1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Annoying buzz when playing music

Discussion in 'Malware and Virus Removal Archive' started by Torontopaddy, 2011/07/09.

  1. 2011/07/09
    Torontopaddy

    Torontopaddy Well-Known Member Thread Starter

    Joined:
    2008/12/31
    Messages:
    7
    Likes Received:
    0
    [Inactive] Annoying buzz when playing music

    I have followed your intructions and am posting the log results of the scans here.

    Malwarebytes (MBAM)

    Malwarebytes' Anti-Malware 1.51.0.1200
    www.malwarebytes.org

    Database version: 7060

    Windows 6.1.7601 Service Pack 1
    Internet Explorer 9.0.8112.16421

    7/9/2011 2:02:10 PM
    mbam-log-2011-07-09 (14-02-10).txt

    Scan type: Quick scan
    Objects scanned: 181699
    Time elapsed: 5 minute(s), 18 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    GMER


    GMER 1.0.15.15640 - http://www.gmer.net
    Rootkit scan 2011-07-09 13:25:28
    Windows 6.1.7601 Service Pack 1
    Running: vrvgc72p.exe


    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e897ec1
    Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings
    Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e897ec1 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\00247e897ec1 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)

    ---- EOF - GMER 1.0.15 ----

    I ran the MBR scan, when I clicked on "save log" it saved it to my desktop but when I went to open it windows asked what program I wanted to open it with? I re-ran it a few times and the only choice it gave me to save it in was a .txt file and I got the same result.

