1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Trojan.maljava detected

Discussion in 'Malware and Virus Removal Archive' started by amaldon, 2011/10/12.

  1. 2011/10/12
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    [Resolved] Trojan.maljava detected

    Hello,

    I recently conducted a virus scan with Symantec endpoint and it discovered 5 different instances of the malware trojan.maljava. Symantec was able to clean 2 of these, delete another, and logged the remaining 2. I was then able to delete the final 2.

    So far I've had no problems with browser hijacking or anything like that though when I attempted to run GMER scan for the second time, I did get a blue screen of death. I'd rather be safe than sorry though.

    Here are my logs (note the GMER log is from my first run-through with the program):

    1) Malwarebytes Log
    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 7926

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 9.0.8112.16421

    10/12/2011 7:35:16 AM
    mbam-log-2011-10-12 (07-35-15).txt

    Scan type: Quick scan
    Objects scanned: 173624
    Time elapsed: 7 minute(s), 23 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    2) Gmer Log
    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-10-12 14:19:57
    Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD1600AAJS-75M0A0 rev.01.03E01
    Running: 5hcdbz9h.exe; Driver: C:\Users\Ben\AppData\Local\Temp\uwldqpow.sys


    ---- System - GMER 1.0.15 ----

    SSDT 8748AFD0 ZwAlertResumeThread
    SSDT 85AFB790 ZwAlertThread
    SSDT 87580AF8 ZwAllocateVirtualMemory
    SSDT 87489C40 ZwAlpcConnectPort
    SSDT 87583E68 ZwAssignProcessToJobObject
    SSDT 8748AD20 ZwCreateMutant
    SSDT 87583B88 ZwCreateSymbolicLinkObject
    SSDT 8757EB90 ZwCreateThread
    SSDT 87583F48 ZwDebugActiveProcess
    SSDT 8757FAD0 ZwDuplicateObject
    SSDT 87581B18 ZwFreeVirtualMemory
    SSDT 8748AE10 ZwImpersonateAnonymousToken
    SSDT 8748AEF0 ZwImpersonateThread
    SSDT 87479B10 ZwLoadDriver
    SSDT 87581A18 ZwMapViewOfSection
    SSDT 87582D00 ZwOpenEvent
    SSDT 8757EA78 ZwOpenProcess
    SSDT 8757F9F0 ZwOpenProcessToken
    SSDT 87582B40 ZwOpenSection
    SSDT 8757FBA0 ZwOpenThread
    SSDT 87583D78 ZwProtectVirtualMemory
    SSDT 87573A18 ZwResumeThread
    SSDT 87573C58 ZwSetContextThread
    SSDT 87575E78 ZwSetInformationProcess
    SSDT 875829F8 ZwSetSystemInformation
    SSDT 87582C20 ZwSuspendProcess
    SSDT 87573AB8 ZwSuspendThread
    SSDT 8757DA68 ZwTerminateProcess
    SSDT 87573B98 ZwTerminateThread
    SSDT 87575F48 ZwUnmapViewOfSection
    SSDT 87580A08 ZwWriteVirtualMemory
    SSDT 87583C78 ZwCreateThreadEx

    INT 0x51 ? 85B9CBF8
    INT 0x61 ? 85B9CBF8
    INT 0x61 ? 85B9CBF8
    INT 0x61 ? 85B9CBF8
    INT 0x61 ? 85B9CBF8
    INT 0x82 ? 85B9CBF8
    INT 0x92 ? 85B9CBF8
    INT 0xA2 ? 85B9CBF8
    INT 0xB2 ? 8424ABF8
    INT 0xB2 ? 8424ABF8
    INT 0xB2 ? 8424ABF8
    INT 0xB2 ? 8424ABF8
    INT 0xB2 ? 8424ABF8
    INT 0xB2 ? 8424ABF8
    INT 0xB2 ? 8424ABF8

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!KeSetEvent + 11D 81EB48A0 8 Bytes [D0, AF, 48, 87, 90, B7, AF, ...]
    .text ntkrnlpa.exe!KeSetEvent + 131 81EB48B4 4 Bytes [F8, 0A, 58, 87] {CLC ; OR BL, [EAX-0x79]}
    .text ntkrnlpa.exe!KeSetEvent + 13D 81EB48C0 4 Bytes [40, 9C, 48, 87]
    .text ntkrnlpa.exe!KeSetEvent + 191 81EB4914 4 Bytes [68, 3E, 58, 87]
    .text ntkrnlpa.exe!KeSetEvent + 1F5 81EB4978 4 Bytes [20, AD, 48, 87]
    .text ...
    ? System32\Drivers\spiu.sys The system cannot find the path specified. !
    .text USBPORT.SYS!DllUnload 8814441B 5 Bytes JMP 85B9C1D8
    .text ad2bo5i9.SYS 87FC2000 22 Bytes [82, 93, 1C, 82, 6C, 92, 1C, ...]
    .text ad2bo5i9.SYS 87FC2017 137 Bytes [00, 32, A7, 78, 80, 3D, A5, ...]
    .text ad2bo5i9.SYS 87FC20A1 43 Bytes [10, EB, 81, 74, 06, E5, 81, ...]
    .text ad2bo5i9.SYS 87FC20CE 10 Bytes [00, 00, 00, 00, 00, 00, C9, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; LEAVE ; HLT ; POP ESP; DEC EDX}
    .text ad2bo5i9.SYS 87FC20DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...]
    .text ...

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Mozilla Firefox\firefox.exe[4112] ntdll.dll!LdrLoadDll 77DA93A8 5 Bytes JMP 5717FAE0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
    .text C:\Program Files\Mozilla Firefox\plugin-container.exe[4560] USER32.dll!GetWindowInfo 764F428E 5 Bytes JMP 572F89A7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
    .text C:\Program Files\Mozilla Firefox\plugin-container.exe[4560] USER32.dll!TrackPopupMenu 765014F3 5 Bytes JMP 572F8F65 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8068E6D6] \SystemRoot\System32\Drivers\spiu.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [8068E042] \SystemRoot\System32\Drivers\spiu.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8068E800] \SystemRoot\System32\Drivers\spiu.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [8068E0C0] \SystemRoot\System32\Drivers\spiu.sys
    IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8068E13E] \SystemRoot\System32\Drivers\spiu.sys
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortNotification] CC358B04
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortWritePortUchar] 8387FE8F
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] [100D8BA5] \Program Files\DAEMON Tools Lite\Engine.dll (Helper library/DT Soft Ltd)
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F87FE60
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortStallExecution] 54771129
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortInitialize] B18D0502
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8
    IAT \SystemRoot\System32\Drivers\ad2bo5i9.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74C57817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74CAA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74C5BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74C4F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74C575E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74C4E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74C88395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74C5DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74C4FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74C4FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74C471CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74CDCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74C7C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74C4D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74C46853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74C4687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74C52AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9B02] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9B02] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9B02] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9B02] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9B02] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9B02] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA99EE] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [6BFA9967] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
    IAT C:\Program Files\AIM\aim.exe[2808] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9B8F] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 84BE91F8
    Device \FileSystem\fastfat \FatCdrom 92C52500
    Device \Driver\volmgr \Device\VolMgrControl 8424C1F8
    Device \Driver\sptd \Device\553672001 spiu.sys
    Device \Driver\usbuhci \Device\USBPDO-0 85F891F8
    Device \Driver\usbuhci \Device\USBPDO-1 85F891F8
    Device \Driver\usbuhci \Device\USBPDO-2 85F891F8
    Device \Driver\usbehci \Device\USBPDO-3 85EF91F8
    Device \Driver\usbuhci \Device\USBPDO-4 85F891F8

    AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)

    Device \Driver\usbuhci \Device\USBPDO-5 85F891F8
    Device \Driver\usbuhci \Device\USBPDO-6 85F891F8
    Device \Driver\volmgr \Device\HarddiskVolume1 8424C1F8
    Device \Driver\usbehci \Device\USBPDO-7 85EF91F8
    Device \Driver\volmgr \Device\HarddiskVolume2 8424C1F8
    Device \Driver\cdrom \Device\CdRom0 85EFB1F8
    Device \Driver\volmgr \Device\HarddiskVolume3 8424C1F8
    Device \Driver\cdrom \Device\CdRom1 85EFB1F8
    Device \Driver\volmgr \Device\HarddiskVolume4 8424C1F8
    Device \Driver\netbt \Device\NetBT_Tcpip_{85B3E74F-D2DA-48AB-AEAC-57BE327755E4} 872BA500
    Device \Driver\netbt \Device\NetBT_Tcpip_{DBFAC80E-BCB6-464C-9A75-3BEF37FDACBC} 872BA500
    Device \Driver\netbt \Device\NetBt_Wins_Export 872BA500
    Device \Driver\Smb \Device\NetbiosSmb 91965500
    Device \Driver\PCI_PNP7992 \Device\0000004e spiu.sys
    Device \Driver\iScsiPrt \Device\RaidPort0 85F911F8

    AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
    AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)

    Device \Driver\usbuhci \Device\USBFDO-0 85F891F8
    Device \Driver\USBSTOR \Device\0000006c 870501F8
    Device \Driver\usbuhci \Device\USBFDO-1 85F891F8
    Device \Driver\usbuhci \Device\USBFDO-2 85F891F8
    Device \Driver\USBSTOR \Device\0000006f 870501F8
    Device \Driver\usbehci \Device\USBFDO-3 85EF91F8
    Device \Driver\usbuhci \Device\USBFDO-4 85F891F8
    Device \Driver\usbuhci \Device\USBFDO-5 85F891F8
    Device \Driver\usbuhci \Device\USBFDO-6 85F891F8
    Device \Driver\usbehci \Device\USBFDO-7 85EF91F8
    Device \Driver\ad2bo5i9 \Device\Scsi\ad2bo5i91 85EF81F8
    Device \Driver\ad2bo5i9 \Device\Scsi\ad2bo5i91Port7Path0Target0Lun0 85EF81F8
    Device \FileSystem\fastfat \Fat 92C52500

    AttachedDevice \FileSystem\fastfat \Fat FLTMGR.SYS (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    Device \FileSystem\cdfs \Cdfs 843FE1F8

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4E 0x4C 0xDA 0x05 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x8F 0xE0 0x8E 0x7C ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2B 0xFE 0x2D 0x85 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x4E 0x4C 0xDA 0x05 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x8F 0xE0 0x8E 0x7C ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2B 0xFE 0x2D 0x85 ...

