<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Techmonkeys.co.uk - All Forums]]></title>
		<link>http://www.techmonkeys.co.uk/</link>
		<description><![CDATA[Techmonkeys.co.uk - http://www.techmonkeys.co.uk]]></description>
		<pubDate>Mon, 06 Feb 2012 08:18:27 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Trojan.gen.2]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-trojan-gen-2</link>
			<pubDate>Sun, 05 Feb 2012 06:19:20 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-trojan-gen-2</guid>
			<description><![CDATA[My daughter's computer has been infected with trojan.gen.2  Symantec quarantines it but it seems to come back. Detection results lists a bunch of files called DWHC8CF.tmp, DWHF77F.tmp, etc. ad ad nauseum.<br />
<br />
I did the DDS and Attach as suggested in a noob instruction post:<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7600.16385  BrowserJavaVersion: 10.1.0<br />
Run by StellaG at 22:04:41 on 2012-02-04<br />
Microsoft Windows 7 Home Premium   6.1.7600.0.932.81.1033.18.3893.1898 [GMT -8:00&#93;<br />
.<br />
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}<br />
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}<br />
FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Program Files\Dell\DellDock\DockLogin.exe<br />
C:\Program Files\Tablet\Pen\Pen_TouchService.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE<br />
C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe<br />
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\system32\Pen_Tablet.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe<br />
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\IDT\WDM\sttray64.exe<br />
C:\Program Files\Dell\QuickSet\quickset.exe<br />
C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Users\StellaG\AppData\Roaming\Google\Google Talk\googletalk.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br />
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe<br />
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe<br />
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe<br />
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE<br />
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin<br />
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe<br />
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Freecorder\FLVSrvc.exe<br />
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe<br />
C:\Windows\splwow64.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe<br />
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe<br />
C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe<br />
c:\program files (x86)\real\realplayer\RealPlay.exe<br />
c:\program files (x86)\real\realplayer\RealPlay.exe<br />
c:\program files (x86)\real\realplayer\RealPlay.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.com/<br />
uInternet Settings,ProxyOverride = *.local<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br />
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File<br />
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll<br />
uRun: [swg&#93; "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
uRun: [Google Update&#93; "C:\Users\StellaG\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
uRun: [AdobeBridge&#93; <br />
uRun: [googletalk&#93; C:\Users\StellaG\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart<br />
uRun: [msnmsgr&#93; "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background<br />
uRunOnce: [Application Restart #1&#93; C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe "C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe" <br />
mRun: [IAStorIcon&#93; C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br />
mRun: [Dell DataSafe Online&#93; "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m<br />
mRun: [Dell Webcam Central&#93; "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2<br />
mRun: [Desktop Disc Tool&#93; "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"<br />
mRun: [QuickTime Task&#93; "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun: [CanonSolutionMenuEx&#93; C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon<br />
mRun: [IJNetworkScanUtility&#93; C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe<br />
mRun: [ccApp&#93; "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"<br />
mRun: [Adobe Reader Speed Launcher&#93; "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"<br />
mRun: [Adobe ARM&#93; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun: [iTunesHelper&#93; "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun: [AdobeCS4ServiceManager&#93; "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin<br />
mRun: [Adobe_ID0ENQBO&#93; C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
mRun: [Freecorder FLV Service&#93; "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run<br />
mRun: [SunJavaUpdateSched&#93; "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br />
mRun: [VirtualCloneDrive&#93; "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s<br />
mRun: [TkBellExe&#93; "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot<br />
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"&#93; "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"<br />
mRunOnce: [Launcher&#93; C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe<br />
mRunOnce: [DSUpdateLauncher&#93; "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"<br />
mRunOnce: [STToasterLauncher&#93; C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe<br />
StartupFolder: C:\Users\StellaG\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELL&#8203;DO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe<br />