    DDS.txt


    .
    DDS (Ver_2011-06-23.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421
    Run by Ian Paterson at 13:39:56 on 2011-07-09
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.4095.2009 [GMT -4:00]
    .
    AV: Rogers Online Protection Anti-Virus *Enabled/Updated* {A61154FD-4365-E00F-9A33-13A09AD54B56}
    SP: Rogers Online Protection Anti-Spyware *Enabled/Updated* {1D70B519-655F-EF81-A083-28D2E15201EB}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Rogers Online Protection Firewall *Enabled* {9E2AD5D8-090A-E157-B16C-BA9564060C2D}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\Fws.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\AEADISRV.EXE
    C:\Program Files (x86)\AGI\core\4.2.0.10753\AGCoreService.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
    C:\Windows\system32\CISVC.EXE
    C:\Windows\system32\crypserv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Hewlett-Packard\HP Touch Screen Enhance Service\HPTSEnSrv.EXE
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe
    C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
    C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe
    C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe
    C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe
    C:\Program Files (x86)\Rogers Backup Manager\VaultClientSRV.exe
    C:\Program Files (x86)\Rogers Backup Manager\VaultClientUpgrade.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\System32\svchost.exe -k bdx
    C:\Windows\system32\svchost.exe -k HPService
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\WUDFHost.exe
    c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Touch Screen Enhance Service\HPTSEnProxy.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
    C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
    C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\rps.exe
    C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
    C:\Program Files (x86)\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~2\Webshots\315~1.761\webshots.scr
    C:\Program Files (x86)\Hewlett Packard\Buttons & OSDs control application gen2\FastUserSwitching.exe
    C:\Program Files (x86)\Hewlett-Packard\HP KEYBOARD\HPKEYBOARD.EXE
    C:\Program Files (x86)\Hewlett Packard\Buttons & OSDs control application gen2\HWManager.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
    C:\Program Files (x86)\Rogers\SelfHealing\shs.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files (x86)\Advanced System Optimizer 3\ASO3.exe
    C:\Program Files (x86)\Hewlett Packard\Buttons & OSDs control application gen2\OSDForm.exe
    C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
    c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    c:\Program Files (x86)\Hewlett-Packard\Media\Live TV\TVAgent.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Windows\System32\svchost.exe -k swprv
    C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
    C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
    C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
    C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
    C:\Windows\sysWOW64\wbem\wmiprvse.exe
    C:\Windows\system32\vssvc.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Bar = Preserve
    uStart Page = hxxp://rogers.my.yahoo.com/?_bc=1
    mStart Page = about:blank
    uInternet Settings,ProxyOverride = localhost;*.local
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO: agihelper.AGUtils: {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - mscoree.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: TBSB08081 Class: {2b036878-b717-4fdb-a5d3-c2c50f256f64} - C:\Program Files (x86)\YPToolbar\YellowPages.ca Toolbar\yp.ca.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
    BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
    TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB: YellowPages.ca Toolbar: {8bc9cf89-7594-4ffe-a6d9-fb585fe20a82} - C:\Program Files (x86)\YPToolbar\YellowPages.ca Toolbar\yp.ca.dll
    TB: RadioBar Toolbar: {5b291e6c-9a74-4034-971b-a4b007a0b315} -
    EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    uRun: [HPAdvisor] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe "
    uRun: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
    mRun: [Buttons & OSDs control application gen2] "C:\Program Files (x86)\Hewlett Packard\Buttons & OSDs control application gen2\FastUserSwitching.exe "
    mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    mRun: [HP KEYBOARD] "C:\Program Files (x86)\Hewlett-Packard\HP KEYBOARD\HPKEYBOARD.EXE "
    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
    mRun: [Rogers SHS] "C:\Program Files (x86)\Rogers\SelfHealing\shs.exe "
    mRun: [RogersServicepointAgent.exe] "C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
    mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe "
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe "
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    StartupFolder: C:\Users\IANPAT~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Webshots.lnk - C:\Program Files (x86)\Webshots\3.1.5.7617\Launcher.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{CEAFBA64-17B8-48C5-902D-0F679463B23C} : DhcpNameServer = 192.168.0.1
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
    Handler: intu-tt2010 - {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files (x86)\TurboTax 2010\ic2010pp.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    BHO-X64: 0x1 - No File
    BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO-X64: HP Print Enhancer - No File
    BHO-X64: agihelper.AGUtils: {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - mscoree.dll
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: TBSB08081 Class: {2B036878-B717-4FDB-A5D3-C2C50F256F64} - C:\Program Files (x86)\YPToolbar\YellowPages.ca Toolbar\yp.ca.dll
    BHO-X64: TBSB08081 - No File
    BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
    BHO-X64: FrostWire Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    BHO-X64: Ask Toolbar BHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: NetAssistantBHO Class: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll
    BHO-X64: NetAssistantBHO - No File
    BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    BHO-X64: HP Smart BHO Class - No File
    TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
    TB-X64: FrostWire Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
    TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB-X64: YellowPages.ca Toolbar: {8BC9CF89-7594-4FFE-A6D9-FB585FE20A82} - C:\Program Files (x86)\YPToolbar\YellowPages.ca Toolbar\yp.ca.dll
    TB-X64: RadioBar Toolbar: {5B291E6C-9A74-4034-971B-A4B007A0B315} -
    EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
    mRun-x64: [Buttons & OSDs control application gen2] "C:\Program Files (x86)\Hewlett Packard\Buttons & OSDs control application gen2\FastUserSwitching.exe "
    mRun-x64: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    mRun-x64: [HP KEYBOARD] "C:\Program Files (x86)\Hewlett-Packard\HP KEYBOARD\HPKEYBOARD.EXE "
    mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun-x64: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    mRun-x64: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe
    mRun-x64: [Rogers SHS] "C:\Program Files (x86)\Rogers\SelfHealing\shs.exe "
    mRun-x64: [RogersServicepointAgent.exe] "C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
    mRun-x64: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe "
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe "
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Ian Paterson\AppData\Roaming\Mozilla\Firefox\Profiles\yfog0bd2.default\
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Users\Ian Paterson\AppData\Local\HuluDesktop\instances\0.9.10.1\nphdplg.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
    R0 RapportKE64;RapportKE64;C:\Windows\system32\Drivers\RapportKE64.sys --> C:\Windows\system32\Drivers\RapportKE64.sys [?]
    R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-6-22 52496]
    R1 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-6-22 61200]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R2 AGCoreService;AG Core Services;C:\Program Files (x86)\AGI\core\4.2.0.10753\AGCoreService.exe [2010-8-5 20480]
    R2 ASO3DiskOptimizer;ASO3DiskOptimizer;C:\Program Files (x86)\Advanced System Optimizer 3\ASO3DefragSrv64.exe [2010-6-17 263480]
    R2 CalendarSynchService;CalendarSynchService;C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe [2009-7-9 21560]
    R2 HP Touch Screen Enhance;HP Touch Screen Enhance;C:\Program Files (x86)\Hewlett-Packard\HP Touch Screen Enhance Service\HPTSEnSrv.EXE [2009-1-20 101888]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-6-2 366640]
    R2 MSSQL$MAXIMIZER;SQL Server (MAXIMIZER);C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
    R2 Radialpoint Security Services;Rogers Online Protection;C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe [2010-6-7 166944]
    R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-6-22 870200]
    R2 RogersSelfHelpService;Rogers SHS Service;C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe [2010-6-3 139264]
    R2 RogersUpdateManager;Rogers Update Manager;C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe [2010-6-3 163840]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-6-6 1153368]
    R2 ServicepointService;ServicepointService;C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe [2011-2-27 689464]
    R2 TVCapSvc;TV Background Capture Service (TVBCS);C:\Program Files (x86)\Hewlett-Packard\Media\Live TV\Kernel\TV\TVCapSvc.exe [2009-7-24 275840]
    R2 VaultClientSRV;Rogers Backup Manager Service;C:\Program Files (x86)\Rogers Backup Manager\VaultClientSRV.exe [2010-6-7 1053936]
    R2 VaultClientUpgrade;Rogers Backup Manager Upgrade Service;C:\Program Files (x86)\Rogers Backup Manager\VaultClientUpgrade.exe [2010-6-7 120048]
    R3 ACPIService;Buttons and OSDs ACPI driver gen2;C:\Windows\system32\DRIVERS\OSDACPI.SYS --> C:\Windows\system32\DRIVERS\OSDACPI.SYS [?]
    R3 AVerAVF2;AVerAVF2;C:\Windows\system32\DRIVERS\AVerAVF2.sys --> C:\Windows\system32\DRIVERS\AVerAVF2.sys [?]
    R3 btusbflt;Bluetooth USB Filter;C:\Windows\system32\drivers\btusbflt.sys --> C:\Windows\system32\drivers\btusbflt.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys --> C:\Windows\system32\DRIVERS\netr28x.sys [?]
    R3 NW1900;NW1900;C:\Windows\system32\DRIVERS\NW1900.sys --> C:\Windows\system32\DRIVERS\NW1900.sys [?]
    R3 RadialpointIDSDriver;RadialpointIDSDriver;C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys [2011-2-27 132616]
    R3 RadialpointIDSFilter;RadialpointIDSFilter;C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys [2011-2-27 35848]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    S2 ASO3DiskOptimizer32;ASO3DiskOptimizer ;c:\programdata\uniplat32.exe --> c:\programdata\uniplat32.exe [?]