    ---- EOF - GMER 1.0.15 ----

    3) MBR log (Quick scan):
    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-10-12 21:19:33
    -----------------------------
    21:19:33.551 OS Version: Windows 6.0.6002 Service Pack 2
    21:19:33.552 Number of processors: 2 586 0xF0D
    21:19:33.553 ComputerName: BEN-PC UserName: Ben
    21:19:39.508 Initialize success
    21:19:44.766 AVAST engine defs: 11101201
    21:19:49.049 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
    21:19:49.052 Disk 0 Vendor: WDC_WD1600AAJS-75M0A0 01.03E01 Size: 152587MB BusType: 3
    21:19:51.265 Disk 0 MBR read successfully
    21:19:51.270 Disk 0 MBR scan
    21:19:51.472 Disk 0 Windows VISTA default MBR code
    21:19:51.515 Disk 0 scanning sectors +312496128
    21:19:51.780 Disk 0 scanning C:\Windows\system32\drivers
    21:20:19.247 Service scanning
    21:20:39.080 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
    21:20:40.087 Modules scanning
    21:21:03.783 Disk 0 trace - called modules:
    21:21:03.843 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x84be61f8]<<
    21:21:03.849 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x852e6620]
    21:21:04.215 3 CLASSPNP.SYS[881a18b3] -> nt!IofCallDriver -> [0x84d15878]
    21:21:04.225 5 acpi.sys[807b76bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x83e45b98]
    21:21:04.236 \Driver\atapi[0x84c40520] -> IRP_MJ_CREATE -> 0x84be61f8
    21:21:06.519 AVAST engine scan C:\Windows
    21:21:17.677 AVAST engine scan C:\Windows\system32
    21:24:49.020 AVAST engine scan C:\Windows\system32\drivers
    21:25:01.402 AVAST engine scan C:\Users\Ben
    21:39:47.554 AVAST engine scan C:\ProgramData
    21:42:07.110 Scan finished successfully
    21:47:54.300 Disk 0 MBR has been saved successfully to "C:\Users\Ben\Documents\Desktop\MBR.dat "
    21:47:54.306 The log file has been saved successfully to "C:\Users\Ben\Documents\Desktop\aswMBR.txt "

    4) DDS log

    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
    Run by Ben at 21:48:45 on 2011-10-12
    Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6002.2.1252.1.1033.18.2012.631 [GMT -4:00]
    .
    AV: Symantec Endpoint Protection *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Symantec Endpoint Protection *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\AERTSrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe
    C:\Program Files\ARX\ARX CryptoKit\utils\arcltsrv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
    C:\Windows\system32\NLSSRV32.EXE
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\New Boundary\PrismXL\PrismXL.sys
    C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\Smc.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
    C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\AIM\aim.exe
    C:\Users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\SymCorpUI.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\SmcGui.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\ips\IPSBHO.DLL
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
    BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
    uRun: [Google Update] "c:\users\ben\appdata\local\google\update\GoogleUpdate.exe" /c
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [vspdfprsrv.exe] c:\program files\visagesoft\expert pdf 6\vspdfprsrv.exe --background
    mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide
    mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    StartupFolder: c:\users\ben\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\ben\appdata\roaming\dropbox\bin\Dropbox.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    TCP: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{85B3E74F-D2DA-48AB-AEAC-57BE327755E4} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{DBFAC80E-BCB6-464C-9A75-3BEF37FDACBC} : DhcpNameServer = 192.168.10.1
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Notify: igfxcui - igfxdev.dll
    Notify: SEP - c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\WinLogoutNotifier.dll
    AppInit_DLLs: KATRACK.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\ben\appdata\roaming\mozilla\firefox\profiles\734osqt1.default\
    FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
    FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
    FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
    FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
    FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
    FF - plugin: c:\users\ben\appdata\local\google\update\1.3.21.69\npGoogleUpdate3.dll
    FF - plugin: c:\users\ben\appdata\roaming\mozilla\plugins\npgoogletalk.dll
    FF - plugin: c:\users\ben\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    ============= SERVICES / DRIVERS ===============
    .
    R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\sep\0c01029f\136b.105\x86\SymDS.sys [2011-5-2 340088]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\sep\0c01029f\136b.105\x86\SymEFA.sys [2011-5-17 756856]
    R1 BHDrvx86;BHDrvx86;c:\programdata\symantec\symantec endpoint protection\12.1.671.4971.105\data\definitions\bashdefs\20110929.001\BHDrvx86.sys [2011-9-29 816760]
    R1 IDSVix86;IDSVix86;c:\programdata\symantec\symantec endpoint protection\12.1.671.4971.105\data\definitions\ipsdefs\20111012.030\IDSvix86.sys [2011-10-12 368248]
    R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\sep\0c01029f\136b.105\x86\Ironx86.sys [2011-5-10 136312]
    R1 SYMTDIV;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\sep\0c01029f\136b.105\x86\symtdiv.sys [2011-4-21 331384]
    R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
    R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2010-4-19 81920]
    R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\nitro pdf\professional\NitroPDFDriverService.exe [2009-12-16 188736]
    R2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2009-12-16 65856]
    R2 SepMasterService;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\ccSvcHst.exe [2011-6-14 137224]
    R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-4-1 428640]
    R3 athur;Wireless Network Adapter Service;c:\windows\system32\drivers\athur.sys [2011-9-8 1387008]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-9-25 105592]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-4-19 112128]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-23 136176]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-23 136176]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
    S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
    S3 pbfilter;pbfilter;c:\users\ben\downloads\peerblock\pbfilter.sys [2009-9-28 16472]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2011-10-12 05:04:51 -------- d-----w- c:\users\ben\appdata\local\NPE
    2011-10-12 05:04:50 -------- d-----w- c:\programdata\Norton
    2011-10-12 02:44:51 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
    2011-10-12 02:44:51 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
    2011-10-12 02:44:51 293376 ----a-w- c:\windows\system32\psisdecd.dll
    2011-10-12 02:44:51 217088 ----a-w- c:\windows\system32\psisrndr.ax
    2011-10-12 02:44:50 2043392 ----a-w- c:\windows\system32\win32k.sys
    2011-10-12 02:44:43 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
    2011-10-12 02:44:39 563712 ----a-w- c:\windows\system32\oleaut32.dll
    2011-10-12 02:44:39 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2011-10-12 02:44:39 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-10-12 02:44:39 238080 ----a-w- c:\windows\system32\oleacc.dll
    2011-09-26 00:20:49 127096 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2011-09-26 00:20:49 -------- d-----w- c:\program files\common files\Symantec Shared
    2011-09-26 00:19:47 94128 ----a-w- c:\windows\system32\FwsVpn.dll
    2011-09-26 00:19:47 32208 ----a-w- c:\windows\system32\drivers\WGX.SYS
    2011-09-26 00:19:47 240048 ----a-w- c:\windows\system32\SymVPN.dll
    2011-09-26 00:19:17 -------- d-----w- c:\windows\system32\drivers\sep\0c01029f\136b.105\x86
    2011-09-26 00:19:17 -------- d-----w- c:\windows\system32\drivers\sep\0c01029f\136B.105
    2011-09-26 00:19:17 -------- d-----w- c:\windows\system32\drivers\sep\0C01029F
    2011-09-26 00:19:17 -------- d-----w- c:\windows\system32\drivers\SEP
    2011-09-26 00:19:17 -------- d-----w- c:\program files\Symantec
    2011-09-26 00:16:56 7269712 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{07950522-d95b-4851-94ac-9d47efcdabb6}\mpengine.dll
    2011-09-13 21:54:03 -------- d-----w- c:\program files\iPod
    .
    ==================== Find3M ====================
    .
    2011-09-01 13:25:46 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-01 02:35:59 1798144 ----a-w- c:\windows\system32\jscript9.dll
    2011-09-01 02:28:15 1126912 ----a-w- c:\windows\system32\wininet.dll
    2011-09-01 02:22:54 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-08-31 21:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    .
    ============= FINISH: 21:50:07.56 ===============
     