StartupFolder: C:\Users\StellaG\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPEN&#8203;OF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab<br />
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E} : DhcpNameServer = 75.75.75.75 75.75.76.76<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\141427F6E6 : DhcpNameServer = 68.87.76.182 68.87.78.134<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\2375942554333373 : DhcpNameServer = 192.168.1.254<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\2456C6B696E6E253337393 : DhcpNameServer = 10.0.1.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\27567696E616 : DhcpNameServer = 192.168.1.254 192.168.0.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\27567696E616D27657563747 : DhcpNameServer = 192.168.1.254 192.168.33.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\34C61637379636A41636B616373723 : DhcpNameServer = 10.0.0.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\34C61637379636A41636B616373723D25374 : DhcpNameServer = 10.0.0.1<br />
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br />
BHO-X64: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll<br />
BHO-X64:     Canon Easy-WebPrint EX BHO - No File<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO-X64:     SkypeIEPluginBHO - No File<br />
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO-X64: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB-X64: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll<br />
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File<br />
EB-X64: {21347690-EC41-4F9A-8887-1F4AEE672439} - No File<br />
mRun-x64: [IAStorIcon&#93; C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br />
mRun-x64: [Dell DataSafe Online&#93; "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m<br />
mRun-x64: [Dell Webcam Central&#93; "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2<br />
mRun-x64: [Desktop Disc Tool&#93; "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"<br />
mRun-x64: [QuickTime Task&#93; "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun-x64: [CanonSolutionMenuEx&#93; C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon<br />
mRun-x64: [IJNetworkScanUtility&#93; C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe<br />
mRun-x64: [ccApp&#93; "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"<br />
mRun-x64: [Adobe Reader Speed Launcher&#93; "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"<br />
mRun-x64: [Adobe ARM&#93; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun-x64: [iTunesHelper&#93; "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun-x64: [AdobeCS4ServiceManager&#93; "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin<br />
mRun-x64: [Adobe_ID0ENQBO&#93; C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
mRun-x64: [Freecorder FLV Service&#93; "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run<br />
mRun-x64: [SunJavaUpdateSched&#93; "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br />
mRun-x64: [VirtualCloneDrive&#93; "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s<br />
mRun-x64: [TkBellExe&#93; "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot<br />
mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"&#93; "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"<br />
mRunOnce-x64: [Launcher&#93; C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe<br />
mRunOnce-x64: [DSUpdateLauncher&#93; "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"<br />
mRunOnce-x64: [STToasterLauncher&#93; C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\StellaG\AppData\Roaming\Mozilla\Firefox\Profiles\pop7e21c.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL<br />
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll<br />
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll<br />
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll<br />
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrow&#8203;serrecordext.dll<br />
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5video&#8203;shim.dll<br />
FF - plugin: C:\Users\StellaG\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll<br />
FF - plugin: C:\Users\StellaG\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll<br />
FF - plugin: C:\Users\StellaG\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --&gt; C:\Windows\system32\Drivers\PxHlpa64.sys [?&#93;<br />
R0 stdflt;Disk Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdflt.sys --&gt; C:\Windows\system32\DRIVERS\stdflt.sys [?&#93;<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --&gt; C:\Windows\system32\DRIVERS\vwififlt.sys [?&#93;<br />
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2010-9-21 89600&#93;<br />
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664&#93;<br />
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648&#93;<br />
R2 IAStorDataMgrSvc;Intel&reg; Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-9 13336&#93;<br />
R2 InstallFilterService;FF Install Filter Service;C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe [2010-11-9 60928&#93;<br />
R2 rimspci;rimspci;C:\Windows\system32\DRIVERS\rimspe64.sys --&gt; C:\Windows\system32\DRIVERS\rimspe64.sys [?&#93;<br />
R2 risdpcie;risdpcie;C:\Windows\system32\DRIVERS\risdpe64.sys --&gt; C:\Windows\system32\DRIVERS\risdpe64.sys [?&#93;<br />
R2 rixdpcie;rixdpcie;C:\Windows\system32\DRIVERS\rixdpe64.sys --&gt; C:\Windows\system32\DRIVERS\rixdpe64.sys [?&#93;<br />
R2 RosettaStoneDaemon;RosettaStoneDaemon;C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2011-3-31 1646056&#93;<br />
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264&#93;<br />
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-11-9 689472&#93;<br />
R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-6-30 1831024&#93;<br />
