:\windows\system32\FlashPlayerApp.exe<br />
2013-03-13 18:40:00	16486616	----a-w-	c:\windows\system32\FlashPlayerInstaller.exe<br />
2013-03-08 08:36:22	293376	----a-w-	c:\windows\system32\winsrv.dll<br />
2013-03-07 01:28:24	2193408	----a-w-	c:\windows\system32\ntoskrnl.exe<br />
2013-03-07 00:50:28	2070016	----a-w-	c:\windows\system32\ntkrnlpa.exe<br />
2013-03-02 02:06:31	916480	----a-w-	c:\windows\system32\wininet.dll<br />
2013-03-02 02:06:30	43520	------w-	c:\windows\system32\licmgr10.dll<br />
2013-03-02 02:06:30	1469440	------w-	c:\windows\system32\inetcpl.cpl<br />
2013-03-02 01:25:02	1867264	----a-w-	c:\windows\system32\win32k.sys<br />
2013-03-02 01:08:47	385024	----a-w-	c:\windows\system32\html.iec<br />
2013-02-27 07:56:51	2067456	----a-w-	c:\windows\system32\mstscax.dll<br />
2013-02-12 00:32:23	12928	----a-w-	c:\windows\system32\drivers\usb8023.sys<br />
2013-02-12 00:32:23	12928	------w-	c:\windows\system32\drivers\usb8023x.sys<br />
.<br />
============= FINISH: 17:01:29.69 ===============</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>Ron Rockwell</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256745-RESOLVED-WIN-XP-quot-Issues-quot</guid>
		</item>
		<item>
			<title><![CDATA[[Inactive] slow]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256743-Inactive-slow&amp;goto=newpost</link>
			<pubDate>Mon, 29 Apr 2013 18:59:53 GMT</pubDate>
			<description><![CDATA[Hi can I have my log's checked please as my notebook is running slow and hesitating when I click to open program's or web pages and also freezing.Samsung RF511 Notebook intel core I5-2450m cpu@2.50 Ghz,8.0GB Ram,Intel HD Graphics,MS Win 7 Home Premium 
 64bit SP1.14MB SKY Broadband. Thank's 
 ...]]></description>
			<content:encoded><![CDATA[<div>Hi can I have my log's checked please as my notebook is running slow and hesitating when I click to open program's or web pages and also freezing.Samsung RF511 Notebook intel core I5-2450m cpu@2.50 Ghz,8.0GB Ram,Intel HD Graphics,MS Win 7 Home Premium<br />
 64bit SP1.14MB SKY Broadband. Thank's<br />
 <br />
Malwarebytes Anti-Malware 1.75.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2013.04.29.08<br />
<br />
Windows 7 Service Pack 1 x64 NTFS<br />
Internet Explorer 10.0.9200.16540<br />
Christine :: CHRISTINE-PC [administrator]<br />
<br />
29/04/2013 19:35:38<br />
mbam-log-2013-04-29 (19-35-38).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 240134<br />
Time elapsed: 5 minute(s), 45 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Values Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 0<br />
(No malicious items detected)<br />
<br />
(end)<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 16/02/2012 16:51:31<br />
System Uptime: 29/04/2013 16:24:31 (3 hours ago)<br />
.<br />
Motherboard: SAMSUNG ELECTRONICS CO., LTD. |  | RF511/RF411/RF711<br />
Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz | CPU 1 | 2501/100mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 502 GiB total, 388.691 GiB free.<br />
D: is FIXED (NTFS) - 409 GiB total, 369.06 GiB free.<br />
E: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
Class GUID: <br />
Description: <br />
Device ID: BTHENUM\{00005557-0000-1000-8000-0002EE000001}_VID&amp;00010001_PID&amp;00FD\8&amp;15C4787D&amp;0&amp;6C9B027885E3_C00000000<br />
Manufacturer: <br />
Name: <br />
PNP Device ID: BTHENUM\{00005557-0000-1000-8000-0002EE000001}_VID&amp;00010001_PID&amp;00FD\8&amp;15C4787D&amp;0&amp;6C9B027885E3_C00000000<br />
Service: <br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP216: 05/03/2013 02:20:45 - Windows Update<br />
RP217: 11/03/2013 20:28:42 - Windows Update<br />
RP218: 13/03/2013 15:11:15 - Windows Update<br />
RP219: 17/03/2013 02:23:02 - McAfee Vulnerability Scanner<br />
RP220: 17/03/2013 02:26:38 - Windows Update<br />
RP221: 17/03/2013 02:37:07 - Installed Java 7 Update 17 (64-bit)<br />
RP222: 27/03/2013 19:38:39 - Scheduled Checkpoint<br />
RP223: 11/04/2013 22:11:48 - Windows Update<br />
RP224: 16/04/2013 04:35:08 - McAfee Vulnerability Scanner<br />
RP225: 26/04/2013 18:44:24 - Windows Update<br />
RP226: 29/04/2013 16:27:32 - McAfee Vulnerability Scanner<br />
.<br />
==== Installed Programs ======================<br />
.<br />
?? ??? ?? Windows Live Mesh ActiveX ???<br />
??? ActiveX ?? Windows Live Mesh ???? ??????? ???????<br />
???? ??? Windows Live<br />
???? ???? ActiveX ????? ?? Windows Live Mesh ????????? ???????<br />
???? Windows Live<br />
????? Windows Live<br />
?????? ??????? ?? Windows Live<br />
??????? ?????????? Windows Live Mesh ActiveX ??? ????????? ???????????<br />
??????? Windows Live Mesh ActiveX ??(????)<br />
??????? Windows Live Mesh ActiveX ???<br />
???????? ?????????? Windows Live<br />
????????? ActiveX ?? Windows Live Mesh ????????????????????????? (???)<br />
?????????? Windows Live<br />
??????????? ?? Windows Live<br />
ActiveX-kontroll för fjärran****ningar för Windows Live Mesh<br />
ActiveX ???????? ?? Windows Live Mesh ?? ?????????? ??????<br />
Adobe AIR<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Reader XI (11.0.02)<br />
Agatha Christie - Death on the Nile<br />
Amazon MP3 Downloader 1.0.9<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
ArcSoft MediaImpression<br />
ArcSoft PhotoImpression 5<br />
ArcSoft TotalMedia 3<br />
ArcSoft VideoImpression 2<br />
„Windows Live Essentials“<br />
„Windows Live Mail“<br />
„Windows Live Mesh ActiveX“ nuotoliniu ryšiu valdiklis<br />
„Windows Live Messenger“<br />
„Windows Live“ fotogalerija<br />
BatteryLifeExtender<br />
Bejeweled 2 Deluxe<br />
Belarc Advisor 8.3<br />
Bing Bar<br />
Bonjour<br />
Broadcom 802.11 Network Adapter<br />
Build-a-lot<br />
Call of Duty<br />
Canon Auto Update Service<br />
CANON iMAGE GATEWAY MyCamera Download Plugin<br />
CANON iMAGE GATEWAY Task for ZoomBrowser EX<br />
Canon MOV Decoder<br />
Canon MOV Encoder<br />
Canon MovieEdit Task for ZoomBrowser EX<br />
Canon Utilities CameraWindow DC 8<br />
Canon Utilities CameraWindow Launcher<br />
Canon Utilities Movie Uploader for YouTube<br />
Canon Utilities MyCamera<br />
Canon Utilities PhotoStitch<br />
Canon Utilities ZoomBrowser EX<br />
Canon ZoomBrowser EX Memory Card Utility<br />
CCleaner<br />
ChargeableUSB<br />
Chuzzle Deluxe<br />
Contrôle ActiveX Windows Live Mesh pour connexions à distance<br />
Control ActiveX de Windows Live Mesh para conexiones remotas<br />
Control ActiveX Windows Live Mesh pentru conexiuni la distan?a<br />
Controle ActiveX do Windows Live Mesh para Conexões Remotas<br />
Controlo ActiveX do Windows Live Mesh para Ligações Remotas<br />
CyberLink Media Suite<br />
CyberLink Media+ Player10<br />
CyberLink MediaShow<br />
CyberLink Power2Go<br />
CyberLink PowerDirector<br />
CyberLink YouCam<br />
D3DX10<br />
Diner Dash 2 Restaurant Rescue<br />
EASEUS Partition Master 9.1.1 Home Edition<br />
Easy Content Share<br />
Easy Display Manager<br />
Easy Migration<br />
Easy Network Manager<br />
Easy SpeedUp Manager<br />
EasyBatteryManager<br />
EasyFileShare<br />
EPSON Printer Software<br />
EPSON S22 Series Printer Uninstall<br />
ETDWare PS/2-X64 8.0.7.2_WHQL<br />
Farm Frenzy<br />
Fast Start<br />
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsluge polaczen zdalnych<br />
Fotogalerija Windows Live<br />
Galeria de Fotografias do Windows Live<br />
Galeria fotografii uslugi Windows Live<br />