  2. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    Attach Log

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft® Windows Vistaâ„¢ Home Basic
    Boot Device: \Device\HarddiskVolume3
    Install Date: 4/19/2010 10:51:07 PM
    System Uptime: 10/12/2011 9:08:33 PM (0 hours ago)
    .
    Motherboard: Dell Inc. | | 0P301D
    Processor: Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz | Socket 775 | 1595/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 139 GiB total, 3.466 GiB free.
    D: is FIXED (NTFS) - 10 GiB total, 5.769 GiB free.
    E: is CDROM ()
    F: is CDROM ()
    G: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP539: 10/12/2011 8:59:47 AM - Scheduled Checkpoint
    .
    ==== Installed Programs ======================
    .
    32 Bit HP CIO Components Installer
    7-Zip 9.13 beta
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X (10.1.1)
    Adobe Shockwave Player 11.5
    AIM 7
    Amazon MP3 Downloader 1.0.12
    Amazon Unbox Video
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ARX CoSign Client
    ARX CryptoKit
    ARX Office Signatures
    ARX OmniSign Printer
    ARX Signature API
    Avanquest update
    Baseball Mogul 2011
    Baseball Mogul 2011 Patch from 1305 to 1308
    BitTorrent
    Bonjour
    CameraHelperMsi
    Camtasia Studio 7
    CCleaner
    Click to Call with Skype
    Defcon v1.6
    Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Dell Resource CD
    Download Updater (AOL LLC)
    Dropbox
    erLT
    eXPert PDF 6
    FitLive 1.1.15
    Freeciv 2.2.3 (GTK+ client)
    Google Earth
    Google Talk Plugin
    Google Update Helper
    Grand Theft Auto
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Insaniquarium Deluxe 1.0
    Insaniquarium Patch Installer 1.2
    Intel(R) Graphics Media Accelerator Driver
    iTunes
    Java Auto Updater
    Java DB 10.6.2.1
    Java(TM) 6 Update 26
    Java(TM) SE Development Kit 6 Update 26
    Logitech Vid HD
    Logitech Webcam Software
    Logitech Webcam Software Driver Package
    LWS Facebook
    LWS Gallery
    LWS Help_main
    LWS Launcher
    LWS Motion Detection
    LWS Pictures And Video
    LWS Twitter
    LWS Video Mask Maker
    LWS VideoEffects
    LWS Webcam Software
    LWS WLM Plugin
    LWS YouTube Plugin
    Magic ISO Maker v5.5 (build 0281)
    Malwarebytes' Anti-Malware version 1.51.2.1300
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Mozilla Firefox 7.0.1 (x86 en-US)
    Mozilla Thunderbird (7.0.1)
    NetBeans IDE 7.0
    Nitro PDF Professional
    OGA Notifier 2.0.0048.0
    ooVoo
    Plants vs. Zombies
    Portal
    QuickTime
    Realtek 8169 8168 8101E 8102E Ethernet Driver
    Realtek High Definition Audio Driver
    Risk WarZone Client
    Sassafras K2 Client
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft Excel 2010 (KB2553070)
    Security Update for Microsoft InfoPath 2010 (KB2510065)
    Security Update for Microsoft Office 2010 (KB2289078)
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2584066)
    Security Update for Microsoft PowerPoint 2010 (KB2519975)
    Security Update for Microsoft Publisher 2010 (KB2409055)
    Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
    Security Update for Microsoft Word 2010 (KB2345000)
    Skypeâ„¢ 5.5
    SMPlayer 0.6.8
    Spybot - Search & Destroy
    SSH Secure Shell
    Steam
    Symantec Endpoint Protection
    System Requirements Lab
    System Requirements Lab CYRI
    Team Fortress 2
    TP-LINK Wireless Client Utility
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft Office 2010 (KB2202188)
    Update for Microsoft Office 2010 (KB2413186)
    Update for Microsoft Office 2010 (KB2494150)
    Update for Microsoft Office 2010 (KB2523113)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553092)
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft OneNote 2010 (KB2493983)
    Update for Microsoft Outlook Social Connector (KB2583935)
    VLC media player 1.0.5
    Warcraft II BNE
    WinRAR archiver
    XviD & MP3 Codec Pack (remove only)
    XviD MPEG-4 Video Codec
    .
    ==== Event Viewer Messages From Past Week ========
    .
    10/6/2011 4:55:28 PM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
    10/6/2011 4:55:04 PM, Error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort0.
    10/12/2011 9:09:48 PM, Error: EventLog [6008] - The previous system shutdown at 9:06:37 PM on 10/12/2011 was unexpected.
    10/12/2011 8:56:56 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
    10/12/2011 7:35:15 AM, Error: PlugPlayManager [11] - The device Root\LEGACY_SMR210\0000 disappeared from the system without first being prepared for removal.
    .
    ==== End Of File ===========================
     

  3. to hide this advert.

  4. 2011/10/13
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    I see you have P2P software ( Azures, Limewire, BitTorrent, uTorrent etc…) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here, and here.

    I would strongly recommend that you uninstall them, and read the links above for educational value!

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.

    A Malware expert will have a look at your log in due course.
     
  5. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===========================================================

    So far things look clean to me....

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    Here's the combo fix log.

    ComboFix 11-10-13.05 - Ben 10/13/2011 17:53:52.1.2 - x86
    Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6002.2.1252.1.1033.18.2012.1067 [GMT -4:00]
    Running from: c:\users\Ben\Documents\Desktop\ComboFix.exe
    AV: Symantec Endpoint Protection *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    SP: Symantec Endpoint Protection *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\program files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
    c:\users\Ben\AppData\Roaming\0ad
    c:\users\Ben\AppData\Roaming\EurekaLog
    c:\users\Ben\Documents\~WRL2473.tmp
    c:\users\Ben\Documents\~WRL2676.tmp
    c:\windows\iun6002.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-09-13 to 2011-10-13 )))))))))))))))))))))))))))))))
    .
    .
    2011-10-13 22:03 . 2011-10-13 22:03 -------- d-----w- c:\users\Ben\AppData\Local\temp
    2011-10-12 05:04 . 2011-10-12 05:12 -------- d-----w- c:\users\Ben\AppData\Local\NPE
    2011-10-12 05:04 . 2011-10-12 05:05 -------- d-----w- c:\programdata\Norton
    2011-10-12 02:44 . 2011-07-29 16:01 293376 ----a-w- c:\windows\system32\psisdecd.dll
    2011-10-12 02:44 . 2011-07-29 16:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
    2011-10-12 02:44 . 2011-07-29 16:00 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
    2011-10-12 02:44 . 2011-07-29 16:00 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
    2011-10-12 02:44 . 2011-09-06 13:30 2043392 ----a-w- c:\windows\system32\win32k.sys
    2011-10-12 02:44 . 2011-09-14 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
    2011-10-12 02:44 . 2011-08-25 16:15 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2011-10-12 02:44 . 2011-08-25 16:14 563712 ----a-w- c:\windows\system32\oleaut32.dll
    2011-10-12 02:44 . 2011-08-25 16:14 238080 ----a-w- c:\windows\system32\oleacc.dll
    2011-10-12 02:44 . 2011-08-25 13:31 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-09-26 00:20 . 2011-09-26 00:25 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2011-09-26 00:20 . 2011-09-26 00:20 127096 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2011-09-26 00:19 . 2011-09-26 00:19 94128 ----a-w- c:\windows\system32\FwsVpn.dll
    2011-09-26 00:19 . 2011-09-26 00:19 32208 ----a-w- c:\windows\system32\drivers\WGX.SYS
    2011-09-26 00:19 . 2011-09-26 00:19 240048 ----a-w- c:\windows\system32\SymVPN.dll
    2011-09-26 00:19 . 2011-09-26 00:20 -------- d-----w- c:\program files\Symantec
    2011-09-26 00:19 . 2011-09-26 00:19 -------- d-----w- c:\windows\system32\drivers\SEP
    2011-09-26 00:16 . 2011-09-21 13:00 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{07950522-D95B-4851-94AC-9D47EFCDABB6}\mpengine.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-09-01 13:25 . 2011-05-20 02:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-08-31 21:00 . 2010-04-20 18:29 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-10-02 22:08 . 2011-03-24 03:42 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
    @= "{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2011-02-18 05:12 94208 ----a-w- c:\users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
    @= "{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2011-02-18 05:12 94208 ----a-w- c:\users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
    @= "{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2011-02-18 05:12 94208 ----a-w- c:\users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
    @= "{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2011-02-18 05:12 94208 ----a-w- c:\users\Ben\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Aim "= "c:\program files\AIM\aim.exe" [2011-01-05 4321112]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl "= "RtHDVCpl.exe" [2008-08-04 6265376]
    "LWS "= "c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-02 190808]
    "BCSSync "= "c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
    "IgfxTray "= "c:\windows\system32\igfxtray.exe" [2010-08-26 136216]
    "HotKeysCmds "= "c:\windows\system32\hkcmd.exe" [2010-08-26 171032]
    "Persistence "= "c:\windows\system32\igfxpers.exe" [2010-08-26 170520]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
    .
    c:\users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA "= 0 (0x0)
    "EnableUIADesktopToggle "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\windows\katrack.dll
    .
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WIRED Login.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WIRED Login.lnk
    backup=c:\windows\pss\WIRED Login.lnk.CommonStartup
    backupExtension=.CommonStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
    2009-04-11 03:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 136176]
    R3 Aken;Aken;c:\users\Ben\AppData\Local\0 A.D. alpha\binaries\system\aken.sys [x]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 136176]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]
    R3 pbfilter;pbfilter;c:\users\Ben\Downloads\PeerBlock\pbfilter.sys [2010-05-12 16472]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-05-28 691696]
    S0 SymDS;Symantec Data Store;c:\windows\system32\Drivers\SEP\0C01029F\136B.105\x86\SYMDS.SYS [2011-05-03 340088]
    S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\Drivers\SEP\0C01029F\136B.105\x86\SYMEFA.SYS [2011-05-18 756856]
    S1 BHDrvx86;BHDrvx86;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\BASHDefs\20110929.001\BHDrvx86.sys [2011-09-29 816760]
    S1 IDSVix86;IDSVix86;c:\programdata\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\IPSDefs\20111012.030\IDSvix86.sys [2011-08-18 368248]
    S1 SymIRON;Symantec Iron Driver;c:\windows\system32\Drivers\SEP\0C01029F\136B.105\x86\Ironx86.SYS [2011-05-11 136312]
    S1 SYMTDIV;Symantec Vista Network Dispatch Driver;c:\windows\system32\Drivers\SEP\0C01029F\136B.105\x86\SYMTDIV.SYS [2011-04-21 331384]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2008-07-15 81920]
    S2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [2009-12-16 188736]
    S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2009-12-16 65856]
    S2 SepMasterService;Symantec Endpoint Protection;c:\program files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe [2011-06-14 137224]
    S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]
    S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athur.sys [2010-01-05 1387008]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-09-26 105592]
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-07-15 112128]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 18:07]
    .
    2011-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 18:07]
    .
    2011-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1817007373-4094006305-2447620712-1000Core.job
    - c:\users\Ben\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-30 03:15]
    .
    2011-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1817007373-4094006305-2447620712-1000UA.job
    - c:\users\Ben\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-30 03:15]
    .
    .
    ------- Supplementary Scan -------
    .
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    TCP: DhcpNameServer = 192.168.1.1
    FF - ProfilePath - c:\users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\
    FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-vspdfprsrv.exe - c:\program files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
    Notify-SEP - c:\program files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\WinLogoutNotifier.dll
    AddRemove-Insaniquarium_Patch_Installer_1.2 - c:\windows\iun6002.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-10-13 18:03
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SepMasterService]
    "ImagePath "= "\ "c:\program files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe\" /s \ "Symantec Endpoint Protection\" /m \ "c:\program files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\sms.dll\" /prefetch:1 "
    --
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SmcService]
    "ImagePath "= "\ "c:\program files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\Smc.exe\" /prefetch:1 "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion]
    "SymbolicLinkValue "=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,4f,00,46,00,\
    .
    Completion time: 2011-10-13 18:06:05
    ComboFix-quarantined-files.txt 2011-10-13 22:06
    .
    Pre-Run: 4,265,259,008 bytes free
    Post-Run: 4,645,900,288 bytes free
    .
    - - End Of File - - C5C8893130FCC953E035383881A37448
     
  7. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks clean now.