R2 TabletServicePen;TabletServicePen;C:\Windows\system32\Pen_Tablet.exe --&gt; C:\Windows\system32\Pen_Tablet.exe [?&#93;<br />
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-11-4 719216&#93;<br />
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --&gt; C:\Windows\system32\DRIVERS\TurboB.sys [?&#93;<br />
R2 UNS;Intel&reg; Management &amp; Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe [2010-11-9 2320920&#93;<br />
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Acceler.sys --&gt; C:\Windows\system32\DRIVERS\Acceler.sys [?&#93;<br />
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --&gt; C:\Windows\system32\DRIVERS\CtClsFlt.sys [?&#93;<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-12 138360&#93;<br />
R3 HECIx64;Intel&reg; Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?&#93;<br />
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --&gt; C:\Windows\system32\DRIVERS\Impcd.sys [?&#93;<br />
R3 IntcDAud;Intel&reg; Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --&gt; C:\Windows\system32\DRIVERS\IntcDAud.sys [?&#93;<br />
R3 NETw5s64;Intel&reg; Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys --&gt; C:\Windows\system32\DRIVERS\NETw5s64.sys [?&#93;<br />
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2010-7-30 25072&#93;<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --&gt; C:\Windows\system32\DRIVERS\Rt64win7.sys [?&#93;<br />
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --&gt; C:\Windows\system32\DRIVERS\Sftfslh.sys [?&#93;<br />
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --&gt; C:\Windows\system32\DRIVERS\Sftplaylh.sys [?&#93;<br />
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --&gt; C:\Windows\system32\DRIVERS\Sftredirlh.sys [?&#93;<br />
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --&gt; C:\Windows\system32\DRIVERS\Sftvollh.sys [?&#93;<br />
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496&#93;<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --&gt; C:\Windows\system32\DRIVERS\vwifimp.sys [?&#93;<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384&#93;<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576&#93;<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16 136176&#93;<br />
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-8-15 284016&#93;<br />
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-4-30 1038088&#93;<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16 136176&#93;<br />
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232&#93;<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2009-9-21 315664&#93;<br />
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184&#93;<br />
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352&#93;<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?&#93;<br />
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --&gt; C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?&#93;<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?&#93;<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-30 00:42:38	--------	d-----w-	C:\Users\StellaG\AppData\Local\{67D643B0-BF5B-4FE8-89CC-37D702BF016D}<br />
2012-01-30 00:42:27	--------	d-----w-	C:\Users\StellaG\AppData\Local\{FF31DEAF-4D20-4BCB-B4DC-4CBCE1882787}<br />
2012-01-30 00:22:14	--------	d-----w-	C:\WTablet<br />
2012-01-27 03:39:56	--------	d-----w-	C:\Users\StellaG\AppData\Local\{599366BB-7860-4530-B141-E42A9DD1ECAE}<br />
2012-01-27 03:39:46	--------	d-----w-	C:\Users\StellaG\AppData\Local\{337BBA0C-BC62-43CE-830E-B62AD3402548}<br />
2012-01-25 22:39:28	--------	d-----w-	C:\Users\StellaG\AppData\Local\{3B9D106C-9B53-4939-AD3C-F3827CFFDC03}<br />
2012-01-25 22:38:56	--------	d-----w-	C:\Users\StellaG\AppData\Local\{298A80CF-877C-4615-AC67-63F6E021B0BC}<br />
2012-01-25 02:11:29	--------	d-----w-	C:\Users\StellaG\AppData\Local\{802EC0F5-681C-43DB-A528-40568D12A5FF}<br />
2012-01-25 02:10:53	--------	d-----w-	C:\Users\StellaG\AppData\Local\{15FC1B1E-D0DF-4284-A42E-EAE15361CDC1}<br />
2012-01-23 23:28:29	--------	d-----w-	C:\Users\StellaG\AppData\Local\{1372B089-E7F9-4322-A5EB-A9291CBB6B0B}<br />
2012-01-23 06:46:48	--------	d-----w-	C:\Users\StellaG\AppData\Local\{D30588A1-EDD2-404B-93F5-7CC2281F4774}<br />
2012-01-22 18:46:34	--------	d-----w-	C:\Users\StellaG\AppData\Local\{893C90FB-07B2-4492-87A9-7490616F904D}<br />
2012-01-22 03:21:22	--------	d-----w-	C:\Users\StellaG\AppData\Local\{489B7082-CCED-415C-887C-EED4C31B547B}<br />
2012-01-22 03:21:11	--------	d-----w-	C:\Users\StellaG\AppData\Local\{3241C915-7593-4A35-BC4A-FF6D1EFC5AE6}<br />
2012-01-19 02:11:28	--------	d-----w-	C:\Users\StellaG\AppData\Local\{4C30E72D-2F37-473F-A3CD-15F58FC56277}<br />
2012-01-19 02:11:17	--------	d-----w-	C:\Users\StellaG\AppData\Local\{E95156D7-C077-43B4-BC38-E78FEAE7345B}<br />
2012-01-18 04:06:38	--------	d-----w-	C:\Users\StellaG\AppData\Local\{C204D1D2-BD17-4695-8365-2D101AB8888D}<br />
2012-01-17 02:03:49	--------	d-----w-	C:\Users\StellaG\AppData\Local\{38CCF4D8-CB02-4572-A040-D45EE4F17DAF}<br />
2012-01-17 02:03:39	--------	d-----w-	C:\Users\StellaG\AppData\Local\{EAEA7421-7342-481B-851C-73EFCED312BA}<br />
2012-01-15 20:18:17	--------	d-----w-	C:\Users\StellaG\AppData\Local\{B4D493C1-2FDA-4C58-822B-44C4804B14B7}<br />
2012-01-15 20:17:51	--------	d-----w-	C:\Users\StellaG\AppData\Local\{461BD313-8BCD-4762-ACB7-D0A25C879D47}<br />
2012-01-15 07:56:01	340992	----a-w-	C:\Windows\System32\schannel.dll<br />
2012-01-14 19:38:31	--------	d-----w-	C:\Users\StellaG\AppData\Local\{5F33D80C-AA61-4F48-8711-2C06ACEFD46F}<br />
2012-01-14 02:28:59	--------	d-----w-	C:\Users\StellaG\AppData\Local\{64CAAF06-E526-44EA-8A6F-7B484A732F1D}<br />