Galerie de photos Windows Live<br />
Galerie foto Windows Live<br />
Galería fotográfica de Windows Live<br />
Google Earth Plug-in<br />
Google Update Helper<br />
Grand Theft Auto Vice City<br />
iCloud<br />
Insaniquarium Deluxe<br />
Intel(R) Control Center<br />
Intel(R) Management Engine Components<br />
Intel(R) Processor Graphics<br />
Intel(R) Rapid Storage Technology<br />
Intel(R) Turbo Boost Technology Monitor 2.0<br />
iTunes<br />
Java 7 Update 11<br />
Java 7 Update 17 (64-bit)<br />
John Deere Drive Green<br />
Junk Mail filter update<br />
Kontrola Windows Live Mesh ActiveX za daljinske veze<br />
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
McAfee Online Backup<br />
McAfee Total Protection<br />
Medal of Honor Allied Assault<br />
Mesh Runtime<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft .NET Framework 4 Extended<br />
Microsoft Application Error Reporting<br />
Microsoft Office 2010<br />
Microsoft Office Click-to-Run 2010<br />
Microsoft Office Starter 2010 - English<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Microsoft XNA Framework Redistributable 4.0<br />
Movie Color Enhancer<br />
MSVC90_x64<br />
MSVC90_x86<br />
MSVCRT<br />
MSVCRT_amd64<br />
Multimedia POP<br />
Nokia Connectivity Cable Driver<br />
NVIDIA Display Control Panel<br />
NVIDIA Graphics Driver 266.72<br />
NVIDIA Install Application<br />
NVIDIA Optimus 1.0.15<br />
NVIDIA Update Components<br />
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená pripojení<br />
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia<br />
PC Connectivity Solution<br />
Peggle<br />
Penguins!<br />
PhoneShare<br />
Plants vs. Zombies<br />
Poczta uslugi Windows Live<br />
Podstawowe programy Windows Live<br />
Polar Golfer<br />
Pošta Windows Live<br />
QuickTime<br />
Raccolta foto di Windows Live<br />
Realtek Ethernet Controller Driver<br />
Realtek High Definition Audio Driver<br />
Renesas Electronics USB 3.0 Host Controller Driver<br />
S?????? f?t???af??? t?? Windows Live<br />
Safari<br />
Samsung AnyWeb Print<br />
Samsung Printer Live Update<br />
Samsung Recovery Solution 5<br />
Samsung Support Center 1.0<br />
Samsung Universal Print Driver<br />
Samsung Universal Scan Driver<br />
Samsung Update Plus<br />
SamsungMovie<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)<br />
Shared C Run-time for x64<br />
SISShortcut<br />
Sky Go Desktop<br />
Skype Click to Call<br />
Skype™ 6.3<br />
SpywareBlaster 5.0<br />
St???e?? e?????? ActiveX t?? Windows Live Mesh ??a ap?µa???sµ??e? s??d?se??<br />
SUPERAntiSpyware<br />
System Requirements Lab for Intel<br />
TomTom HOME<br />
TomTom HOME Visual Studio Merge Modules<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Update for Microsoft .NET Framework 4 Extended (KB2468871)<br />
Update for Microsoft .NET Framework 4 Extended (KB2533523)<br />
Update for Microsoft .NET Framework 4 Extended (KB2600217)<br />
User Guide<br />
Uzak Baglantilar Için Windows Live Mesh ActiveX Denetimi<br />
WIDCOMM Bluetooth Software<br />
WildTangent Games<br />
Windows Driver Package - Nokia pccsmcfd LegacyDriver  (05/31/2012 7.1.2.0)<br />
Windows Live<br />
Windows Live ??<br />
Windows Live ?? ???<br />
Windows Live ???<br />
Windows Live ????<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Fotótár<br />
Windows Live Foto-galerija<br />
Windows Live fotoattelu galerija<br />
Windows Live Fotogalerie<br />
Windows Live Fotogalleri<br />
Windows Live Fotogaléria<br />
Windows Live Fotograf Galerisi<br />
Windows Live Galeria de Fotos<br />
Windows Live Galerija fotografija<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Language Selector<br />
Windows Live Mail<br />
Windows Live Mesh<br />
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen<br />
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger<br />
Windows Live Mesh ActiveX-objekt til fjernforbindelser<br />
Windows Live Mesh ActiveX-vezérlo távoli kapcsolatokhoz<br />
Windows Live Mesh ActiveX Control for Remote Connections<br />
Windows Live Mesh ActiveX kontrola za daljinske veze<br />
Windows Live Mesh ActiveX vadikla attalajiem savienojumiem<br />
Windows Live Meshin etäyhteyksien ActiveX-komponentti<br />
Windows Live Messenger<br />
Windows Live MIME IFilter<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live Pošta<br />
Windows Live Remote Client<br />
Windows Live Remote Client Resources<br />
Windows Live Remote Service<br />
Windows Live Remote Service Resources<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live Temel Parçalar<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
Windows Liven asennustyökalu<br />
Windows Liven sähköposti<br />
Windows Liven valokuvavalikoima<br />
WordCaptureX Pro<br />
WOT for Internet Explorer<br />
Zuma Deluxe<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
29/04/2013 19:15:42, Error: Ntfs [55]  - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.<br />
29/04/2013 19:15:42, Error: Ntfs [55]  - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume \Device\HarddiskVolume2.<br />
29/04/2013 18:07:31, Error: Service Control Manager [7023]  - The Peer Name Resolution Protocol service terminated with the following error:  %%-2140993535<br />
29/04/2013 18:07:31, Error: Service Control Manager [7001]  - The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error:  %%-2140993535<br />
29/04/2013 18:07:31, Error: Microsoft-Windows-PNRPSvc [102]  - The Peer Name Resolution Protocol cloud did not start because the creation of the default identity failed with error code: 0x80630801.<br />
29/04/2013 18:07:24, Error: Microsoft-Windows-SharedAccess_NAT [31004]  - The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.<br />
29/04/2013 15:15:14, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.<br />
29/04/2013 15:15:14, Error: Service Control Manager [7000]  - The Windows Search service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
29/04/2013 15:15:14, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error &quot;1053&quot; attempting to start the service WSearch with arguments &quot;&quot; in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}<br />
29/04/2013 15:14:47, Error: Service Control Manager [7031]  - The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.<br />
29/04/2013 15:14:47, Error: Service Control Manager [7024]  - The Windows Search service terminated with service-specific error %%-1073473535.<br />
26/04/2013 19:33:12, Error: Service Control Manager [7034]  - The ArcSoft Connect Daemon service terminated unexpectedly.  It has done this 1 time(s).<br />
26/04/2013 19:20:57, Error: Service Control Manager [7022]  - The NVIDIA Update Service Daemon service hung on starting.<br />
26/04/2013 19:13:49, Error: Microsoft-Windows-DistributedCOM [10016]  - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {B77C4C36-0154-4C52-AB49-FAA03837E47F}  and APPID  {EA022610-0748-4C24-B229-6C507EBDFDBB}  to the user Christine-PC\Christine SID (S-1-5-21-1867582200-139094598-4032816429-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.<br />
23/04/2013 14:56:45, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk1\DR2.<br />
23/04/2013 14:56:43, Error: Microsoft-Windows-BitLocker-Driver [24620]  - Encrypted volume check: Volume information on F: cannot be read.<br />
.<br />
==== End Of File ===========================<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 10.0.9200.16537<br />