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  8. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    OTL LOG

    OTL logfile created on: 10/13/2011 8:10:03 PM - Run 1
    OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Ben\Documents\Desktop
    Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.97 Gb Total Physical Memory | 1.19 Gb Available Physical Memory | 60.77% Memory free
    4.16 Gb Paging File | 3.13 Gb Available in Paging File | 75.12% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 138.96 Gb Total Space | 4.25 Gb Free Space | 3.06% Space Free | Partition Type: NTFS
    Drive D: | 10.00 Gb Total Space | 5.77 Gb Free Space | 57.69% Space Free | Partition Type: NTFS

    Computer Name: BEN-PC | User Name: Ben | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011/10/13 20:06:39 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Ben\Documents\Desktop\OTL.exe
    PRC - [2011/06/17 19:10:04 | 001,664,744 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\Smc.exe
    PRC - [2011/06/14 18:31:44 | 000,137,224 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe
    PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2011/04/01 01:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
    PRC - [2011/01/05 13:11:04 | 004,321,112 | ---- | M] (AOL Inc.) -- C:\Program Files\AIM\aim.exe
    PRC - [2009/12/22 10:21:26 | 000,116,672 | ---- | M] (Algorithmic Research Ltd.) -- C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe
    PRC - [2009/12/16 10:11:06 | 000,065,856 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\System32\NLSSRV32.EXE
    PRC - [2009/12/16 10:09:04 | 000,188,736 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
    PRC - [2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
    PRC - [2008/08/04 17:16:46 | 006,265,376 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
    PRC - [2008/07/15 12:20:04 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTSrv.exe
    PRC - [2007/07/27 00:00:00 | 000,532,480 | ---- | M] (New Boundary Technologies, Inc.) -- C:\Program Files\Common Files\New Boundary\PrismXL\PrismXL.sys


    ========== Modules (No Company Name) ==========

    MOD - [2011/03/15 07:13:46 | 004,254,560 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
    MOD - [2011/01/05 13:06:43 | 000,176,128 | ---- | M] () -- C:\Program Files\AIM\nssckbi.dll
    MOD - [2010/03/24 22:17:36 | 008,794,464 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
    MOD - [2010/03/15 16:57:20 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll


    ========== Win32 Services (SafeList) ==========

    SRV - [2011/06/23 23:20:22 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2011/06/17 19:10:04 | 001,664,744 | ---- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\Smc.exe -- (SmcService)
    SRV - [2011/06/17 18:50:30 | 000,280,496 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\snac.exe -- (SNAC)
    SRV - [2011/06/14 18:31:44 | 000,137,224 | ---- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\ccSvcHst.exe -- (SepMasterService)
    SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
    SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2011/04/01 01:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
    SRV - [2010/03/04 13:00:56 | 000,025,704 | R--- | M] (Amazon.com) [On_Demand | Stopped] -- C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe -- (ADVService)
    SRV - [2009/12/22 10:21:26 | 000,116,672 | ---- | M] (Algorithmic Research Ltd.) [Auto | Running] -- C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe -- (ARcltsrv)
    SRV - [2009/12/16 10:11:06 | 000,065,856 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\System32\NLSSRV32.EXE -- (nlsX86cc)
    SRV - [2009/12/16 10:09:04 | 000,188,736 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe -- (NitroDriverReadSpool)
    SRV - [2008/07/15 12:20:04 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AERTSrv.exe -- (AERTFilters)
    SRV - [2008/01/20 22:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2007/07/27 00:00:00 | 000,532,480 | ---- | M] (New Boundary Technologies, Inc.) [Auto | Running] -- C:\Program Files\Common Files\New Boundary\PrismXL\PrismXL.sys -- (PrismXL)


    ========== Driver Services (SafeList) ==========

    DRV - [2011/09/29 17:36:15 | 000,816,760 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\BASHDefs\20110929.001\BHDrvx86.sys -- (BHDrvx86)
    DRV - [2011/09/25 20:23:37 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\VirusDefs\20111013.003\NAVEX15.SYS -- (NAVEX15)
    DRV - [2011/09/25 20:23:36 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
    DRV - [2011/09/25 20:23:36 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
    DRV - [2011/09/25 20:23:36 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\VirusDefs\20111013.003\NAVENG.SYS -- (NAVENG)
    DRV - [2011/09/25 20:20:49 | 000,127,096 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
    DRV - [2011/08/17 21:33:36 | 000,368,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\Definitions\IPSDefs\20111012.030\IDSvix86.sys -- (IDSVix86)
    DRV - [2011/05/27 22:07:30 | 000,516,216 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\srtsp.sys -- (SRTSP)
    DRV - [2011/05/27 22:07:30 | 000,050,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
    DRV - [2011/05/17 22:32:28 | 000,756,856 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\Drivers\SEP\0C01029F\136B.105\x86\SYMEFA.SYS -- (SymEFA)
    DRV - [2011/05/10 22:54:58 | 000,136,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\Ironx86.sys -- (SymIRON)
    DRV - [2011/05/02 21:19:00 | 000,340,088 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\Drivers\SEP\0C01029F\136B.105\x86\SYMDS.SYS -- (SymDS)
    DRV - [2011/04/21 00:21:32 | 000,331,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\symtdiv.sys -- (SYMTDIV)
    DRV - [2011/04/01 01:11:10 | 004,333,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam Pro 9000(UVC)
    DRV - [2011/04/01 01:09:48 | 000,291,424 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
    DRV - [2010/05/28 17:39:26 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
    DRV - [2010/05/12 11:18:29 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Users\Ben\Downloads\PeerBlock\pbfilter.sys -- (pbfilter)
    DRV - [2010/05/07 18:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
    DRV - [2010/03/04 21:50:14 | 000,261,152 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
    DRV - [2010/01/05 18:54:52 | 001,387,008 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athur.sys -- (athur)
    DRV - [2008/07/15 15:20:24 | 000,112,128 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
    DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\Windows\System32\drivers\ASPI32.SYS -- (ASPI32)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========



    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    IE - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 69 E1 72 CD 1F 58 CC 01 [binary data]
    IE - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en) "
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..extensions.enabledItems: YoutubeDownloader@PeterOlayev.com:1.5
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
    FF - prefs.js..extensions.enabledItems: flickr@jzlabs.com:1.0.7
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
    FF - prefs.js..extensions.enabledItems: {e8f509f0-b677-11de-8a39-0800200c9a66}:1.8
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24


    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Ben\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ben\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ben\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Data\IPSFFPlgn\ [2011/09/25 20:21:54 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 18:08:44 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/16 02:52:21 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/09/13 17:50:31 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

    [2010/04/20 00:36:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ben\AppData\Roaming\Mozilla\Extensions
    [2010/04/20 00:36:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ben\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
    [2011/10/12 00:43:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\extensions
    [2010/04/27 10:19:59 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2010/07/06 20:49:15 | 000,000,000 | ---D | M] (Ad blocker) -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3612C}
    [2011/09/01 09:19:46 | 000,000,000 | ---D | M] ( "ImageHost Grabber ") -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
    [2011/10/12 00:43:46 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
    [2011/01/26 01:02:01 | 000,000,000 | ---D | M] ( "flickr original ") -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\extensions\flickr@jzlabs.com
    [2010/05/29 12:00:10 | 000,000,914 | ---- | M] () -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\searchplugins\dictionarycom.xml
    [2010/05/17 21:30:59 | 000,001,180 | ---- | M] () -- C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\734osqt1.default\searchplugins\urban-dictionary.xml
    [2011/06/16 21:11:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2011/08/26 03:35:54 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
    [2010/04/30 14:46:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    [2010/09/30 19:37:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2010/10/24 14:07:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    [2011/01/17 18:15:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    [2011/03/10 06:30:01 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    [2011/06/16 21:11:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
    () (No name found) -- C:\USERS\BEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\734OSQT1.DEFAULT\EXTENSIONS\{E8F509F0-B677-11DE-8A39-0800200C9A66}.XPI
    () (No name found) -- C:\USERS\BEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\734OSQT1.DEFAULT\EXTENSIONS\FLVMOVIESDOWNLOADER@RZLL.XPI
    [2011/10/02 18:08:43 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
    [2011/10/02 18:08:38 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

    O1 HOSTS File: ([2011/10/13 18:03:36 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Symantec\Symantec Endpoint Protection\12.1.671.4971.105\Bin\IPS\IPSBHO.dll (Symantec Corporation)
    O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
    O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
    O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
    O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
    O4 - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000..\Run: [Aim] C:\Program Files\AIM\aim.exe (AOL Inc.)
    O4 - Startup: C:\Users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ben\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-1817007373-4094006305-2447620712-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
    O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
    O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{85B3E74F-D2DA-48AB-AEAC-57BE327755E4}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBFAC80E-BCB6-464C-9A75-3BEF37FDACBC}: DhcpNameServer = 192.168.10.1
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O20 - AppInit_DLLs: (C:\Windows\katrack.dll) -C:\Windows\katrack.dll (Sassafras Software Inc.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Users\Ben\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
    O24 - Desktop BackupWallPaper: C:\Users\Ben\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
    O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found

    Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lameacm - C:\Windows\System32\LameACM.acm (http://www.mp3dev.org/)
    Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.i420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)
    Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)
    Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/10/13 20:06:34 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Ben\Documents\Desktop\OTL.exe
    [2011/10/13 18:06:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2011/10/13 18:06:07 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2011/10/13 18:06:07 | 000,000,000 | ---D | C] -- C:\Users\Ben\AppData\Local\temp
    [2011/10/13 17:51:02 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2011/10/13 17:51:02 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2011/10/13 17:51:02 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2011/10/13 17:50:48 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
    [2011/10/13 17:50:38 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2011/10/13 17:44:30 | 004,259,790 | R--- | C] (Swearware) -- C:\Users\Ben\Documents\Desktop\ComboFix.exe
    [2011/10/12 22:28:33 | 000,000,000 | ---D | C] -- C:\Users\Ben\Documents\Desktop\New Folder
    [2011/10/12 19:07:08 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\Ben\Documents\Desktop\aswMBR.exe
    [2011/10/12 14:25:19 | 000,000,000 | ---D | C] -- C:\Users\Ben\Documents\Desktop\announcements_files
    [2011/10/12 01:32:03 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Ben\Documents\Desktop\dds.scr
    [2011/10/12 01:04:51 | 000,000,000 | ---D | C] -- C:\Users\Ben\AppData\Local\NPE
    [2011/10/12 01:04:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2011/09/25 20:20:49 | 000,127,096 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
    [2011/09/25 20:20:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
    [2011/09/25 20:19:47 | 000,240,048 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\SymVPN.dll
    [2011/09/25 20:19:47 | 000,094,128 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\FwsVpn.dll
    [2011/09/25 20:19:47 | 000,032,208 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\WGX.SYS
    [2011/09/25 20:19:17 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86
    [2011/09/25 20:19:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Symantec Endpoint Protection
    [2011/09/25 20:19:17 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
    [2011/09/25 20:19:17 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\SEP
    [2011/09/25 20:19:17 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105
    [2011/09/25 20:19:17 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\SEP\0C01029F
    [2010/08/25 19:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll

    ========== Files - Modified Within 30 Days ==========

    [2011/10/13 20:06:39 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Ben\Documents\Desktop\OTL.exe
    [2011/10/13 19:38:03 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/10/13 19:37:04 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1817007373-4094006305-2447620712-1000UA.job
    [2011/10/13 19:15:32 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/10/13 19:15:32 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/10/13 18:03:36 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2011/10/13 17:44:33 | 004,259,790 | R--- | M] (Swearware) -- C:\Users\Ben\Documents\Desktop\ComboFix.exe
    [2011/10/13 17:15:46 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/10/13 17:15:29 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/10/13 17:15:20 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
    [2011/10/13 12:56:05 | 000,001,834 | ---- | M] () -- C:\Users\Ben\Documents\.drjava
    [2011/10/12 21:47:54 | 000,000,512 | ---- | M] () -- C:\Users\Ben\Documents\Desktop\MBR.dat
    [2011/10/12 21:10:00 | 000,371,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2011/10/12 21:08:54 | 566,701,134 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2011/10/12 20:37:02 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1817007373-4094006305-2447620712-1000Core.job
    [2011/10/12 14:25:25 | 000,039,372 | ---- | M] () -- C:\Users\Ben\Documents\Desktop\announcements.html
    [2011/10/12 03:07:18 | 001,784,030 | ---- | M] () -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\Cat.DB
    [2011/10/12 03:03:11 | 000,607,168 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/10/12 03:03:11 | 000,104,808 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/10/12 01:32:05 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Ben\Documents\Desktop\dds.scr
    [2011/10/12 01:31:47 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\Ben\Documents\Desktop\aswMBR.exe
    [2011/10/11 23:04:23 | 000,833,679 | ---- | M] () -- C:\Users\Ben\Documents\IMAG0221.jpg
    [2011/10/03 23:05:30 | 000,196,808 | ---- | M] () -- C:\Users\Ben\Documents\Video call snapshot 1.png
    [2011/10/02 09:46:07 | 000,119,296 | ---- | M] () -- C:\Users\Ben\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/09/25 20:20:49 | 000,127,096 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
    [2011/09/25 20:20:49 | 000,007,510 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
    [2011/09/25 20:20:49 | 000,000,806 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF
    [2011/09/25 20:19:47 | 000,240,048 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\SymVPN.dll
    [2011/09/25 20:19:47 | 000,094,128 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\FwsVpn.dll
    [2011/09/25 20:19:47 | 000,032,208 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\WGX.SYS
    [2011/09/25 20:19:47 | 000,000,114 | ---- | M] () -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\isolate.ini
    [2011/09/24 11:48:35 | 000,161,384 | ---- | M] () -- C:\Users\Ben\Documents\IMAG0161.jpg
    [2011/09/24 11:46:38 | 000,128,285 | ---- | M] () -- C:\Users\Ben\Documents\IMAG0153.jpg
    [2011/09/24 11:37:50 | 000,949,891 | ---- | M] () -- C:\Users\Ben\Documents\IMAG0156.jpg
    [2011/09/24 11:37:47 | 000,913,288 | ---- | M] () -- C:\Users\Ben\Documents\IMAG0157.jpg
    [2011/09/24 11:22:32 | 000,216,294 | ---- | M] () -- C:\Users\Ben\Documents\IMAG01.jpg
    [2011/09/20 09:14:09 | 000,371,239 | ---- | M] () -- C:\Users\Ben\Documents\Picture 13.png
    [2011/09/19 16:38:55 | 000,513,923 | ---- | M] () -- C:\Users\Ben\Documents\336924_10150447603429619_507089618_10964522_759740999_o.jpg

    ========== Files Created - No Company Name ==========

    [2011/10/13 17:51:02 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2011/10/13 17:51:02 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2011/10/13 17:51:02 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2011/10/13 17:51:02 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2011/10/13 17:51:02 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2011/10/12 21:47:54 | 000,000,512 | ---- | C] () -- C:\Users\Ben\Documents\Desktop\MBR.dat
    [2011/10/12 14:25:18 | 000,039,372 | ---- | C] () -- C:\Users\Ben\Documents\Desktop\announcements.html
    [2011/10/11 23:04:01 | 000,833,679 | ---- | C] () -- C:\Users\Ben\Documents\IMAG0221.jpg
    [2011/10/03 23:05:29 | 000,196,808 | ---- | C] () -- C:\Users\Ben\Documents\Video call snapshot 1.png
    [2011/09/25 20:20:52 | 001,784,030 | ---- | C] () -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\Cat.DB
    [2011/09/25 20:20:49 | 000,007,510 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
    [2011/09/25 20:20:49 | 000,000,806 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.INF
    [2011/09/25 20:19:47 | 000,000,114 | ---- | C] () -- C:\Windows\System32\drivers\SEP\0C01029F\136B.105\x86\isolate.ini
    [2011/09/24 11:48:30 | 000,161,384 | ---- | C] () -- C:\Users\Ben\Documents\IMAG0161.jpg
    [2011/09/24 11:46:36 | 000,128,285 | ---- | C] () -- C:\Users\Ben\Documents\IMAG0153.jpg
    [2011/09/24 11:36:33 | 000,949,891 | ---- | C] () -- C:\Users\Ben\Documents\IMAG0156.jpg
    [2011/09/24 11:36:20 | 000,913,288 | ---- | C] () -- C:\Users\Ben\Documents\IMAG0157.jpg
    [2011/09/24 01:00:29 | 000,216,294 | ---- | C] () -- C:\Users\Ben\Documents\IMAG01.jpg
    [2011/09/20 09:13:45 | 000,371,239 | ---- | C] () -- C:\Users\Ben\Documents\Picture 13.png
    [2011/09/19 16:38:46 | 000,513,923 | ---- | C] () -- C:\Users\Ben\Documents\336924_10150447603429619_507089618_10964522_759740999_o.jpg
    [2011/09/14 20:48:43 | 566,701,134 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2011/04/01 01:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
    [2011/04/01 01:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
    [2011/04/01 01:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
    [2011/04/01 00:56:00 | 000,027,872 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
    [2011/03/22 23:58:22 | 000,014,168 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
    [2011/03/22 23:01:04 | 000,122,816 | ---- | C] () -- C:\Windows\System32\ArMonitor.dll
    [2010/11/12 21:50:42 | 000,006,883 | ---- | C] () -- C:\Users\Ben\AppData\Roaming\.freeciv-client-rc-2.2
    [2010/10/06 22:12:07 | 000,000,061 | ---- | C] () -- C:\Windows\popcinfo.dat
    [2010/09/10 16:14:29 | 000,119,296 | ---- | C] () -- C:\Users\Ben\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/08/25 20:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
    [2010/08/25 20:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
    [2010/08/25 20:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin
    [2010/08/25 19:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
    [2010/08/25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
    [2010/08/25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
    [2010/07/01 12:12:19 | 000,020,436 | ---- | C] () -- C:\Windows\W2BNEUnin.dat
    [2010/06/10 15:37:55 | 000,641,021 | ---- | C] () -- C:\Windows\unins000.exe
    [2010/06/10 15:37:55 | 000,187,904 | ---- | C] () -- C:\Windows\System32\Lame.exe
    [2010/06/10 15:37:55 | 000,166,912 | ---- | C] () -- C:\Windows\System32\Lame_enc.dll
    [2010/06/10 15:37:55 | 000,001,662 | ---- | C] () -- C:\Windows\unins000.dat
    [2010/05/10 07:56:45 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
    [2010/05/07 18:43:30 | 000,025,824 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
    [2010/04/20 14:05:27 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
    [2010/04/19 22:34:31 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
    [2010/04/19 22:34:10 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
    [2010/04/19 22:34:10 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
    [2010/04/19 22:23:44 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
    [2010/04/19 20:01:46 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll
    [2010/04/19 20:01:45 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1545.dll
    [2010/04/19 20:01:44 | 000,147,172 | ---- | C] () -- C:\Windows\System32\igfcg550.bin
    [2009/12/03 17:27:28 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
    [2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
    [2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
    [2009/06/17 11:13:30 | 000,508,224 | ---- | C] () -- C:\Windows\System32\ICCProfiles.dll
    [2006/11/02 08:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2006/11/02 08:44:53 | 000,371,936 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2006/11/02 06:33:01 | 000,607,168 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2006/11/02 06:33:01 | 000,104,808 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
    [2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2004/12/20 11:08:28 | 000,155,648 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
    [2004/12/20 11:03:26 | 000,679,936 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
    [2000/09/01 13:00:00 | 000,001,620 | ---- | C] () -- C:\Windows\keyacc.ini