2012-01-14 02:28:48	--------	d-----w-	C:\Users\StellaG\AppData\Local\{FA124A86-087A-4F0B-B9A2-646F655A4A71}<br />
2012-01-14 02:28:08	--------	d-----w-	C:\Users\StellaG\AppData\Local\{387B6821-4CF7-4B4B-95F1-7CE43DAF1B10}<br />
2012-01-14 02:28:07	--------	d-----w-	C:\Users\StellaG\AppData\Local\{BE180405-C07F-419A-B0A7-3A9A35DDAC97}<br />
2012-01-12 23:29:22	--------	d-----w-	C:\Users\StellaG\AppData\Local\{9F24F10D-8A24-48A2-BE4E-8FC6F56C463F}<br />
2012-01-12 23:28:56	--------	d-----w-	C:\Users\StellaG\AppData\Local\{D412E0A9-FBF1-4CD0-B4EC-B452FFC268DC}<br />
2012-01-11 22:48:25	1328640	----a-w-	C:\Windows\SysWow64\quartz.dll<br />
2012-01-11 22:48:21	1572864	----a-w-	C:\Windows\System32\quartz.dll<br />
2012-01-11 22:48:18	514560	----a-w-	C:\Windows\SysWow64\qdvd.dll<br />
2012-01-11 22:48:17	366592	----a-w-	C:\Windows\System32\qdvd.dll<br />
2012-01-11 22:47:56	1739160	----a-w-	C:\Windows\System32\ntdll.dll<br />
2012-01-11 22:47:53	1292592	----a-w-	C:\Windows\SysWow64\ntdll.dll<br />
2012-01-11 22:47:49	77312	----a-w-	C:\Windows\System32\packager.dll<br />
2012-01-11 22:47:48	67072	----a-w-	C:\Windows\SysWow64\packager.dll<br />
2012-01-10 02:30:44	--------	d-----w-	C:\Users\StellaG\AppData\Local\{4AB0EE59-E981-47AC-9731-B2051C69CE96}<br />
2012-01-10 02:30:32	--------	d-----w-	C:\Users\StellaG\AppData\Local\{81053FE3-2B39-47D7-A15B-166B6C828BD0}<br />
2012-01-09 05:17:28	--------	d-----w-	C:\Users\StellaG\AppData\Local\{39B8E3EA-F85A-401E-9927-D954163E3741}<br />
2012-01-09 05:17:09	--------	d-----w-	C:\Users\StellaG\AppData\Local\{708948A3-D639-479A-A982-042555B71D20}<br />
2012-01-07 22:01:26	--------	d-----w-	C:\Users\StellaG\AppData\Local\{77C6841B-8470-4249-936B-B8D7E0A145A4}<br />
2012-01-07 22:01:11	--------	d-----w-	C:\Users\StellaG\AppData\Local\{E836EF51-0851-47ED-944A-F9AC0095F36D}<br />
2012-01-07 07:45:37	--------	d-----w-	C:\Users\StellaG\AppData\Local\{2D615850-2ADD-45E1-AA01-FA3693AE1F9D}<br />
2012-01-07 07:32:25	--------	d-----w-	C:\Users\StellaG\AppData\Local\{4B9FE473-BC5B-4AD7-8F2D-48ADB0E7E830}<br />
2012-01-07 07:32:15	--------	d-----w-	C:\Users\StellaG\AppData\Local\{84361391-33A2-42E7-A52F-78AB389FDF4F}<br />
2012-01-07 07:31:58	--------	d-----w-	C:\Users\StellaG\Tracing<br />
2012-01-07 06:14:32	--------	d-----w-	C:\Windows\PCHEALTH<br />
2012-01-07 06:10:00	6260088	----a-w-	C:\Program Files (x86)\Common Files\Windows Live\.cache\fbfedced1cccd0203\Silverlight.4.0.exe<br />
2012-01-07 06:09:02	--------	d-----w-	C:\Users\StellaG\AppData\Local\Windows Live<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2011-12-04 20:21:33	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2011-11-24 05:00:47	3141632	----a-w-	C:\Windows\System32\win32k.sys<br />
2011-11-24 01:59:28	0	----a-w-	C:\Windows\SysWow64\sho2B7D.tmp<br />
2011-11-17 07:17:03	152432	----a-w-	C:\Windows\System32\drivers\ksecpkg.sys<br />
2011-11-17 07:17:02	95088	----a-w-	C:\Windows\System32\drivers\ksecdd.sys<br />
2011-11-17 07:15:08	460296	----a-w-	C:\Windows\System32\drivers\cng.sys<br />
2011-11-17 07:12:02	395776	----a-w-	C:\Windows\System32\webio.dll<br />
2011-11-17 07:11:33	28672	----a-w-	C:\Windows\System32\sspisrv.dll<br />
2011-11-17 07:11:33	136192	----a-w-	C:\Windows\System32\sspicli.dll<br />
2011-11-17 07:11:02	28160	----a-w-	C:\Windows\System32\secur32.dll<br />
2011-11-17 07:08:18	1446912	----a-w-	C:\Windows\System32\lsasrv.dll<br />
2011-11-17 07:05:16	31232	----a-w-	C:\Windows\System32\lsass.exe<br />
2011-11-17 05:39:28	314368	----a-w-	C:\Windows\SysWow64\webio.dll<br />
2011-11-17 05:39:21	224768	----a-w-	C:\Windows\SysWow64\schannel.dll<br />
2011-11-17 05:39:21	22016	----a-w-	C:\Windows\SysWow64\secur32.dll<br />
2011-11-17 05:35:13	96768	----a-w-	C:\Windows\SysWow64\sspicli.dll<br />
.<br />
============= FINISH: 22:05:59.31 ===============.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume2<br />
Install Date: 11/16/2010 5:44:30 PM<br />
System Uptime: 2/3/2012 12:30:13 AM (46 hours ago)<br />
.<br />
Motherboard: Dell Inc. |  | 0G939P<br />
Processor: Intel&reg; Core&#153; i5 CPU       M 460  @ 2.53GHz | U2E1 | 2508/133mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 283 GiB total, 134.51 GiB free.<br />
D: is CDROM (CDFS)<br />
E: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP116: 1/15/2012 3:00:38 AM - Windows Update<br />
RP117: 1/22/2012 11:26:28 AM - Scheduled Checkpoint<br />
RP118: 1/24/2012 3:01:06 AM - Windows Update<br />
.<br />
==== Installed Programs ======================<br />
.<br />
.<br />
 Leawo Video2FLV Converter version  4.0.0.0<br />
Accelerometer<br />
Adobe Acrobat 5.0<br />
Adobe After Effects CS4<br />
Adobe After Effects CS4 Presets<br />
Adobe After Effects CS4 Template Projects &amp; Footage<br />
Adobe After Effects CS4 Third Party Content<br />
Adobe AIR<br />
Adobe Anchor Service CS4<br />
Adobe Bridge CS4<br />
Adobe CMaps CS4<br />
Adobe Color - Photoshop Specific CS4<br />
Adobe Color EU Extra Settings CS4<br />
Adobe Color JA Extra Settings CS4<br />
Adobe Color NA Recommended Settings CS4<br />
Adobe Color Video Profiles AE CS4<br />
Adobe Color Video Profiles CS CS4<br />
Adobe Creative Suite 4 Production Premium<br />
Adobe CS4 American English Speech Analysis Models<br />
Adobe CS4 French Speech Analysis Models<br />
Adobe CS4 German Speech Analysis Models<br />
Adobe CS4 International English Speech Analysis Models<br />
Adobe CS4 Italian Speech Analysis Models<br />
Adobe CS4 Japanese Speech Analysis Models<br />
Adobe CS4 Korean Speech Analysis Models<br />
Adobe CS4 Spanish Speech Analysis Models<br />
Adobe CSI CS4<br />
Adobe Default Language CS4<br />
Adobe Device Central CS4<br />
Adobe Drive CS4<br />
Adobe Dynamiclink Support<br />
Adobe Encore CS4<br />
Adobe Encore CS4 Codecs<br />