Run by Christine at 19:42:20 on 2013-04-29<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.8103.5625 [GMT 1:00]<br />
.<br />
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}<br />
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\windows\system32\lsm.exe<br />
C:\windows\system32\svchost.exe -k DcomLaunch<br />
C:\windows\system32\nvvsvc.exe<br />
C:\windows\system32\svchost.exe -k RPCSS<br />
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\windows\system32\svchost.exe -k LocalService<br />
C:\windows\system32\svchost.exe -k netsvcs<br />
C:\windows\system32\svchost.exe -k GPSvcGroup<br />
C:\windows\system32\svchost.exe -k NetworkService<br />
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe<br />
C:\windows\system32\WLANExt.exe<br />
C:\windows\System32\spoolsv.exe<br />
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE<br />
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br />
C:\windows\system32\taskhost.exe<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\windows\system32\Dwm.exe<br />
C:\windows\Explorer.EXE<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\windows\system32\taskeng.exe<br />
C:\Program Files (x86)\SAMSUNG\SISv3\XeControl.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe<br />
C:\windows\system32\mfevtps.exe<br />
C:\windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe<br />
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe<br />
C:\windows\system32\rundll32.exe<br />
C:\windows\system32\rundll32.exe<br />
C:\windows\SysWOW64\rundll32.exe<br />
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE<br />
C:\windows\system32\taskeng.exe<br />
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe<br />
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe<br />
C:\windows\system32\igfxext.exe<br />
C:\windows\system32\igfxsrvc.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\PROGRA~1\McAfee\MSC\McAPExe.exe<br />
C:\windows\system32\SearchIndexer.exe<br />
C:\windows\System32\alg.exe<br />
C:\windows\system32\svchost.exe -k bthsvcs<br />
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe<br />
C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe<br />
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe<br />
C:\Program Files\McAfee\MAT\McPvTray.exe<br />
C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe<br />
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe<br />
C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe<br />
C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe<br />
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe<br />
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE<br />
C:\windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe<br />
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br />
C:\windows\system32\Macromed\Flash\FlashUtil64_11_7_700_169_ActiveX.exe<br />
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe<br />
c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe<br />
C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe<br />
C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe<br />
C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe<br />
C:\windows\notepad.exe<br />
C:\windows\system32\wbem\wmiprvse.exe<br />
C:\windows\System32\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.co.uk/<br />
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Samsung BHO Class: {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll<br />
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll<br />
BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll<br />
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - <br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll<br />
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - <br />
TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll<br />
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll<br />
uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe<br />
mRun: [mcpltui_exe] &quot;C:\Program Files\McAfee.com\Agent\mcagent.exe&quot; /runkey<br />
mRun: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent<br />
uPolicies-Explorer: NoDrives = dword:0<br />
mPolicies-Explorer: NoDriveTypeAutoRun = dword:28<br />
mPolicies-Explorer: NoDrives = dword:0<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: Send image to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br />
IE: Send page to &amp;Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab<br />
TCP: NameServer = 192.168.0.1<br />
TCP: Interfaces\{06800801-C2F4-461A-AC24-C6149121E12E} : NameServer = 88.82.13.44<br />
TCP: Interfaces\{6FCCD9FA-0DCF-4AE2-93FB-2541A7BEBD63} : DHCPNameServer = 192.168.0.1<br />
TCP: Interfaces\{6FCCD9FA-0DCF-4AE2-93FB-2541A7BEBD63}\2656C6B696E6534376 : DHCPNameServer = 192.168.2.1<br />
TCP: Interfaces\{6FCCD9FA-0DCF-4AE2-93FB-2541A7BEBD63}\34C616368616E60234F64747167656020333 : DHCPNameServer = 192.168.1.254<br />
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll<br />
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll<br />
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll<br />
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll<br />
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll<br />
x64-BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll<br />
x64-BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll<br />
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll<br />
x64-TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll<br />
x64-TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll<br />
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s<br />
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll<br />
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br />
x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll<br />
x64-Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - &lt;orphaned&gt;<br />
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll<br />
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll<br />
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
x64-Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll<br />
x64-Notify: igfxcui - igfxdev.dll<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 mfehidk;McAfee Inc. mfehidk;C:\windows\System32\drivers\mfehidk.sys [2012-11-9 771096]<br />
R0 mfewfpk;McAfee Inc. mfewfpk;C:\windows\System32\drivers\mfewfpk.sys [2012-11-9 339776]<br />
R0 nvpciflt;nvpciflt;C:\windows\System32\drivers\nvpciflt.sys [2011-9-7 25960]<br />
R1 MOBKFilter;MOBKFilter;C:\windows\System32\drivers\MOBK.sys [2013-2-9 66040]<br />
R1 SABI;SAMSUNG Kernel Driver For Windows 7;C:\windows\System32\drivers\SABI.sys [2011-9-7 13824]<br />
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]<br />
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]<br />
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-12 140672]<br />
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]<br />
R2 HomeNetSvc;McAfee Home Network;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-2-9 221296]<br />
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2013-4-8 103472]<br />
R2 McMPFSvc;McAfee Personal Firewall;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-2-9 221296]<br />
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-2-9 221296]<br />
R2 mcpltsvc;McAfee Platform Services;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-2-9 221296]<br />