    ========== LOP Check ==========

    [2010/12/04 14:53:18 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\.freeciv
    [2011/10/12 00:47:03 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\.minecraft
    [2011/07/18 01:24:26 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\.minecraft_xray
    [2010/04/19 23:58:38 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\acccore
    [2010/05/11 11:53:25 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Amazon
    [2011/10/07 07:59:07 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\BitTorrent
    [2010/05/29 12:45:38 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\DAEMON Tools Lite
    [2010/05/10 05:46:37 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Downloaded Installations
    [2011/10/13 17:43:29 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Dropbox
    [2010/07/25 15:06:06 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\eXPert PDF 6
    [2011/06/22 01:11:08 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Fit3DLive
    [2010/06/22 13:52:03 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Leadertech
    [2011/03/14 13:10:26 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Nitro PDF
    [2010/11/12 00:36:04 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\ooVoo Details
    [2011/06/13 17:26:29 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\SSH
    [2011/06/09 19:17:45 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\SystemRequirementsLab
    [2010/04/20 00:36:27 | 000,000,000 | ---D | M] -- C:\Users\Ben\AppData\Roaming\Thunderbird
    [2011/10/13 17:14:32 | 000,032,520 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
    [2009/04/10 23:36:38 | 000,333,257 | RHS- | M] () -- C:\bootmgr
    [2010/04/19 23:46:32 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
    [2011/10/13 18:06:06 | 000,013,095 | ---- | M] () -- C:\ComboFix.txt
    [2006/09/18 17:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2010/04/19 21:10:16 | 000,540,697 | ---- | M] () -- C:\Driver_Vista_6235_03242010.zip
    [2011/01/08 14:08:43 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2011/01/13 20:26:25 | 000,000,729 | -H-- | M] () -- C:\IPH.PH
    [2010/05/16 10:14:17 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
    [2011/01/08 14:08:43 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2011/10/13 17:15:25 | 2424,578,048 | -HS- | M] () -- C:\pagefile.sys
    [2011/04/10 18:32:37 | 000,000,000 | ---- | M] () -- C:\t1do.1

    < %systemroot%\Fonts\*.com >
    [2006/11/02 08:35:34 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2006/11/02 08:35:34 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2006/11/02 08:35:34 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2010/04/19 22:42:51 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2006/09/18 17:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2009/12/04 10:53:54 | 000,281,600 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpcpp094.dll
    [2006/10/26 19:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
    [2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2008/01/20 22:57:01 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2008/01/20 23:31:11 | 015,716,352 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
    [2008/01/20 23:31:01 | 000,102,400 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
    [2008/01/20 23:31:12 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
    [2006/11/02 06:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
    [2006/11/02 06:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >
    [2010/04/25 15:15:07 | 000,000,000 | ---D | M] -- C:\Windows\system32\config\systemprofile\AppData\Local\IsolatedStorage\lggagwz5.vgj\0kkvvykp.wy2\Url.baos234cgu3y3glozyjwicytydpaxc2n\Url.x3upfl5pwc2qpjifbyrh04mtwz3rn4cm\Files\bak

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2011/05/20 21:18:11 | 000,000,286 | -HS- | M] () -- C:\Users\Ben\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2010/04/19 19:55:11 | 000,000,402 | -HS- | M] () -- C:\Users\Ben\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >
    [1999/09/10 12:06:00 | 000,004,672 | ---- | M] (Adaptec) -- C:\Windows\system\WOWPOST.EXE

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Files - Unicode (All) ==========
    [2010/05/09 01:07:00 | 000,000,000 | ---D | M](C:\Users\Ben\Favorites\??sorted Bookmarks) -- C:\Users\Ben\Favorites\뵘Ƴsorted Bookmarks

    < End of report >
     
  9. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    Extras Log

    OTL Extras logfile created on: 10/13/2011 8:10:03 PM - Run 1
    OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Ben\Documents\Desktop
    Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1.97 Gb Total Physical Memory | 1.19 Gb Available Physical Memory | 60.77% Memory free
    4.16 Gb Paging File | 3.13 Gb Available in Paging File | 75.12% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 138.96 Gb Total Space | 4.25 Gb Free Space | 3.06% Space Free | Partition Type: NTFS
    Drive D: | 10.00 Gb Total Space | 5.77 Gb Free Space | 57.69% Space Free | Partition Type: NTFS