Adobe Encore CS4 Library<br />
Adobe ExtendScript Toolkit CS4<br />
Adobe Extension Manager CS4<br />
Adobe Flash CS4<br />
Adobe Flash CS4 Extension - Flash Lite STI en<br />
Adobe Flash CS4 STI-en<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Fonts All<br />
Adobe Illustrator CS4<br />
Adobe Linguistics CS4<br />
Adobe Media Encoder CS4<br />
Adobe Media Encoder CS4 Additional Exporter<br />
Adobe Media Encoder CS4 Dolby<br />
Adobe Media Encoder CS4 Exporter<br />
Adobe Media Encoder CS4 Importer<br />
Adobe Media Player<br />
Adobe MotionPicture Color Files CS4<br />
Adobe OnLocation CS4<br />
Adobe Output Module<br />
Adobe PDF Library Files CS4<br />
Adobe Photoshop CS4<br />
Adobe Photoshop CS4 Support<br />
Adobe Premiere Pro CS4<br />
Adobe Premiere Pro CS4 Functional Content<br />
Adobe Premiere Pro CS4 Third Party Content<br />
Adobe Reader X (10.0.1)<br />
Adobe Search for Help<br />
Adobe Service Manager Extension<br />
Adobe Setup<br />
Adobe Shockwave Player 11.6<br />
Adobe Soundbooth CS4<br />
Adobe Soundbooth CS4 Codecs<br />
Adobe Type Support CS4<br />
Adobe Update Manager CS4<br />
Adobe Version Cue CS4 Server<br />
Adobe WinSoft Linguistics Plugin<br />
Adobe XMP Panels CS4<br />
AdobeColorCommonSetCMYK<br />
AdobeColorCommonSetRGB<br />
Advanced Audio FX Engine<br />
Apple Application Support<br />
Apple Software Update<br />
BlueJ 3.0.5<br />
BYOB<br />
Canon Easy-PhotoPrint EX<br />
Canon Easy-WebPrint EX<br />
Canon IJ Network Scan Utility<br />
Canon IJ Network Tool<br />
Canon Inkjet Printer/Scanner/Fax Extended Survey Program<br />
Canon MG5200 series User Registration<br />
Canon MP Navigator EX 4.0<br />
Canon My Printer<br />
Canon Solution Menu EX<br />
Connect<br />
Cozi<br />
D3DX10<br />
Dell DataSafe Local Backup<br />
Dell DataSafe Local Backup - Support Software<br />
Dell DataSafe Online<br />
Dell Dock<br />
Dell Getting Started Guide<br />
Dell Webcam Central<br />
Freecorder 4<br />
Google Chrome<br />
Google Chrome Canary<br />
Google Talk (remove only)<br />
Google Talk Plugin<br />
Google Toolbar for Internet Explorer<br />
Google Update Helper<br />
GoToAssist 8.0.0.514<br />
Intel&reg; Control Center<br />
Intel&reg; Graphics Media Accelerator Driver<br />
Intel&reg; Management Engine Components<br />
Intel&reg; Rapid Storage Technology<br />
Internet Explorer<br />
Java Auto Updater<br />
Java&#153; 6 Update 20<br />
Java&#153; 7 Update 1<br />
Java&#153; SE Development Kit 7<br />
kuler<br />
Live! Cam Avatar Creator<br />
LiveUpdate 3.3 (Symantec Corporation)<br />
McAfee Security Scan Plus<br />
Microsoft Office 2010<br />
Microsoft Office Click-to-Run 2010<br />
Microsoft Office Starter 2010 - English<br />
Microsoft Silverlight<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Microsoft Visual C++ Run Time  Lib Setup<br />
Mozilla Firefox 4.0.1 (x86 en-US)<br />
MSVCRT<br />
MSVCRT Redists<br />
OpenOffice.org 3.2<br />
Pando Media Booster<br />
PDF Settings CS4<br />
Pen Tablet<br />
Photoshop Camera Raw<br />
Pixel Bender Toolkit<br />
Pokemon Online 1.0.00<br />
QuickTime<br />
RealNetworks - Microsoft Visual C++ 2008 Runtime<br />
RealPlayer<br />
RealUpgrade 1.1<br />
Rosetta Stone Ltd Services<br />
Rosetta Stone TOTALe<br />
Roxio Burn<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Skype Click to Call<br />
Skype? 5.5<br />
Starry??Sky?`in Spring?`<br />
Suite Shared Configuration CS4<br />
swMSM<br />
TeamSpeak 3 Client<br />
The KMPlayer (remove only)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Vegas Pro 10.0<br />
VirtualCloneDrive<br />
WebTablet IE Plugin<br />
WebTablet Netscape Plugin<br />
WildTangent Games<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Installer<br />
Windows Live Messenger<br />
Windows Live Photo Common<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live Sync<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
WinRAR archiver<br />
Youtube Downloader HD v. 2.8<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
2/4/2012 4:22:50 PM, Error: Service Control Manager [7031&#93;  - The Symantec Endpoint Protection service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.<br />
2/4/2012 12:55:07 PM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TouchServicePen service.<br />
2/4/2012 12:08:40 PM, Error: NetBT [4321&#93;  - The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.128. The computer with the IP address 192.168.1.143 did not allow the name to be claimed by this computer.<br />
2/4/2012 10:56:17 AM, Error: BROWSER [8020&#93;  - The browser was unable to promote itself to master browser.  The computer that currently believes it is the master browser is unknown.<br />
2/4/2012 10:42:55 AM, Error: Service Control Manager [7009&#93;  - A timeout was reached (30000 milliseconds) while waiting for the Windows Modules Installer service to connect.<br />
2/4/2012 10:42:55 AM, Error: Service Control Manager [7000&#93;  - The Windows Modules Installer service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
2/4/2012 10:42:55 AM, Error: Microsoft-Windows-DistributedCOM [10005&#93;  - DCOM got error "1053" attempting to start the service TrustedInstaller with arguments "" in order to run the server: {752073A1-23F2-4396-85F0-8FDB879ED0ED}<br />
2/4/2012 10:01:52 PM, Error: NetBT [4321&#93;  - The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.128. The computer with the IP address 192.168.1.138 did not allow the name to be claimed by this computer.<br />
2/3/2012 5:11:19 PM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.<br />
2/3/2012 10:31:22 PM, Error: Service Control Manager [7031&#93;  - The Symantec Endpoint Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.<br />