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-2-9 221296]<br />
R2 McPvDrv;McPvDrv Driver;C:\windows\System32\drivers\McPvDrv.sys [2013-4-6 74560]<br />
R2 mfecore;McAfee Anti-Malware Core;C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [2013-2-9 1007288]<br />
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2013-2-9 218320]<br />
R2 mfevtp;McAfee Validation Trust Protection Service;C:\windows\System32\mfevtps.exe [2013-2-9 182312]<br />
R2 MOBKbackup;McAfee Online Backup;C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe [2010-4-13 231224]<br />
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]<br />
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-4-15 3289208]<br />
R2 TomTomHOMEService;TomTomHOMEService;C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe [2012-8-28 92632]<br />
R2 TurboB;Turbo Boost UI Monitor driver;C:\windows\System32\drivers\TurboB.sys [2010-10-8 19192]<br />
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-9-7 2655768]<br />
R3 BTWAMPFL;BTWAMPFL;C:\windows\System32\drivers\btwampfl.sys [2012-2-16 348712]<br />
R3 btwl2cap;Bluetooth L2CAP Service;C:\windows\System32\drivers\btwl2cap.sys [2012-2-16 39464]<br />
R3 cfwids;McAfee Inc. cfwids;C:\windows\System32\drivers\cfwids.sys [2012-11-9 69672]<br />
R3 clwvd;CyberLink WebCam Virtual Driver;C:\windows\System32\drivers\clwvd.sys [2010-11-10 31088]<br />
R3 ETD;ELAN PS/2 Port Input Device;C:\windows\System32\drivers\ETD.sys [2011-9-7 138024]<br />
R3 IntcDAud;Intel(R) Display Audio;C:\windows\System32\drivers\IntcDAud.sys [2011-9-7 317440]<br />
R3 mfeavfk;McAfee Inc. mfeavfk;C:\windows\System32\drivers\mfeavfk.sys [2012-11-9 309400]<br />
R3 mfefirek;McAfee Inc. mfefirek;C:\windows\System32\drivers\mfefirek.sys [2012-11-9 515528]<br />
R3 mfencbdc;McAfee Inc. mfencbdc;C:\windows\System32\drivers\mfencbdc.sys [2012-11-2 328976]<br />
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\windows\System32\drivers\nusb3hub.sys [2010-12-3 80384]<br />
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\windows\System32\drivers\nusb3xhc.sys [2010-12-3 181248]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2011-9-7 533096]<br />
R3 Sftfs;Sftfs;C:\windows\System32\drivers\Sftfslh.sys [2011-10-1 764264]<br />
R3 Sftplay;Sftplay;C:\windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648]<br />
R3 Sftredir;Sftredir;C:\windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960]<br />
R3 Sftvol;Sftvol;C:\windows\System32\drivers\Sftvollh.sys [2011-10-1 22376]<br />
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-28 161384]<br />
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-1 183560]<br />
S3 epmntdrv;epmntdrv;C:\windows\System32\epmntdrv.sys [2012-5-10 16776]<br />
S3 EuGdiDrv;EuGdiDrv;C:\windows\System32\EuGdiDrv.sys [2012-5-10 9096]<br />
S3 HipShieldK;McAfee Inc. HipShieldK;C:\windows\System32\drivers\HipShieldK.sys [2013-4-6 197264]<br />
S3 mfencrk;McAfee Inc. mfencrk;C:\windows\System32\drivers\mfencrk.sys [2012-11-2 97208]<br />
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers\rdpvideominiport.sys [2012-10-26 19456]<br />
S3 Samsung UPD Service;Samsung UPD Service;C:\windows\System32\SUPDSvc.exe [2011-9-7 166704]<br />
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2012-10-26 57856]<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2012-10-26 30208]<br />
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-10-8 150016]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2012-2-16 1255736]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]<br />
.<br />
=============== File Associations ===============<br />
.<br />
FileExt: .jse: JSEFile=C:\windows\SysWow64\CScript.exe &quot;%1&quot; %*<br />
FileExt: .wsf: WSFFile=C:\windows\SysWow64\CScript.exe &quot;%1&quot; %*<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-04-29 18:34:01	25928	----a-w-	C:\windows\System32\drivers\mbam.sys<br />
2013-04-29 18:34:01	--------	d-----w-	C:\Program Files (x86)\Malwarebytes' Anti-Malware<br />
2013-04-26 17:48:21	--------	d-----w-	C:\Users\Christine\AppData\Local\{34F0C62D-8303-472F-A724-EEBB03534DB0}<br />
2013-04-24 11:16:35	1656680	----a-w-	C:\windows\System32\drivers\ntfs.sys<br />
2013-04-23 14:08:13	--------	d-----w-	C:\Users\Christine\AppData\Local\{FBFCA0E5-4BA3-4A22-9090-1144E39B7D8B}<br />
2013-04-22 11:02:42	--------	d-----w-	C:\Users\Christine\AppData\Local\{DB6E6C06-137E-4FAD-A954-CEBFE58E2DC7}<br />
2013-04-20 13:40:13	--------	d-----w-	C:\Users\Christine\AppData\Local\{D70A6203-A948-4E06-B00E-7EBD848958F5}<br />
2013-04-17 20:16:57	--------	d-----w-	C:\Users\Christine\AppData\Roaming\ZoomBrowser EX<br />
2013-04-17 20:10:06	--------	d-----w-	C:\ProgramData\ZoomBrowser<br />
2013-04-17 20:09:04	--------	d-----w-	C:\ProgramData\Canon_Inc_IC<br />
2013-04-17 20:09:01	--------	d-----w-	C:\Program Files (x86)\Canon<br />
2013-04-17 20:03:50	--------	d-----w-	C:\Program Files (x86)\Common Files\Canon<br />
2013-04-12 20:51:11	--------	d-----w-	C:\Users\Christine\AppData\Local\{5836C7FB-BC10-4BE3-A118-6D8E48BCB55E}<br />
2013-04-09 20:51:41	3153408	----a-w-	C:\windows\System32\win32k.sys<br />
2013-04-09 20:51:23	223752	----a-w-	C:\windows\System32\drivers\fvevol.sys<br />
2013-04-09 20:51:16	5550424	----a-w-	C:\windows\System32\ntoskrnl.exe<br />
2013-04-09 20:51:14	3968856	----a-w-	C:\windows\SysWow64\ntkrnlpa.exe<br />
2013-04-09 20:51:14	3913560	----a-w-	C:\windows\SysWow64\ntoskrnl.exe<br />
2013-04-09 20:51:13	43520	----a-w-	C:\windows\System32\csrsrv.dll<br />
2013-04-09 20:51:13	112640	----a-w-	C:\windows\System32\smss.exe<br />
2013-04-09 20:51:12	6656	----a-w-	C:\windows\SysWow64\apisetschema.dll<br />
2013-04-09 20:41:43	--------	d-----w-	C:\Users\Christine\AppData\Local\{5CC70AAD-BEF4-4BF4-A908-8BFAC9D41106}<br />
2013-04-07 19:32:15	--------	d-----w-	C:\Users\Christine\AppData\Local\{D7F2B93A-00F9-4BEE-B2F6-0026FCF23410}<br />
2013-04-06 01:52:22	74560	----a-w-	C:\windows\System32\drivers\McPvDrv.sys<br />
2013-04-06 01:52:08	197264	----a-w-	C:\windows\System32\drivers\HipShieldK.sys<br />
2013-03-30 19:08:53	--------	d-----w-	C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69<br />
2013-03-30 19:08:53	--------	d-----w-	C:\Program Files\iTunes<br />
2013-03-30 19:08:53	--------	d-----w-	C:\Program Files\iPod<br />
2013-03-30 19:08:53	--------	d-----w-	C:\Program Files (x86)\iTunes<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-04-29 15:28:05	71048	----a-w-	C:\windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2013-04-29 15:28:05	691592	----a-w-	C:\windows\SysWow64\FlashPlayerApp.exe<br />
2013-03-17 02:37:35	108448	----a-w-	C:\windows\System32\WindowsAccessBridge-64.dll<br />
2013-03-17 02:37:34	963488	----a-w-	C:\windows\System32\deployJava1.dll<br />
2013-03-17 02:37:34	1085344	----a-w-	C:\windows\System32\npDeployJava1.dll<br />
2013-02-21 10:30:16	1766912	----a-w-	C:\windows\SysWow64\wininet.dll<br />
2013-02-21 10:29:39	2877440	----a-w-	C:\windows\SysWow64\jscript9.dll<br />
2013-02-21 10:29:37	61440	----a-w-	C:\windows\SysWow64\iesetup.dll<br />
2013-02-21 10:29:37	109056	----a-w-	C:\windows\SysWow64\iesysprep.dll<br />
2013-02-21 10:15:07	2240512	----a-w-	C:\windows\System32\wininet.dll<br />
2013-02-21 10:14:09	3958784	----a-w-	C:\windows\System32\jscript9.dll<br />
2013-02-21 10:14:05	67072	----a-w-	C:\windows\System32\iesetup.dll<br />