    Computer Name: BEN-PC | User Name: Ben | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    [HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    [HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    [HKEY_USERS\S-1-5-21-1817007373-4094006305-2447620712-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{F0E2DD2F-88AE-4AD5-A84D-E44086EA80AA}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{019DFB58-3D35-4BF1-96CC-5E93E524C8F3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{025E03D3-D769-45D9-88BC-063EDB732E98}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{02CB6F0F-7D8D-45CE-BC82-2FDC8003AAAE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{04EA6CAB-5B33-479D-9F85-C0E9E73C3274}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{056D0BCD-D553-4844-9441-A77702AD0E1A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{0AA3B0BE-9AE5-4067-BB5A-F7FB2F73F587}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{0ADF2DA9-2CA2-404B-BFEC-37B36C3F557D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{0AFAB94D-34A0-491D-A105-AF4D3EBC1C92}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{0DD1850E-43B2-40C4-876A-61D61D90DFD5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{0FC5B711-B73C-4A3F-A50F-DE70DC27BBF9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{1186F8E1-F9FA-408D-8958-600F93D15E5B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{128F9C59-DF27-4D80-8350-FFFF92C59BDB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{187AD9CB-9DAF-4674-91FC-11AA8E44B79B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{187FF44A-A9DA-449F-98D4-18789D931431}" = protocol=6 | dir=in | app=c:\users\ben\appdata\local\google\google talk plugin\googletalkplugin.exe |
    "{19559E10-5A21-4E28-B9F3-C916401ABF4D}" = protocol=17 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
    "{1A03CA4D-DE3A-4C4A-A00A-4B77D3A05025}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{1C651FED-D575-4AE6-91F4-4784CD095651}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
    "{213746DB-84A2-409B-B665-DEB09AD07A3E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{214EE5AF-749D-4F32-B6D8-9D59D569B694}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{21C767DF-148F-4AFB-A24F-613099F28C30}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{2437F0E4-9951-4CFC-942D-7FBD2731D8D4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{2525A172-CA5E-4007-A613-814F12AB2DE6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{29886E7D-98A4-4121-93F6-E5384D9386CF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{2CA47DAA-1DC9-4BEA-B6D2-67F6CCA760C1}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{2D947129-D2F7-4B4F-A316-6A41C46551D5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3101E34D-E98A-4F94-AAF6-B668E6569E88}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\smc.exe |
    "{325BCE63-548F-44EA-A3F0-A605582A34A2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{32B3F821-D32C-4F5B-9D06-990ABF351C5D}" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "{32C5D0E4-B554-464F-8588-B0065AB6040C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{348D7428-7049-4D18-A5DD-5DCAD4FEFAA4}" = protocol=17 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
    "{3509C05C-3986-4DE0-966F-1E7C2051D190}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
    "{35990C44-84AD-414E-88EF-2A8DC934AB09}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3760286F-5073-4961-986D-ED68FEECD9A7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3805F4E4-93AD-4B8D-96A3-40163CE66A8D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3808948B-F0AD-497D-9A2C-966F12F05A69}" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "{39648EDD-6234-49AF-AF89-0659CCDCAE71}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3B7E620A-866B-4A71-B43C-CB0D8848363F}" = protocol=17 | dir=in | app=c:\users\ben\appdata\local\google\google talk plugin\googletalkplugin.exe |
    "{3D9163BF-AF6F-4AF1-A5E1-DA6592040B7A}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\snac.exe |
    "{3DCCDC73-FE89-44A9-B7F4-0C8B03328AF7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3F26FA7E-481E-473E-A47F-02F99E7D258A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{3F68A589-450F-4ECA-8975-F3FF8D87FF38}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{40546D3C-9D84-458D-B763-FF62484BDC8B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{422D33A7-DC80-4BFA-A035-2D9230A0BA32}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{43000567-8B84-4924-9FE0-6D6DB82BC3ED}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{43AD1910-24CB-41F3-9A44-80945A5C4D52}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{475A7C32-818A-45E4-AF53-2B5EC16288F4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{478846E9-1A88-40EF-AFF1-DB697FD76DB5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{4B79956D-DBEF-4AC5-B1B8-C6E8A8CD81D4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{4CE196B0-149B-47F8-A40C-F1A69EB7655B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{51ED6609-192F-4F0F-A495-C0AA0AB780BD}" = dir=in | app=c:\program files\itunes\itunes.exe |
    "{539A50E3-F589-4AD0-84DC-13D737502FA4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{53EE134E-30EB-453C-9444-ECD723D7C114}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{55391F4E-C7F5-42B6-9670-E44EE44EBC12}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{5659827A-BAF3-4222-84A4-CF3ED989DF53}" = protocol=17 | dir=in | app=c:\users\ben\appdata\roaming\dropbox\bin\dropbox.exe |
    "{5B5C3EBF-6324-43F7-8379-D6F773C93348}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{5B7732CE-223D-4206-8B82-5F48FBD56C6A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{5FFBBE65-A5C7-4031-8E5C-8986497144D0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{61D2F5A8-84B7-43D5-9AD6-DE9E0BFF7B3A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{65A0121D-6D4E-44BD-BABD-37205A4FAC38}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{68813375-D444-4E19-81E5-42D8FBF08CEB}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\snac.exe |
    "{695B9182-8A37-4F10-B88F-30BDAA5252FE}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\smc.exe |
    "{69F0F9B0-DE22-4D3E-BF22-8A8F350DB300}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{6D2A8B38-17AB-4EE8-8E12-2100F3B9E638}" = protocol=6 | dir=in | app=c:\windows\keyacc32.exe |
    "{6E188E55-967C-4D5D-9412-8EF9400643EF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{72AB3D2A-F72C-4399-AF6E-C993EB642BC6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{7384479C-F6EF-4350-A6BC-8A2A4F063577}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{73908E7D-6AC3-4DA6-8F1E-AE7B81DF3E23}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{73E206C4-4D4B-4996-91AD-A1C14B95A0A7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{75BD8C39-260F-4141-A9E3-22A7DC0B460D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{7C7ACB63-4A1B-4CD4-A2A0-088869A3549C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{7D5AF387-CDB4-463D-925A-0CCC10326C7F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{7DDC3C6D-F99D-4868-9264-C84F98B74807}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\snac.exe |
    "{7F42C9C5-0F19-43D3-B062-65FA4F5D9B4F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{80142717-5DCD-49F4-B0B9-6EC0A067B2CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{816D1870-B820-4704-90A1-079A24FDECD9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{81F66B28-140F-4D3B-BBB3-681ACF317C27}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{823F953F-3228-4691-9220-BFFBB07F97E9}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
    "{84209137-E628-496A-A711-D9602B3C2127}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8566234B-AA2F-413A-9D73-065FDF53A4CA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8829A717-DC3F-4314-B5C4-4C79B8111DDC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{884AED5F-9A01-4DFC-B61F-08FEF29DE00C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{88A71D6E-587B-4901-AE39-6B0A87AC3B9A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{88D32DEF-832A-4963-B559-E44B79522EFF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8A3CC328-430D-4426-BDBA-3F1E7D7E1081}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8A93C675-08CA-45F0-8E18-9F6957897869}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8C3B35B2-D723-44C4-B4B0-09BC79430392}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8C48387D-DF29-4EA1-9C7F-D5BF9D2087BA}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{8CACD180-6754-48A0-9F33-34A3457A833C}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\12.1.671.4971.105\bin\smc.exe |
    "{8D25E5CC-EF77-4144-9560-66719F0DEFB0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{90162EB6-5A90-40C5-BE72-6AABD712263E}" = protocol=17 | dir=in | app=c:\windows\keyacc32.exe |
    "{92FDDF8F-319C-434D-B821-8A6DD564089B}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{93886B0C-E89C-4996-9084-DF5A3347CD01}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{957EBC5A-5D27-4EC7-A72C-F56DB1206162}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{95FA2BE1-B487-4BE3-9849-F5ABF5FD34A2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{9627F2CB-51C9-476A-A9E1-5410B2270BFC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{964C7857-DE52-4E74-BB7F-A7B9D371539E}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
    "{99C70871-9EBE-42EA-A54A-48BDE40B76CB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{9BD9D112-6947-4B06-9A6D-8B509846AD8C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{9D8BBB19-CFF7-44BA-91B2-B439ABD82D35}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{9E90ADE0-0A05-41AF-8F66-82DF9BCD3307}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{9EB374A0-1DDD-435C-8836-6F828D87A538}" = protocol=17 | dir=in | app=c:\users\ben\appdata\local\google\google talk plugin\googletalkplugin.exe |
    "{A2F08ECB-63A1-42CA-ACE6-B796DAF465CD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A349FB16-C8D4-4392-864B-CF7C4D0DEB5C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A564B01E-9B89-431C-94CD-CB48587FAB16}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A7F57A37-4D81-4B2B-9F52-4C9334859507}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A83DABF9-F0FE-470E-BF01-42B048976B38}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A88FD550-CF7F-4466-9E95-17371CC0CF37}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A8AC7BC4-EF52-4632-A862-62A90AA1E59A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{ABD69E3B-2E1D-4C42-B987-7696941F4D0E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{AEBE29A1-2946-40B0-89B7-177AFC341A82}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{B2587BE6-4348-4ACA-B47B-8C851BA0A853}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
    "{B4BEC1E3-D1AC-4AB1-9ED2-9FA2B2D77FFB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{B66367B7-E4C3-4C67-9952-453C6C78FAE0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{B6769C4D-22F5-4918-8E2E-58E203570C44}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{BA9F6B63-B2B8-49DF-B074-344CD960FF71}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{BBE1F914-ACFC-400E-BEA0-CDA13A67BC33}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{BE806A8E-5681-4418-B7CF-2CCD18254193}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{BFADE9D3-FEBF-4590-938E-A271B975F098}" = protocol=6 | dir=in | app=c:\program files\symantec\symantec endpoint protection\smc.exe |
    "{C312A838-E16F-4241-9212-BD5EF3CB38EC}" = protocol=6 | dir=in | app=c:\users\ben\appdata\roaming\dropbox\bin\dropbox.exe |
    "{C607AE90-D24E-4CBF-9622-3B5931C828E8}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{C8C3A634-E89F-4284-A3DB-03BAF5D10249}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{C93184DB-5331-472D-8130-F198410F0C09}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{C93EE4D3-DB71-4E9D-BCD1-0E2A24C8EDD6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{C982A772-9636-48B4-9CAE-2AFAADFC97A9}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{D1865DCF-A654-4D6A-B776-2AA715220C0D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{D1E21B09-63E7-4ADE-86C3-D9C811865A25}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{D47C91EE-338F-4EE9-A83D-3A4BBA6FA2D7}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{D8BA6F79-1134-4081-9323-E6255967475C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
    "{DA6CCD60-2324-414E-98F7-F5816240673D}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
    "{DB1D078F-3CF8-400A-9E6F-8EC8F2B0C62E}" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "{DD2815EF-92BE-42D3-A943-F429D8639E2C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{DE0E9F68-B10D-4B44-B8A7-B27C2DD99F19}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{DF27999A-1597-4EF2-9490-78654AAED65A}" = protocol=6 | dir=in | app=c:\program files\logitech\logitech vid\vid.exe |
    "{E56888DD-317C-4C03-8785-C6E960F3668F}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
    "{EC7A0E7E-3383-4913-BECD-0ECE729BE1EB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{ED4330F9-65C6-414D-99E7-3E9FD2A22411}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{EE802606-08F1-461A-B7CB-548AB10CFAAD}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{EEF81C42-8B45-4937-8FF9-9F12BD5A0B25}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{EF8F66A1-BE2D-45B1-9A99-AC0798886A94}" = protocol=6 | dir=in | app=c:\users\ben\appdata\local\google\google talk plugin\googletalkplugin.exe |
    "{EFB19BD1-3091-448D-B033-FF7C079890CE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{F09186B7-47FF-4EE6-945B-3A66A7289133}" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
    "{F2123EBB-E2F1-4AD7-A702-E99F9B44DE1A}" = protocol=17 | dir=in | app=c:\program files\symantec\symantec endpoint protection\snac.exe |
    "{F39FA2DD-9874-4B07-BE76-0983402A5270}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
    "{F465E023-8182-41F1-9405-2AF94BEC4BF3}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{F7756F26-A52D-4876-BFF2-FDF4D3766676}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{F9488C62-C180-4941-9AFB-787BDE42DF27}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{FB632176-DE36-40A0-97F9-0328984D6D0C}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{FC5ED0CA-D7E3-4CC9-A397-A9471D9965CE}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{FD692829-051D-4271-BAC5-21049A4E1854}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{FDDBA97B-B87F-42FE-8BB9-69C065E3C528}" = protocol=6 | dir=in | app=c:\program files\common files\symantec shared\ccapp.exe |
    "{FEC24E32-A29D-4CC9-80D3-DB793E0D904F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{FFA098D8-3F54-4DE9-94BE-B7E7C3FFC35B}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
    "TCP Query User{29873DCC-70D6-4CEC-A1C7-62A1D17CE6D5}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
    "TCP Query User{4037E147-F3FA-4092-BE69-B79AC904CAD1}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "TCP Query User{8BEB1D4D-92AC-4281-956E-56A0EE8FBB70}C:\users\ben\appdata\local\freeciv-2.2.3-gtk2\freeciv-server.exe" = protocol=6 | dir=in | app=c:\users\ben\appdata\local\freeciv-2.2.3-gtk2\freeciv-server.exe |
    "TCP Query User{919F34EB-33E5-4BEB-AF88-EB5B97507459}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
    "TCP Query User{97869064-2DED-483D-9100-788ACF6AF22B}C:\program files\steam\steamapps\bbyang\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\bbyang\team fortress 2\hl2.exe |
    "TCP Query User{9F27FC9C-3BB1-4668-A79B-DEEB88828345}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
    "TCP Query User{AC5A31D4-7494-464C-887B-BDF1950D3726}C:\program files\defcon\defcon.exe" = protocol=6 | dir=in | app=c:\program files\defcon\defcon.exe |
    "TCP Query User{C135B294-2606-44E0-BC8B-55A73B768FBD}C:\program files\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
    "TCP Query User{E0171128-2A88-4F3C-8FD1-10847FC35908}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "TCP Query User{E20589D5-948B-481B-A9FE-ECB07B3F7FC8}C:\program files\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files\oovoo\oovoo.exe |
    "TCP Query User{EF9E9A51-3335-4412-A366-C9FE622C8C40}C:\users\ben\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\ben\appdata\roaming\dropbox\bin\dropbox.exe |
    "UDP Query User{0B3EFD37-45CE-4882-B044-136FA3A57582}C:\program files\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
    "UDP Query User{0F49983F-6FFE-41D8-B1F0-F29AE3977475}C:\program files\steam\steamapps\bbyang\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\bbyang\team fortress 2\hl2.exe |
    "UDP Query User{8DE32C6C-FCEF-4754-828C-C837998B15E8}C:\users\ben\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\ben\appdata\roaming\dropbox\bin\dropbox.exe |
    "UDP Query User{8F3961B5-33D5-443E-8497-8CEDD5281050}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
    "UDP Query User{97F9235D-A025-400A-AC94-EB58DB0B4F38}C:\users\ben\appdata\local\freeciv-2.2.3-gtk2\freeciv-server.exe" = protocol=17 | dir=in | app=c:\users\ben\appdata\local\freeciv-2.2.3-gtk2\freeciv-server.exe |
    "UDP Query User{9AD9295F-C27B-4ED9-9AF0-1ADD88E3BCFC}C:\program files\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files\oovoo\oovoo.exe |
    "UDP Query User{A1AE724F-AF4E-475F-9EB4-E74F31D07768}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "UDP Query User{BB781661-9207-439C-9737-42ADA3BDD823}C:\program files\defcon\defcon.exe" = protocol=17 | dir=in | app=c:\program files\defcon\defcon.exe |
    "UDP Query User{C92DD050-F03D-43E5-86F6-F6DA255B856F}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
    "UDP Query User{E505FA2D-F840-4A76-8DA6-B406C6FA7755}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "UDP Query User{E5E7DF38-E6EA-4CE1-A465-AA44EEA4EACE}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
    "{08A6039D-A5B8-46E8-A3F9-7E2AE5C1B191}" = Nitro PDF Professional
    "{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
    "{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
    "{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
    "{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
    "{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
    "{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
    "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 26
    "{32A3A4F4-B792-11D6-A78A-00B0D0160260}" = Java(TM) SE Development Kit 6 Update 26
    "{37B03AA0-B125-4649-900C-F26E1081F163}" = Camtasia Studio 7
    "{3B53324C-AE52-42CC-9AA5-8EB11D8F657B}" = ARX Signature API
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
    "{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
    "{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
    "{61CA2080-38ED-11DF-72AE-006FF94E2CD6}" = Baseball Mogul 2011
    "{6615AD32-C190-4E61-B418-4357B7A3C11E}" = ARX CoSign Client
    "{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
    "{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
    "{73EC658D-A1C6-40CA-8E86-E05821BAACE7}" = Java DB 10.6.2.1
    "{74E2CD0C-D4A2-11D3-95A6-0000E86CFDE5}" = SSH Secure Shell
    "{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
    "{7A2A107B-9695-423F-9462-8F17C178BD35}" = TP-LINK Wireless Client Utility
    "{82705358-3BD6-3CD5-AA9A-B8F058BE3A29}" = Google Talk Plugin
    "{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
    "{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
    "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
    "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
    "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
    "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
    "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
    "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
    "{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
    "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
    "{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
    "{95A6C205-5364-458B-AF5E-5102C9555ED4}" = ARX OmniSign Printer
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
    "{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
    "{A3AEEA68-AC93-4F6F-8D2D-78BBF7E422B8}" = Symantec Endpoint Protection
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skypeâ„¢ 5.5
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
    "{AD37DC96-D09B-4819-96E7-A9799D6B00E4}" = ARX Office Signatures
    "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
    "{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
    "{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
    "{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
    "{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
    "{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
    "{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
    "{E05E32B0-3C0D-11DF-6784-04265D1318BE}" = Baseball Mogul 2011 Patch from 1305 to 1308
    "{E23D1D2C-1762-11D5-A8D2-00C04FA35723}" = Sassafras K2 Client
    "{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F75D2B1D-5309-41DF-BC96-DFC3C3568C1D}" = ARX CryptoKit
    "{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
    "{FC279721-37A6-4777-AFD8-7A56681EBA14}" = eXPert PDF 6
    "{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
    "7-Zip" = 7-Zip 9.13 beta
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "AIM_7" = AIM 7
    "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.12
    "BitTorrent" = BitTorrent
    "CCleaner" = CCleaner
    "Defcon_is1" = Defcon v1.6
    "Grand Theft Auto" = Grand Theft Auto
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "Insaniquarium Deluxe 1.0" = Insaniquarium Deluxe 1.0
    "InstallShield_{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
    "Logitech Vid" = Logitech Vid HD
    "lvdrivers_12.10" = Logitech Webcam Software Driver Package
    "Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
    "Mozilla Thunderbird (7.0.1)" = Mozilla Thunderbird (7.0.1)
    "nbi-nb-base-7.0.0.0.0" = NetBeans IDE 7.0
    "Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
    "Plants vs. Zombies" = Plants vs. Zombies
    "Risk WarZone Client" = Risk WarZone Client
    "SMPlayer" = SMPlayer 0.6.8
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "Steam App 400" = Portal
    "Steam App 440" = Team Fortress 2
    "VLC media player" = VLC media player 1.0.5
    "Warcraft II BNE" = Warcraft II BNE
    "WinRAR archiver" = WinRAR archiver
    "XviD & MP3 Codec Pack_is1" = XviD & MP3 Codec Pack (remove only)
    "XviD_is1" = XviD MPEG-4 Video Codec