1/31/2012 8:15:56 PM, Error: BROWSER [8019&#93;  - The browser was unable to promote itself to master browser.  The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer.<br />
1/31/2012 6:12:06 PM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrustedInstaller service.<br />
1/31/2012 3:39:39 AM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.<br />
1/31/2012 3:39:39 AM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.<br />
1/29/2012 5:07:09 PM, Error: BROWSER [8009&#93;  - The browser was unable to promote itself to master browser.  The computer that currently believes it is the master browser is STELLAPC.<br />
1/29/2012 4:54:12 PM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MMCSS service.<br />
1/29/2012 4:54:12 PM, Error: Service Control Manager [7000&#93;  - The Multimedia Class Scheduler service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
1/29/2012 4:52:20 PM, Error: Service Control Manager [7011&#93;  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service.<br />
1/29/2012 4:49:55 PM, Error: Service Control Manager [7022&#93;  - The Windows Update service hung on starting.<br />
1/29/2012 4:47:55 PM, Error: Service Control Manager [7022&#93;  - The Security Center service hung on starting.<br />
1/29/2012 4:45:54 PM, Error: Service Control Manager [7022&#93;  - The Windows Defender service hung on starting.<br />
1/29/2012 4:40:17 PM, Error: VDS Basic Provider [1&#93;  - Unexpected failure. Error code: 490@01010004<br />
1/28/2012 10:59:23 AM, Error: BROWSER [8009&#93;  - The browser was unable to promote itself to master browser.  The computer that currently believes it is the master browser is CARLOS-PC.<br />
.<br />
==== End Of File ===========================]]></description>
			<content:encoded><![CDATA[My daughter's computer has been infected with trojan.gen.2  Symantec quarantines it but it seems to come back. Detection results lists a bunch of files called DWHC8CF.tmp, DWHF77F.tmp, etc. ad ad nauseum.<br />
<br />
I did the DDS and Attach as suggested in a noob instruction post:<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7600.16385  BrowserJavaVersion: 10.1.0<br />
Run by StellaG at 22:04:41 on 2012-02-04<br />
Microsoft Windows 7 Home Premium   6.1.7600.0.932.81.1033.18.3893.1898 [GMT -8:00]<br />
.<br />
AV: Symantec Endpoint Protection *Enabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}<br />
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
SP: Symantec Endpoint Protection *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}<br />
FW: Symantec Endpoint Protection *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\STacSV64.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Program Files\Dell\DellDock\DockLogin.exe<br />
C:\Program Files\Tablet\Pen\Pen_TouchService.exe<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\SYSTEM32\WISPTIS.EXE<br />
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files (x86)\Bonjour\mDNSResponder.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE<br />
C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe<br />
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Windows\system32\Pen_Tablet.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SmcGui.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE<br />
C:\Windows\System32\rundll32.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe<br />
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\IDT\WDM\sttray64.exe<br />
C:\Program Files\Dell\QuickSet\quickset.exe<br />
C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE<br />
C:\Windows\System32\igfxtray.exe<br />
C:\Windows\System32\hkcmd.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Windows\System32\igfxpers.exe<br />
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Users\StellaG\AppData\Roaming\Google\Google Talk\googletalk.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br />
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe<br />
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe<br />
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe<br />
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe<br />
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE<br />
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin<br />
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe<br />
C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe<br />
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\Freecorder\FLVSrvc.exe<br />
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe<br />
C:\Windows\splwow64.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe<br />
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe<br />
C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe<br />
C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe<br />
c:\program files (x86)\real\realplayer\RealPlay.exe<br />
c:\program files (x86)\real\realplayer\RealPlay.exe<br />
c:\program files (x86)\real\realplayer\RealPlay.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.google.com/<br />
uInternet Settings,ProxyOverride = *.local<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br />
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File<br />
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll<br />
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
uRun: [Google Update] "C:\Users\StellaG\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
uRun: [AdobeBridge] <br />
uRun: [googletalk] C:\Users\StellaG\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart<br />
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background<br />
uRunOnce: [Application Restart #1] C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe "C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe" <br />