2013-02-21 10:14:05	136704	----a-w-	C:\windows\System32\iesysprep.dll<br />
2013-02-19 12:01:03	2706432	----a-w-	C:\windows\SysWow64\mshtml.tlb<br />
2013-02-19 11:42:14	2706432	----a-w-	C:\windows\System32\mshtml.tlb<br />
2013-02-19 11:10:53	71680	----a-w-	C:\windows\SysWow64\RegisterIEPKEYs.exe<br />
2013-02-19 10:51:18	89600	----a-w-	C:\windows\System32\RegisterIEPKEYs.exe<br />
2013-02-12 05:45:24	135168	----a-w-	C:\windows\apppatch\AppPatch64\AcXtrnal.dll<br />
2013-02-12 05:45:22	350208	----a-w-	C:\windows\apppatch\AppPatch64\AcLayers.dll<br />
2013-02-12 05:45:22	308736	----a-w-	C:\windows\apppatch\AppPatch64\AcGenral.dll<br />
2013-02-12 05:45:22	111104	----a-w-	C:\windows\apppatch\AppPatch64\acspecfc.dll<br />
2013-02-12 04:48:31	474112	----a-w-	C:\windows\apppatch\AcSpecfc.dll<br />
2013-02-12 04:48:26	2176512	----a-w-	C:\windows\apppatch\AcGenral.dll<br />
2013-02-12 04:12:05	19968	----a-w-	C:\windows\System32\drivers\usb8023.sys<br />
.<br />
============= FINISH: 19:43:05.19 ===============</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>fred scuttle</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256743-Inactive-slow</guid>
		</item>
		<item>
			<title><![CDATA[[Inactive] unwanted mixidj search engine]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256737-Inactive-unwanted-mixidj-search-engine&amp;goto=newpost</link>
			<pubDate>Mon, 29 Apr 2013 03:40:25 GMT</pubDate>
			<description><![CDATA[I installed some free software and got several unwanted browser add-ons. Some were removable. But mixidj was not. Would you help me remove it? Thanks. 
 
Here are the scan results. 
 
. 
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. 
IF REQUESTED, ZIP IT UP & ATTACH IT 
. 
DDS...]]></description>
			<content:encoded><![CDATA[<div>I installed some free software and got several unwanted browser add-ons. Some were removable. But mixidj was not. Would you help me remove it? Thanks.<br />
<br />
Here are the scan results.<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume2<br />
Install Date: 6/23/2012 8:56:31 AM<br />
System Uptime: 4/28/2013 10:29:20 PM (1 hours ago)<br />
.<br />
Motherboard: ASUSTeK Computer Inc. |  | K53Z <br />
Processor: AMD A6-3420M APU with Radeon(tm) HD Graphics | P0 | 1500/100mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 300 GiB total, 219.011 GiB free.<br />
D: is FIXED (NTFS) - 373 GiB total, 333.14 GiB free.<br />
E: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP152: 4/7/2013 9:21:59 PM - Windows Update<br />
RP153: 4/11/2013 8:40:41 AM - Windows Update<br />
RP154: 4/14/2013 11:45:39 AM - Windows Update<br />
RP155: 4/18/2013 7:49:25 AM - Windows Update<br />
RP156: 4/22/2013 1:00:35 AM - Windows Update<br />
RP157: 4/24/2013 7:14:59 AM - Windows Update<br />
RP158: 4/24/2013 9:23:25 AM - Installed Rapport<br />
RP159: 4/27/2013 10:41:27 AM - Windows Update<br />
.<br />
==== Installed Programs ======================<br />
.<br />
??????? Windows Live Mesh ActiveX ??(????)<br />
??????? Windows Live Mesh ActiveX ???<br />
1-Click YouTube Downloader 10.1<br />
ActivePerl 5.14.2 Build 1402 (64-bit)<br />
Adobe Flash Player 10 Plugin<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Reader X (10.1.6)<br />
Amazon Kindle<br />
AMD APP SDK Runtime<br />
AMD Catalyst Install Manager<br />
AMD Fuel<br />
AMD Media Foundation Decoders<br />
AMD System Monitor<br />
AMD VISION Engine Control Center<br />
Anki<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
ArsClip<br />
ASUS AI Recovery<br />
ASUS FaceLogon<br />
ASUS FancyStart<br />
ASUS LifeFrame3<br />
ASUS Live Update<br />
ASUS Power4Gear Hybrid<br />
ASUS Sonic Focus<br />
ASUS Splendid Video Enhancement Technology<br />
ASUS USB Charger Plus<br />
ASUS Virtual Camera<br />
ASUS WebStorage<br />
ASUS_Screensaver<br />
AsusVibe2.0<br />
Atheros Client Installation Program<br />
ATK Package<br />
Audacity 2.0.2<br />
AudibleManager<br />
AutoHotkey 1.0.48.05<br />
AxCrypt 1.7.2867.0<br />
Bing Bar<br />
Bitcoin<br />
Bluetooth Win7 Suite (64)<br />
Bonjour<br />
Camtasia Studio 6<br />
Canon MX320 series MP Drivers<br />
Catalyst Control Center InstallProxy<br />
Catalyst Control Center Localization All<br />
Catalyst Control Center Profiles Mobile<br />
ccc-utility64<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
CCleaner<br />
Compatibility Pack for the 2007 Office system<br />
Contrôle ActiveX Windows Live Mesh pour connexions à distance<br />
Control ActiveX de Windows Live Mesh para conexiones remotas<br />
Controlo ActiveX do Windows Live Mesh para Ligações Remotas<br />
CyberLink LabelPrint<br />
CyberLink Media Suite<br />
CyberLink Power2Go<br />
D3DX10<br />
Dropbox<br />
DVD Decrypter (Remove Only)<br />
ETDWare PS/2-X64 8.0.5.1_WHQL<br />
EXAKT<br />
Fast Boot<br />
FileBox eXtender<br />
FileZilla Client 3.6.0.2<br />
Freeplane<br />
Galeria de Fotografias do Windows Live<br />
Galerie de photos Windows Live<br />
Galería fotográfica de Windows Live<br />
Google Chrome<br />
Google Drive<br />
Google Earth Plug-in<br />
Google Talk Plugin<br />
Google Update Helper<br />
GoToMeeting 5.5.0.1133<br />
HTML-Kit 292<br />
ImgBurn<br />
iTunes<br />
Java 7 Update 17<br />
Java Auto Updater<br />
Java(TM) 6 Update 33 (64-bit)<br />
Java(TM) SE Development Kit 6 Update 33 (64-bit)<br />
JavaFX 2.1.1<br />
Junk Mail filter update<br />
Kingsoft Office 2012 (8.1.0.3375)<br />
LAME v3.99.3 (for Windows)<br />
Macro Express 3<br />
magicJack<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
Megacubo 10<br />
Mesh Runtime<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft .NET Framework 4 Extended<br />
Microsoft Application Error Reporting<br />
Microsoft Office 2010<br />
Microsoft Office File Validation Add-In<br />
Microsoft Office Professional Edition 2003<br />
Microsoft Security Client<br />
Microsoft Security Essentials<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2005 Redistributable (x64)<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
MP3 Skype Recorder<br />
MSVCRT<br />
MSVCRT_amd64<br />
MWSnap 3<br />
Nuance PDF Reader<br />
Oracle Database 11g Express Edition<br />
PDFill PDF Editor with FREE Writer and FREE Tools<br />
Rapport<br />
Realtek Ethernet Controller Driver<br />
Realtek High Definition Audio Driver<br />
Realtek USB 2.0 Card Reader<br />
Search Protect by conduit<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)<br />
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)<br />
Skype Click to Call<br />
Skype™ 6.1<br />
SPAR PHM 4.0<br />
Spybot - Search &amp; Destroy<br />
Staples Easy Print<br />
Syntext Serna Free 4.4.0<br />
TeamViewer 8<br />
TeleKast version 1.0.1<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Update for Microsoft .NET Framework 4 Extended (KB2468871)<br />
Update for Microsoft .NET Framework 4 Extended (KB2533523)<br />
Update for Microsoft .NET Framework 4 Extended (KB2600217)<br />
Virtual Magnifying Glass v3.5<br />
VLC media player 2.0.5<br />
Wajam<br />
WampServer 2.2<br />
Windows Live<br />
Windows Live ???<br />
Windows Live ????<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Family Safety<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Language Selector<br />
Windows Live Mail<br />
Windows Live Mesh<br />
Windows Live Mesh ActiveX Control for Remote Connections<br />
Windows Live Messenger<br />