    S2 AxInstSV32;ActiveX Installer (AxInstSV) ;c:\programdata\vdsbas32.exe --> c:\programdata\vdsbas32.exe [?]
    S2 BFE32;Base Filtering Engine ;c:\programdata\odbccu3232.exe --> c:\programdata\odbccu3232.exe [?]
    S2 btwdins32;Bluetooth Service ;c:\programdata\iscsicpl32.exe --> c:\programdata\iscsicpl32.exe [?]
    S2 btwdins3232;Bluetooth Service ;c:\programdata\wlancfg32.exe --> c:\programdata\wlancfg32.exe [?]
    S2 btwdins323232;Bluetooth Service ;c:\programdata\remotepg32.exe --> c:\programdata\remotepg32.exe [?]
    S2 clr_optimization_v2.0.50727_3232;Microsoft .NET Framework NGEN v2.0.50727_X86 ;c:\programdata\msidntld32.exe --> c:\programdata\msidntld32.exe [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_3232;Microsoft .NET Framework NGEN v4.0.30319_X86 ;c:\programdata\drtprov32.exe --> c:\programdata\drtprov32.exe [?]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 CryptSvc32;Cryptographic Services ;c:\programdata\opengl3232.exe --> c:\programdata\opengl3232.exe [?]
    S2 DPS32;Diagnostic Policy Service ;c:\programdata\iccvid32.exe --> c:\programdata\iccvid32.exe [?]
    S2 EapHost32;Extensible Authentication Protocol ;c:\programdata\kbd10632.exe --> c:\programdata\kbd10632.exe [?]
    S2 EapHost3232;Extensible Authentication Protocol ;c:\programdata\cmicryptinstall32.exe --> c:\programdata\cmicryptinstall32.exe [?]
    S2 EFS32;Encrypting File System (EFS) ;c:\programdata\kbdinguj32.exe --> c:\programdata\kbdinguj32.exe [?]
    S2 fdPHost32;Function Discovery Provider Host ;c:\programdata\apisetschema32.exe --> c:\programdata\apisetschema32.exe [?]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-8 135664]
    S2 hkmsvc32;Health Key and Certificate Management ;c:\programdata\jsproxy32.exe --> c:\programdata\jsproxy32.exe [?]
    S2 HomeGroupListener32;HomeGroup Listener ;c:\programdata\prnntfy32.exe --> c:\programdata\prnntfy32.exe [?]
    S2 HP Health Check Service32;HP Health Check Service ;c:\programdata\oleaut3232.exe --> c:\programdata\oleaut3232.exe [?]
    S2 iPod Service32;iPod Service ;c:\programdata\signdrv32.exe --> c:\programdata\signdrv32.exe [?]
    S2 iPod Service3232;iPod Service ;c:\programdata\dhcpcsvc632.exe --> c:\programdata\dhcpcsvc632.exe [?]
    S2 MDM32;Machine Debug Manager ;c:\programdata\kbdhe32.exe --> c:\programdata\kbdhe32.exe [?]
    S2 MSDTC32;Distributed Transaction Coordinator ;c:\programdata\framedyn32.exe --> c:\programdata\framedyn32.exe [?]
    S2 MSDTC3232;Distributed Transaction Coordinator ;c:\programdata\fxscom32.exe --> c:\programdata\fxscom32.exe [?]
    S2 Net Driver HPZ1232;Net Driver HPZ12 ;c:\programdata\httpapi32.exe --> c:\programdata\httpapi32.exe [?]
    S2 Netlogon32;Netlogon ;c:\programdata\syssetup32.exe --> c:\programdata\syssetup32.exe [?]
    S2 PlugPlay32;Plug and Play ;c:\programdata\mfplay32.exe --> c:\programdata\mfplay32.exe [?]
    S2 Radialpoint Security Services32;Rogers Online Protection ;c:\programdata\nvd3dum32.exe --> c:\programdata\nvd3dum32.exe [?]
    S2 RadialpointIDSAgent;RadialpointIDSAgent;C:\Program Files (x86)\Rogers Online Protection\Rogers Online Protection\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe [2011-2-27 5832712]
    S2 RasMan32;Remote Access Connection Manager ;c:\programdata\dxptaskringtone32.exe --> c:\programdata\dxptaskringtone32.exe [?]
    S2 RogersUpdateManager32;Rogers Update Manager ;c:\programdata\kbdmonmo32.exe --> c:\programdata\kbdmonmo32.exe [?]
    S2 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2007-8-24 362992]
    S2 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-8-24 309744]
    S2 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-8-24 166384]
    S2 SensrSvc32;Adaptive Brightness ;c:\programdata\fdwnet32.exe --> c:\programdata\fdwnet32.exe [?]
    S2 SessionEnv32;Remote Desktop Configuration ;c:\programdata\tlscsp32.exe --> c:\programdata\tlscsp32.exe [?]
    S2 sppsvc32;Software Protection ;c:\programdata\dskquoui32.exe --> c:\programdata\dskquoui32.exe [?]
    S2 SQLBrowser32;SQL Server Browser ;c:\programdata\msaatext32.exe --> c:\programdata\msaatext32.exe [?]
    S2 TabletInputService32;Tablet PC Input Service ;c:\programdata\wlansec32.exe --> c:\programdata\wlansec32.exe [?]
    S2 TVCapSvc32;TV Background Capture Service (TVBCS) ;c:\programdata\api-ms-win-core-localregistry-l1-1-032.exe --> c:\programdata\api-ms-win-core-localregistry-l1-1-032.exe [?]
    S2 W32Time32;Windows Time ;c:\programdata\nlslexicons001032.exe --> c:\programdata\nlslexicons001032.exe [?]
    S2 WatAdminSvc32;Windows Activation Technologies Service ;c:\programdata\offfilt32.exe --> c:\programdata\offfilt32.exe [?]
    S2 WdiServiceHost32;Diagnostic Service Host ;c:\programdata\dispex32.exe --> c:\programdata\dispex32.exe [?]
    S2 WdiSystemHost32;Diagnostic System Host ;c:\programdata\actioncentercpl32.exe --> c:\programdata\actioncentercpl32.exe [?]
    S2 Winmgmt32;Windows Management Instrumentation ;c:\programdata\mssip3232.exe --> c:\programdata\mssip3232.exe [?]
    S2 wlcrasvc32;Windows Live Mesh remote connections service ;c:\programdata\bitsperf32.exe --> c:\programdata\bitsperf32.exe [?]
    S2 WPDBusEnum32;Portable Device Enumerator Service ;c:\programdata\bitsprx632.exe --> c:\programdata\bitsprx632.exe [?]
    S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-8 135664]