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br />
mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m<br />
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2<br />
mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"<br />
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon<br />
mRun: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe<br />
mRun: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"<br />
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"<br />
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin<br />
mRun: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
mRun: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run<br />
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br />
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s<br />
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot<br />
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"<br />
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe<br />
mRunOnce: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"<br />
mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe<br />
StartupFolder: C:\Users\StellaG\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELL&#8203;DO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe<br />
StartupFolder: C:\Users\StellaG\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPEN&#8203;OF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab<br />
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E} : DhcpNameServer = 75.75.75.75 75.75.76.76<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\141427F6E6 : DhcpNameServer = 68.87.76.182 68.87.78.134<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\2375942554333373 : DhcpNameServer = 192.168.1.254<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\2456C6B696E6E253337393 : DhcpNameServer = 10.0.1.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\27567696E616 : DhcpNameServer = 192.168.1.254 192.168.0.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\27567696E616D27657563747 : DhcpNameServer = 192.168.1.254 192.168.33.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\34C61637379636A41636B616373723 : DhcpNameServer = 10.0.0.1<br />
TCP: Interfaces\{C2601D18-B00F-4564-82F5-EDA301AF3D0E}\34C61637379636A41636B616373723D25374 : DhcpNameServer = 10.0.0.1<br />
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br />
BHO-X64: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll<br />
BHO-X64:     Canon Easy-WebPrint EX BHO - No File<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO-X64:     SkypeIEPluginBHO - No File<br />
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO-X64: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB-X64: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll<br />
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File<br />
EB-X64: {21347690-EC41-4F9A-8887-1F4AEE672439} - No File<br />
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br />
mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m<br />
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2<br />
mRun-x64: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"<br />
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun-x64: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon<br />
mRun-x64: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe<br />
mRun-x64: [ccApp] "C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe"<br />
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"<br />
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun-x64: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin<br />
mRun-x64: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE<br />
mRun-x64: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run<br />
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br />
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s<br />
mRun-x64: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot<br />
mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"<br />
mRunOnce-x64: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe<br />
mRunOnce-x64: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"<br />
mRunOnce-x64: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\StellaG\AppData\Roaming\Mozilla\Firefox\Profiles\pop7e21c.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL<br />
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll<br />
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll<br />
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll<br />
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrow&#8203;serrecordext.dll<br />
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5video&#8203;shim.dll<br />
FF - plugin: C:\Users\StellaG\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll<br />
FF - plugin: C:\Users\StellaG\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll<br />
FF - plugin: C:\Users\StellaG\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --&gt; C:\Windows\system32\Drivers\PxHlpa64.sys [?]<br />
R0 stdflt;Disk Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdflt.sys --&gt; C:\Windows\system32\DRIVERS\stdflt.sys [?]<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --&gt; C:\Windows\system32\DRIVERS\vwififlt.sys [?]<br />
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_0057cbec48a2d7cf\AESTSr64.exe [2010-9-21 89600]<br />
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]<br />
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]<br />
R2 IAStorDataMgrSvc;Intel&reg; Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-9 13336]<br />
R2 InstallFilterService;FF Install Filter Service;C:\Program Files (x86)\STMicroelectronics\Accelerometer\InstallFilterService.exe [2010-11-9 60928]<br />