Windows Live MIME IFilter<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live Remote Client<br />
Windows Live Remote Client Resources<br />
Windows Live Remote Service<br />
Windows Live Remote Service Resources<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
WinFlash<br />
WinRAR 4.20 (64-bit)<br />
Wireless Console 3<br />
Yahoo! Messenger<br />
Yahoo! Software Update<br />
Yahoo! Toolbar<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
4/27/2013 6:48:48 AM, Error: Schannel [36888]  - The following fatal alert was generated: 40. The internal error state is 107.<br />
4/27/2013 6:48:48 AM, Error: Schannel [36874]  - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.<br />
4/24/2013 8:33:55 PM, Error: Microsoft-Windows-DistributedCOM [10016]  - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID  {9BA05972-F6A8-11CF-A442-00A0C90A8F39}  and APPID  {9BA05972-F6A8-11CF-A442-00A0C90A8F39}  to the user LRCM-PC\Murray SID (S-1-5-21-395879043-1767180283-1117684252-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.<br />
4/21/2013 5:52:20 PM, Error: Service Control Manager [7034]  - The Google Update Service (gupdate) service terminated unexpectedly.  It has done this 1 time(s).<br />
.<br />
==== End Of File ===========================<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 9.0.8112.16476  BrowserJavaVersion: 10.17.2<br />
Run by Murray at 23:02:33 on 2013-04-28<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.7657.5212 [GMT -4:00]<br />
.<br />
AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}<br />
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Program Files\Microsoft Security Client\MsMpEng.exe<br />
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Windows\system32\FBAgent.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe<br />
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe<br />
C:\Prey\platform\windows\cronsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe<br />
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE<br />
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe<br />
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe<br />
C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe<br />
C:\Program Files\Elantech\ETDCtrl.exe<br />
C:\Program Files\Microsoft Security Client\msseces.exe<br />
C:\Program Files (x86)\Citrix\GoToMeeting\1133\g2mstart.exe<br />
C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe<br />
C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe<br />
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe<br />
C:\Program Files (x86)\Citrix\GoToMeeting\1133\g2mcomm.exe<br />
C:\Program Files\Elantech\ETDCtrlHelper.exe<br />
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe<br />
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\ASUS\P4G\BatteryLife.exe<br />
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe<br />
C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe<br />
C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler64.exe<br />
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
C:\Program Files (x86)\Google\Drive\googledrivesync.exe<br />
C:\Program Files\Microsoft Security Client\NisSrv.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\SysWOW64\ACEngSvr.exe<br />
C:\Program Files (x86)\Skype\Phone\Skype.exe<br />
C:\Users\Murray\AppData\Roaming\SearchProtect\bin\cltmng.exe<br />
C:\Program Files (x86)\Google\Drive\googledrivesync.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe<br />
C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files (x86)\Citrix\GoToMeeting\1133\g2mlauncher.exe<br />
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe<br />
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe<br />
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\AsusWSPanel.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files\FileBX\FileBX.exe<br />
C:\Users\Murray\AppData\Roaming\Dropbox\bin\Dropbox.exe<br />
C:\Program Files\FileBX\Fbx32helper.exe<br />
C:\Windows\AsScrPro.exe<br />
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Windows\System32\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://search.conduit.com/?ctid=CT3287822&amp;octid=CT3287822&amp;SearchSource=61&amp;CUI=UN77173014416987741&amp;UM=2&amp;UP=SPE88797D9-3B9F-431A-BC22-4717DB99743D<br />
uSearch Bar = hxxp://search.minituner.org/<br />
uSearch Page = hxxp://search.minituner.org/<br />
uDefault_Page_URL = hxxp://asus.msn.com<br />
mStart Page = hxxp://asus.msn.com<br />
mSearch Page = hxxp://search.minituner.org/<br />
mDefault_Search_URL = hxxp://search.minituner.org/<br />
uSearchAssistant = hxxp://feed.helperbar.com/?publisher=OPENCANDY&amp;dpid=OPENCANDYAPRIL&amp;co=CA&amp;userid=5c472d85-a6b1-4217-a831-93d147796895&amp;affid=110774&amp;searchtype=ds&amp;babsrc=lnkry&amp;q={searchTerms}<br />
uSearchURL,(Default) = hxxp://search.minituner.org/q/%s<br />
mSearchAssistant = hxxp://search.minituner.org/<br />
mCustomizeSearch = hxxp://search.minituner.org/<br />
mWinlogon: Userinit = userinit.exe,<br />
BHO: &amp;Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: Spybot-S&amp;D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDHelper.dll<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br />
BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll<br />
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - <br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - <br />
TB: &lt;No Name&gt;: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - &lt;no file&gt;<br />
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet Explorer\iedvtool.dll<br />
uRun: [Google Update] &quot;C:\Users\Murray\AppData\Local\Google\Update\GoogleUpdate.exe&quot; /c<br />
uRun: [GoToMeeting] &quot;C:\Program Files (x86)\Citrix\GoToMeeting\1133\g2mstart.exe&quot; &quot;/Trigger RunAtLogon&quot;<br />
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search &amp; Destroy\TeaTimer.exe<br />
uRun: [Speech Recognition] &quot;C:\Windows\Speech\Common\sapisvr.exe&quot; -SpeechUX -Startup<br />
uRun: [GoogleDriveSync] &quot;C:\Program Files (x86)\Google\Drive\googledrivesync.exe&quot; /autostart<br />
uRun: [cdloader] &quot;C:\Users\Murray\AppData\Roaming\mjusbsp\cdloader2.exe&quot; MAGICJACK<br />
uRun: [Megacubo] &quot;C:\Program Files (x86)\Megacubo\megacubo.exe&quot; -load:update -type:startup<br />
uRun: [Skype] &quot;C:\Program Files (x86)\Skype\Phone\Skype.exe&quot; /minimized /regrun<br />
uRun: [Messenger (Yahoo!)] &quot;C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe&quot; -quiet<br />
uRun: [MP3 Skype Recorder] C:\Program Files (x86)\MP3 Skype Recorder\MP3 Skype Recorder.exe<br />
uRun: [SearchProtect] C:\Users\Murray\AppData\Roaming\SearchProtect\bin\cltmng.exe<br />
uRunOnce: [Application Restart #1] C:\Users\Murray\AppData\Local\Google\Chrome\Application\chrome.exe  --flag-switches-begin --flag-switches-end --restore-last-session<br />
mRun: [Nuance PDF Reader-reminder] &quot;C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe&quot; -r &quot;C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini&quot;<br />
mRun: [ASUSPRP] &quot;C:\Program Files (x86)\ASUS\APRP\APRP.EXE&quot;<br />
mRun: [SonicMasterTray] C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe<br />
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe<br />
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe<br />
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe<br />