    S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms [2009-6-10 23536]
    S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2007-8-24 72176]
    S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-8-24 1083888]
    S3 ST50220;Sonix ST50220 USB Video Camera Driver;C:\Windows\system32\Drivers\ST50220.sys --> C:\Windows\system32\Drivers\ST50220.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe --> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    .
    =============== Created Last 30 ================
    .
    2011-07-09 15:40:09 -------- d-----w- C:\Users\Ian Paterson\Windows BBS
    2011-07-09 13:40:40 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{14F8A6DD-F4C7-4B1D-9B21-CA4D776E2309}\mpengine.dll
    2011-07-07 13:11:10 -------- d-----w- C:\Program Files (x86)\YPToolbar
    2011-07-05 13:31:59 -------- d-sh--w- C:\ProgramData\SysWoW32
    2011-07-04 14:04:48 -------- d-sh--w- C:\ProgramData\36CADC5BEFE181554F6706FB37457FDF
    2011-07-04 14:04:47 203776 --sh--w- C:\ProgramData\unrar.exe
    2011-07-04 14:03:26 190976 ----a-w- C:\Windows\SysWow64\hnetmon32.exe
    2011-07-04 13:59:25 -------- d-----w- C:\Program Files\Maximizer 11
    2011-07-03 17:32:06 -------- d-----w- C:\Users\Ian Paterson\Mystery Shopping
    2011-07-01 17:22:10 438808 ----a-w- C:\Windows\System32\drivers\iaStor.sys
    2011-06-21 04:08:29 -------- d-----w- C:\Users\Ian Paterson\AppData\Local\Mozilla
    2011-06-17 03:36:25 -------- d-----w- C:\Users\Ian Paterson\AppData\Local\{19CB55A4-8105-4AC8-A656-440FE35804A4}
    2011-06-15 23:50:18 3135488 ----a-w- C:\Windows\System32\win32k.sys
    2011-06-15 23:50:18 289280 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
    2011-06-15 23:50:18 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
    2011-06-15 23:50:18 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
    2011-06-15 23:50:17 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
    2011-06-15 23:50:17 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-06-15 23:50:15 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
    2011-06-15 23:50:15 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
    2011-06-15 23:50:15 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
    2011-06-15 23:50:01 861696 ----a-w- C:\Windows\System32\oleaut32.dll
    2011-06-15 23:50:00 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
    2011-06-15 23:49:56 976896 ----a-w- C:\Windows\System32\inetcomm.dll
    2011-06-15 23:49:56 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
    2011-06-13 20:39:25 -------- d-----w- C:\Users\Ian Paterson\2011 Job Search
    2011-06-13 18:29:00 -------- d-----w- C:\Users\Ian Paterson\Computer Service Tips
    .
    ==================== Find3M ====================
    .
    2011-07-05 15:27:58 1860 ----a-w- C:\Windows\System32\ASOROSet.bin
    2011-06-22 22:01:32 64272 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys
    2011-06-17 00:22:11 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-05-29 13:11:30 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    2011-05-29 13:11:20 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-05-24 23:14:10 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2011-05-24 11:42:55 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
    2011-05-24 10:40:05 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
    2011-05-24 10:40:05 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
    2011-05-24 10:39:38 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
    2011-05-24 10:37:54 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
    2011-05-04 05:25:03 2315776 ----a-w- C:\Windows\System32\tquery.dll
    2011-05-04 05:22:25 778752 ----a-w- C:\Windows\System32\mssvp.dll
    2011-05-04 05:22:25 2223616 ----a-w- C:\Windows\System32\mssrch.dll
    2011-05-04 05:22:24 75264 ----a-w- C:\Windows\System32\msscntrs.dll
    2011-05-04 05:22:24 491520 ----a-w- C:\Windows\System32\mssph.dll
    2011-05-04 05:22:24 288256 ----a-w- C:\Windows\System32\mssphtb.dll
    2011-05-04 05:19:28 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
    2011-05-04 05:19:28 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe
    2011-05-04 05:19:28 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe
    2011-05-04 04:34:43 1549312 ----a-w- C:\Windows\SysWow64\tquery.dll
    2011-05-04 04:32:02 666624 ----a-w- C:\Windows\SysWow64\mssvp.dll
    2011-05-04 04:32:01 337408 ----a-w- C:\Windows\SysWow64\mssph.dll
    2011-05-04 04:32:01 197120 ----a-w- C:\Windows\SysWow64\mssphtb.dll
    2011-05-04 04:32:01 1401344 ----a-w- C:\Windows\SysWow64\mssrch.dll
    2011-05-04 04:32:00 59392 ----a-w- C:\Windows\SysWow64\msscntrs.dll
    2011-05-04 04:28:31 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe
    2011-05-04 04:28:31 427520 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe
    2011-05-04 04:28:31 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
    2011-04-23 01:29:25 2303488 ----a-w- C:\Windows\System32\jscript9.dll
    2011-04-23 01:19:19 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-04-22 23:35:56 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2011-04-22 23:25:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-04-22 22:15:29 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
    2009-08-08 03:45:43 714528 ----a-w- C:\Program Files\JavaSetup6u15.exe
    2007-05-18 01:56:56 473072 ----a-w- C:\Program Files\msgr8ca.exe
    .
    ============= FINISH: 13:40:49.59 ===============