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-1817007373-4094006305-2447620712-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{dfc307dd-ab9f-4f7b-844c-a97d6e70cac4}_is1" = FitLive 1.1.15
    "Dropbox" = Dropbox
    "Freeciv-2.2.3-gtk2" = Freeciv 2.2.3 (GTK+ client)

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 7/8/2011 3:24:37 PM | Computer Name = Ben-PC | Source = Application Hang | ID = 1002
    Description = The program firefox.exe version 5.0.0.4183 stopped interacting with
    Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Problem Reports and Solutions control panel. Process
    ID: 14a8 Start Time: 01cc3ce33de865a5 Termination Time: 3275

    Error - 7/10/2011 11:31:35 PM | Computer Name = Ben-PC | Source = Symantec AntiVirus | ID = 16711731
    Description = Security Risk Found!Tracking Cookies in File: Unavailable by: Manual
    scan. Action: Quarantine failed : Leave Alone failed. Action Description: The
    file was deleted successfully.

    Error - 7/12/2011 9:36:29 PM | Computer Name = Ben-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 7/12/2011 9:42:06 PM | Computer Name = Ben-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 7/13/2011 3:09:54 AM | Computer Name = Ben-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 7/13/2011 3:09:55 AM | Computer Name = Ben-PC | Source = Windows Search Service | ID = 3013
    Description =

    Error - 7/13/2011 3:11:20 AM | Computer Name = Ben-PC | Source = Symantec AntiVirus | ID = 16711731
    Description = Security Risk Found!Tracking Cookies in File: Unavailable by: Manual
    scan. Action: Quarantine failed : Leave Alone failed. Action Description: The
    file was deleted successfully.

    Error - 7/13/2011 3:45:23 AM | Computer Name = Ben-PC | Source = Application Hang | ID = 1002
    Description = The program QuickTimePlayer.exe version 7.69.80.9 stopped interacting
    with Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Problem Reports and Solutions control panel. Process
    ID: 1160 Start Time: 01cc412035ea53d0 Termination Time: 163

    Error - 7/13/2011 4:00:17 AM | Computer Name = Ben-PC | Source = Symantec AntiVirus | ID = 16711731
    Description = Security Risk Found!Tracking Cookies in File: Unavailable by: Manual
    scan. Action: Quarantine failed : Leave Alone failed. Action Description: The
    file was deleted successfully.

    Error - 7/13/2011 9:14:21 AM | Computer Name = Ben-PC | Source = WinMgmt | ID = 10
    Description =

    [ System Events ]
    Error - 10/13/2011 5:22:43 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:24:00 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:25:30 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:29:55 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:33:38 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:35:53 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:42:00 PM | Computer Name = Ben-PC | Source = Dhcp | ID = 1001
    Description = Your computer was not assigned an address from the network (by the
    DHCP Server) for the Network Card with network address B0487A89A02E. The following
    error occurred: %%121. Your computer will continue to try and obtain an address
    on its own from the network address (DHCP) server.

    Error - 10/13/2011 5:53:22 PM | Computer Name = Ben-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 10/13/2011 5:58:51 PM | Computer Name = Ben-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 10/13/2011 6:03:39 PM | Computer Name = Ben-PC | Source = Service Control Manager | ID = 7030
    Description =


    < End of report >
     
  10. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It's clean.

    Update your Java version here: http://www.java.com/en/download/installed.jsp

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  11. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    Checkup log

    Results of screen317's Security Check version 0.99.7
    Windows Vista Service Pack 2 (UAC is disabled!)
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Symantec Endpoint Protection
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 27
    Java(TM) SE Development Kit 6 Update 26
    Java DB 10.6.2.1
    Out of date Java installed!
    Adobe Flash Player 10.3.183.7
    Adobe Reader X (10.1.1)
    Mozilla Firefox (x86 en-US..) Firefox Out of Date!
    Mozilla Thunderbird (7.0.1) Thunderbird Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Norton ccSvcHst.exe
    ``````````End of Log````````````
     
  12. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Unless you're Java developer uninstall:
    Java(TM) SE Development Kit 6 Update 26
    Java DB 10.6.2.1
     
  13. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    I'm writing Java programs for a CS class. I don't know if that qualifies as a developer though. Haha.
     
  14. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It's up to you if you need those two.
     
  15. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    I just finished the ESET online scan and there were no threats.
     
  16. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     
  17. 2011/10/13
    amaldon

    amaldon Inactive Thread Starter

    Joined:
    2011/10/12
    Messages:
    9
    Likes Received:
    0
    Here's the final log!

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Ben
    ->Temp folder emptied: 98594 bytes
    ->Temporary Internet Files folder emptied: 661719 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 60785639 bytes
    ->Flash cache emptied: 2717 bytes

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 59.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Ben
    ->Flash cache emptied: 0 bytes

    User: Default

    User: Default User

    User: Public

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.29.1 log created on 10132011_232311

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...




    I've taken your advice and have installed hippo, petunia, and web of trust.

    Thank you so much for your help Broni! This is a great site and I'll be sure to donate!
     
  18. 2011/10/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Way to go!! [​IMG]
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.