mRun: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe<br />
mRun: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
mRun: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\AsusWSPanel.exe /S<br />
mRun: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun: [iTunesHelper] &quot;C:\Program Files (x86)\iTunes\iTunesHelper.exe&quot;<br />
mRun: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
mRun: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe<br />
StartupFolder: C:\Users\Murray\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Murray\AppData\Roaming\Dropbox\bin\Dropbox.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ASUSVI~1.LNK - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FILEBO~1.LNK - C:\Program Files\FileBX\FileBX.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Megacubo.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe<br />
uPolicies-Explorer: NoDriveAutoRun = dword:0<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: E&amp;xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}<br />
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDHelper.dll<br />
TCP: NameServer = 192.168.2.1<br />
TCP: Interfaces\{4D3F7226-B4A8-4244-B9C2-236BD6360A5C} : DHCPNameServer = 10.47.44.18 10.47.44.1<br />
TCP: Interfaces\{90B428C4-B95F-4CD9-97CB-074602CE4370} : DHCPNameServer = 192.168.2.1<br />
TCP: Interfaces\{90B428C4-B95F-4CD9-97CB-074602CE4370}\14E64627F696461405 : DHCPNameServer = 192.168.43.1<br />
TCP: Interfaces\{90B428C4-B95F-4CD9-97CB-074602CE4370}\2454C4C4037303 : DHCPNameServer = 192.168.2.1<br />
TCP: Interfaces\{90B428C4-B95F-4CD9-97CB-074602CE4370}\A607C613 : DHCPNameServer = 10.128.128.128<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\MP3 Skype Recorder\Skype4COM.dll<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
AppInit_DLLs= c:\progra~3\browse~1\22580~1.182\{16cdf~1\brwmngr.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
x64-mStart Page = hxxp://asus.msn.com<br />
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br />
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll<br />
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll<br />
x64-TB: &lt;No Name&gt;: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - &lt;no file&gt;<br />
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 <br />
x64-Run: [AtherosBtStack] &quot;C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe&quot;<br />
x64-Run: [AthBtTray] &quot;C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe&quot;<br />
x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe<br />
x64-Run: [MSC] &quot;C:\Program Files\Microsoft Security Client\msseces.exe&quot; -hide -runkey<br />
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll<br />
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab<br />
x64-DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab<br />
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab<br />
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2012-1-17 79488]<br />
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2012-1-17 40064]<br />
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-1-20 230320]<br />
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]<br />
R1 RapportCerberus_51755;RapportCerberus_51755;C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_51755.sys [2013-3-26 586072]<br />
R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-4-2 228600]<br />
R1 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-4-2 357272]<br />
R2 AFBAgent;AFBAgent;C:\Windows\System32\FBAgent.exe [2012-1-17 379520]<br />
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-1-17 204288]<br />
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-9-28 361984]<br />
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]<br />
R2 Atheros Bt&amp;Wlan Coex Agent;Atheros Bt&amp;Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-3-13 138400]<br />
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-13 74912]<br />
R2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [2013-4-11 93984]<br />
R2 CronService;Cron Service for Prey;C:\Prey\platform\windows\cronsvc.exe [2012-11-28 23552]<br />
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-13 418376]<br />
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-13 701512]<br />
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2012-3-20 130008]<br />
R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-4-2 1124184]<br />
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search &amp; Destroy\SDWinSec.exe [2012-6-24 1153368]<br />
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-3-19 3289208]<br />
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-3-27 3560288]<br />
R3 AiCharger;ASUS Charger Driver;C:\Windows\System32\drivers\AiCharger.sys [2012-1-17 16768]<br />
R3 amdhub30;AMD USB 3.0 Hub Driver;C:\Windows\System32\drivers\amdhub30.sys [2012-1-17 96896]<br />
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2012-1-17 46136]<br />
R3 amdxhc;AMD USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\amdxhc.sys [2012-1-17 214144]<br />
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-1-17 231440]<br />
R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-13 28832]<br />
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2011-11-10 138024]<br />
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-8-27 25928]<br />
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-1-27 379360]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-17 452200]<br />
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-1-17 53376]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]<br />
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-2 183560]<br />
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2011-10-18 48488]<br />
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]<br />
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);C:\Windows\System32\drivers\L1C62x64.sys [2009-6-10 57344]<br />
S3 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE --&gt; c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE XE [?]<br />
S3 OracleXETNSListener;OracleXETNSListener;C:\oraclexe\app\oracle\product\11.2.0\server\bin\TNSLSNR.EXE [2011-8-27 512000]<br />
S3 RapportKE64;RapportKE64;C:\Windows\System32\drivers\RapportKE64.sys [2012-7-28 236248]<br />
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2012-1-17 250984]<br />
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\System32\drivers\SiSG664.sys [2009-6-10 56832]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-2-18 59392]<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2011-2-18 31232]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]<br />
S3 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2012-6-14 109064]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-6-24 1255736]<br />
S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE --&gt; c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe XE [?]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]<br />
SUnknown exhuyfpe;exhuyfpe; [x]<br />
.<br />
=============== File Associations ===============<br />
.<br />
FileExt: .txt: Applications\Notepad2.exe=&quot;C:\Program Files (x86)\notepad2\Notepad2.exe&quot; &quot;%1&quot; [UserChoice]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-04-28 17:33:12	--------	d-----w-	C:\Users\Murray\AppData\Local\Deal Spy<br />