    DDS asked me to unzip the attached file and I didn't do that as instructed but only seemed to get the one log to save. I couldn't find the "Attach.txt" file

    I followed your instructions as best I could. Please let me know if I did anything wrong and how to correct it and I will try again.

    Thanks for your patience and your help, this is my first time for this process.
     
  2. 2011/07/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please paste Attach.txt into your next reply.

    You're not saying what are your computer issues.

    Your logs look clean so far.
     

  3. to hide this advert.

  4. 2011/07/09
    Torontopaddy

    Torontopaddy Well-Known Member Thread Starter

    Joined:
    2008/12/31
    Messages:
    7
    Likes Received:
    0
    I am getting an annoying buzz when I play music in iTunes, windows media Player and YouTube. I used a registered version of Malwarebytes and Advanced System Optimizer to do deep scans of my computer. They report evderything is cleaned up but I am still getting this annoying buzz.

    I explained in the reply to my original post that I didn't get an Attach.txt log to save when I ran DDS,. I only got the DDS.txt log even after runnning it several times.
    When I clicked on the "save log" button I got a dialogue box that asked me to save attach log as an attachment and I didn't do that as instructed. I don't know where i went wrong and if you can tell me I'll try again.
     
  5. 2011/07/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's fine.
    I don't see anything malicious in your logs, so I suggest you start new topic in Windows forum.
     
  6. 2011/07/10
    Torontopaddy

    Torontopaddy Well-Known Member Thread Starter

    Joined:
    2008/12/31
    Messages:
    7
    Likes Received:
    0
    Thanks for your attemted help. I originally posted in Windows 7 forum and was asked to transfer that post to this forum. Thanks for the suggestion but I guess that isn't the right forum for this type of problem.
     
  7. 2011/07/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We checked for possible infection in this forum. I don't see any.
     
  8. 2011/07/11
    Torontopaddy

    Torontopaddy Well-Known Member Thread Starter

    Joined:
    2008/12/31
    Messages:
    7
    Likes Received:
    0
    Thank you for trying to help me. I'll have to keep trying to find a solution to this problem.
     
  9. 2011/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome [​IMG]
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.