2013-04-28 17:31:39	--------	d-----w-	C:\MyMusic<br />
2013-04-28 17:31:23	--------	d-----w-	C:\Program Files (x86)\1-Click YouTube Downloader<br />
2013-04-28 17:31:10	--------	d-----w-	C:\Program Files (x86)\SearchProtect<br />
2013-04-28 17:30:56	--------	d-----w-	C:\Users\Murray\AppData\Roaming\SearchProtect<br />
2013-04-28 13:29:57	9317456	----a-w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E74855B8-C9DF-40DC-9060-AB890629074A}\mpengine.dll<br />
2013-04-27 14:42:10	9317456	------w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll<br />
2013-04-24 11:27:28	905296	------w-	C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4836E450-50AE-48B1-BF6F-3AF6E7CD20CE}\gapaengine.dll<br />
2013-04-23 20:25:39	1656680	----a-w-	C:\Windows\System32\drivers\ntfs.sys<br />
2013-04-19 15:55:45	--------	d-----w-	C:\Users\Murray\TeleKast<br />
2013-04-19 15:55:42	--------	d-----w-	C:\Users\Murray\AppData\Roaming\Lightscape<br />
2013-04-19 15:55:42	--------	d-----w-	C:\Users\Murray\AppData\Local\Lightscape<br />
2013-04-19 15:55:31	--------	d-----w-	C:\Program Files (x86)\TeleKast<br />
2013-04-10 12:02:47	3717632	----a-w-	C:\Windows\System32\mstscax.dll<br />
2013-04-10 12:02:46	3217408	----a-w-	C:\Windows\SysWow64\mstscax.dll<br />
2013-04-10 12:02:44	44032	----a-w-	C:\Windows\System32\tsgqec.dll<br />
2013-04-10 12:02:44	36864	----a-w-	C:\Windows\SysWow64\tsgqec.dll<br />
2013-04-10 12:02:44	158720	----a-w-	C:\Windows\System32\aaclient.dll<br />
2013-04-10 12:02:44	131584	----a-w-	C:\Windows\SysWow64\aaclient.dll<br />
2013-04-10 12:02:32	3153408	----a-w-	C:\Windows\System32\win32k.sys<br />
2013-04-10 12:00:51	223752	----a-w-	C:\Windows\System32\drivers\fvevol.sys<br />
2013-04-10 12:00:46	5550424	----a-w-	C:\Windows\System32\ntoskrnl.exe<br />
2013-04-10 12:00:44	3968856	----a-w-	C:\Windows\SysWow64\ntkrnlpa.exe<br />
2013-04-10 12:00:44	3913560	----a-w-	C:\Windows\SysWow64\ntoskrnl.exe<br />
2013-04-10 12:00:43	43520	----a-w-	C:\Windows\System32\csrsrv.dll<br />
2013-04-10 12:00:43	112640	----a-w-	C:\Windows\System32\smss.exe<br />
2013-04-10 12:00:42	6656	----a-w-	C:\Windows\SysWow64\apisetschema.dll<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-04-29 02:32:03	29	----a-w-	C:\Windows\SysWow64\TempWmicBatchFile.bat<br />
2013-04-24 13:27:26	71048	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2013-04-24 13:27:26	691592	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2013-04-11 14:22:56	770384	----a-w-	C:\Windows\SysWow64\msvcr100.dll<br />
2013-04-11 14:22:56	421200	----a-w-	C:\Windows\SysWow64\msvcp100.dll<br />
2013-04-04 18:50:32	25928	----a-w-	C:\Windows\System32\drivers\mbam.sys<br />
2013-04-02 17:16:10	236248	----a-w-	C:\Windows\System32\drivers\RapportKE64.sys<br />
2013-04-02 10:34:28	282744	------w-	C:\Windows\System32\MpSigStub.exe<br />
2013-03-06 20:58:38	95648	----a-w-	C:\Windows\SysWow64\WindowsAccessBridge-32.dll<br />
2013-03-06 20:58:32	861088	----a-w-	C:\Windows\SysWow64\npDeployJava1.dll<br />
2013-03-06 20:58:32	782240	----a-w-	C:\Windows\SysWow64\deployJava1.dll<br />
2013-02-22 14:36:37	45056	----a-w-	C:\Windows\SysWow64\acovcnt.exe<br />
2013-02-22 06:27:49	2312704	----a-w-	C:\Windows\System32\jscript9.dll<br />
2013-02-22 06:20:51	1392128	----a-w-	C:\Windows\System32\wininet.dll<br />
2013-02-22 06:19:37	1494528	----a-w-	C:\Windows\System32\inetcpl.cpl<br />
2013-02-22 06:15:48	173056	----a-w-	C:\Windows\System32\ieUnatt.exe<br />
2013-02-22 06:15:23	599040	----a-w-	C:\Windows\System32\vbscript.dll<br />
2013-02-22 06:12:41	2382848	----a-w-	C:\Windows\System32\mshtml.tlb<br />
2013-02-22 03:46:00	1800704	----a-w-	C:\Windows\SysWow64\jscript9.dll<br />
2013-02-22 03:38:00	1129472	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2013-02-22 03:37:50	1427968	----a-w-	C:\Windows\SysWow64\inetcpl.cpl<br />
2013-02-22 03:34:17	142848	----a-w-	C:\Windows\SysWow64\ieUnatt.exe<br />
2013-02-22 03:34:03	420864	----a-w-	C:\Windows\SysWow64\vbscript.dll<br />
2013-02-22 03:31:46	2382848	----a-w-	C:\Windows\SysWow64\mshtml.tlb<br />
2013-02-12 05:45:24	135168	----a-w-	C:\Windows\apppatch\AppPatch64\AcXtrnal.dll<br />
2013-02-12 05:45:22	350208	----a-w-	C:\Windows\apppatch\AppPatch64\AcLayers.dll<br />
2013-02-12 05:45:22	308736	----a-w-	C:\Windows\apppatch\AppPatch64\AcGenral.dll<br />
2013-02-12 05:45:22	111104	----a-w-	C:\Windows\apppatch\AppPatch64\acspecfc.dll<br />
2013-02-12 04:48:31	474112	----a-w-	C:\Windows\apppatch\AcSpecfc.dll<br />
2013-02-12 04:48:26	2176512	----a-w-	C:\Windows\apppatch\AcGenral.dll<br />
2013-02-12 04:12:05	19968	----a-w-	C:\Windows\System32\drivers\usb8023.sys<br />
.<br />
============= FINISH: 23:03:25.82 ===============<br />
<br />
Malwarebytes Anti-Malware (Trial) 1.62.0.1300<br />
<a rel="nofollow" href="http://www.malwarebytes.org" target="_blank">www.malwarebytes.org</a><br />
<br />
Database version: v2012.08.28.01<br />
<br />
Windows 7 Service Pack 1 x64 NTFS<br />
Internet Explorer 9.0.8112.16421<br />
Murray :: LRCM-PC [administrator]<br />
<br />
Protection: Enabled<br />
<br />
8/27/2012 8:59:18 PM<br />
mbam-log-2012-08-27 (20-59-18).txt<br />
<br />
Scan type: Quick scan<br />
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM<br />
Scan options disabled: P2P<br />
Objects scanned: 196503<br />
Time elapsed: 5 minute(s), 8 second(s)<br />
<br />
Memory Processes Detected: 0<br />
(No malicious items detected)<br />
<br />
Memory Modules Detected: 0<br />
(No malicious items detected)<br />
<br />
Registry Keys Detected: 2<br />
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -&gt; Quarantined and deleted successfully.<br />
HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Values Detected: 1<br />
HKCU\Software\InstalledBrowserExtensions\215 Apps|2258 (PUP.CrossFire.SA) -&gt; Data: I Want This -&gt; Quarantined and deleted successfully.<br />
<br />
Registry Data Items Detected: 0<br />
(No malicious items detected)<br />
<br />
Folders Detected: 0<br />
(No malicious items detected)<br />
<br />
Files Detected: 1<br />
C:\Users\Murray\Local Settings\TempDIR\BetterInstaller.exe (PUP.BundleInstaller.Somoto) -&gt; Quarantined and deleted successfully.<br />
<br />
(end)</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>MurrayWise</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256737-Inactive-unwanted-mixidj-search-engine</guid>
		</item>
		<item>
			<title><![CDATA[[Inactive] Fbi virus]]></title>
			<link>http://discussions.virtualdr.com/showthread.php?256731-Inactive-Fbi-virus&amp;goto=newpost</link>
			<pubDate>Sun, 28 Apr 2013 11:40:40 GMT</pubDate>
			<description>Have a dell dimension 4700 that boots to the fbi virus. I try to go to safe mode but get a blue screen technical error. It is just an older computer. I there any other way to remove this without going to safe mode?</description>
			<content:encoded><![CDATA[<div>Have a dell dimension 4700 that boots to the fbi virus. I try to go to safe mode but get a blue screen technical error. It is just an older computer. I there any other way to remove this without going to safe mode?</div>

 ]]></content:encoded>
			<category domain="http://discussions.virtualdr.com/forumdisplay.php?71-Intensive-Care-Unit">Intensive Care Unit</category>
			<dc:creator>kspeel</dc:creator>
			<guid isPermaLink="true">http://discussions.virtualdr.com/showthread.php?256731-Inactive-Fbi-virus</guid>
		</item>
	</channel>
</rss>