R2 rimspci;rimspci;C:\Windows\system32\DRIVERS\rimspe64.sys --&gt; C:\Windows\system32\DRIVERS\rimspe64.sys [?]<br />
R2 risdpcie;risdpcie;C:\Windows\system32\DRIVERS\risdpe64.sys --&gt; C:\Windows\system32\DRIVERS\risdpe64.sys [?]<br />
R2 rixdpcie;rixdpcie;C:\Windows\system32\DRIVERS\rixdpe64.sys --&gt; C:\Windows\system32\DRIVERS\rixdpe64.sys [?]<br />
R2 RosettaStoneDaemon;RosettaStoneDaemon;C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2011-3-31 1646056]<br />
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]<br />
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-11-9 689472]<br />
R2 Symantec AntiVirus;Symantec Endpoint Protection;C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2010-6-30 1831024]<br />
R2 TabletServicePen;TabletServicePen;C:\Windows\system32\Pen_Tablet.exe --&gt; C:\Windows\system32\Pen_Tablet.exe [?]<br />
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2011-11-4 719216]<br />
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --&gt; C:\Windows\system32\DRIVERS\TurboB.sys [?]<br />
R2 UNS;Intel&reg; Management &amp; Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe [2010-11-9 2320920]<br />
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Acceler.sys --&gt; C:\Windows\system32\DRIVERS\Acceler.sys [?]<br />
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --&gt; C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]<br />
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-12 138360]<br />
R3 HECIx64;Intel&reg; Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?]<br />
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --&gt; C:\Windows\system32\DRIVERS\Impcd.sys [?]<br />
R3 IntcDAud;Intel&reg; Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --&gt; C:\Windows\system32\DRIVERS\IntcDAud.sys [?]<br />
R3 NETw5s64;Intel&reg; Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys --&gt; C:\Windows\system32\DRIVERS\NETw5s64.sys [?]<br />
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2010-7-30 25072]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --&gt; C:\Windows\system32\DRIVERS\Rt64win7.sys [?]<br />
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --&gt; C:\Windows\system32\DRIVERS\Sftfslh.sys [?]<br />
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --&gt; C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]<br />
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --&gt; C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]<br />
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --&gt; C:\Windows\system32\DRIVERS\Sftvollh.sys [?]<br />
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --&gt; C:\Windows\system32\DRIVERS\vwifimp.sys [?]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16 136176]<br />
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-8-15 284016]<br />
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-4-30 1038088]<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-16 136176]<br />
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2009-9-21 315664]<br />
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]<br />
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?]<br />
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --&gt; C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-30 00:42:38	--------	d-----w-	C:\Users\StellaG\AppData\Local\{67D643B0-BF5B-4FE8-89CC-37D702BF016D}<br />
2012-01-30 00:42:27	--------	d-----w-	C:\Users\StellaG\AppData\Local\{FF31DEAF-4D20-4BCB-B4DC-4CBCE1882787}<br />
2012-01-30 00:22:14	--------	d-----w-	C:\WTablet<br />
2012-01-27 03:39:56	--------	d-----w-	C:\Users\StellaG\AppData\Local\{599366BB-7860-4530-B141-E42A9DD1ECAE}<br />
2012-01-27 03:39:46	--------	d-----w-	C:\Users\StellaG\AppData\Local\{337BBA0C-BC62-43CE-830E-B62AD3402548}<br />
2012-01-25 22:39:28	--------	d-----w-	C:\Users\StellaG\AppData\Local\{3B9D106C-9B53-4939-AD3C-F3827CFFDC03}<br />
2012-01-25 22:38:56	--------	d-----w-	C:\Users\StellaG\AppData\Local\{298A80CF-877C-4615-AC67-63F6E021B0BC}<br />
2012-01-25 02:11:29	--------	d-----w-	C:\Users\StellaG\AppData\Local\{802EC0F5-681C-43DB-A528-40568D12A5FF}<br />
2012-01-25 02:10:53	--------	d-----w-	C:\Users\StellaG\AppData\Local\{15FC1B1E-D0DF-4284-A42E-EAE15361CDC1}<br />
2012-01-23 23:28:29	--------	d-----w-	C:\Users\StellaG\AppData\Local\{1372B089-E7F9-4322-A5EB-A9291CBB6B0B}<br />
2012-01-23 06:46:48	--------	d-----w-	C:\Users\StellaG\AppData\Local\{D30588A1-EDD2-404B-93F5-7CC2281F4774}<br />
2012-01-22 18:46:34	--------	d-----w-	C:\Users\StellaG\AppData\Local\{893C90FB-07B2-4492-87A9-7490616F904D}<br />
2012-01-22 03:21:22	--------	d-----w-	C:\Users\StellaG\AppData\Local\{489B7082-CCED-415C-887C-EED4C31B547B}<br />
2012-01-22 03:21:11	--------	d-----w-	C:\Users\StellaG\AppData\Local\{3241C915-7593-4A35-BC4A-FF6D1EFC5AE6}<br />
2012-01-19 02:11:28	--------	d-----w-	C:\Users\StellaG\AppData\Local\{4C30E72D-2F37-473F-A3CD-15F58FC56277}<br />
2012-01-19 02:11:17	--------	d-----w-	C:\Users\StellaG\AppData\Local\{E95156D7-C077-43B4-BC38-E78FEAE7345B}<br />
2012-01-18 04:06:38	--------	d-----w-	C:\Users\StellaG\AppData\Local\{C204D1D2-BD17-4695-8365-2D101AB8888D}<br />
2012-01-17 02:03:49	--------	d-----w-	C:\Users\StellaG\AppData\Local\{38CCF4D8-CB02-4572-A040-D45EE4F17DAF}<br />
2012-01-17 02:03:39	--------	d-----w-	C:\Users\StellaG\AppData\Local\{EAEA7421-7342-481B-851C-73EFCED312BA}<br />
2012-01-15 20:18:17	--------	d-----w-	C:\Users\StellaG\AppData\Local\{B4D493C1-2FDA-4C58-822B-44C4804B14B7}<br />
2012-01-15 20:17:51	--------	d-----w-	C:\Users\StellaG\AppData\Local\{461BD313-8BCD-4762-ACB7-D0A25C879D47}<br />
2012-01-15 07:56:01	340992	----a-w-	C:\Windows\System32\schannel.dll<br />
2012-01-14 19:38:31	--------	d-----w-	C:\Users\StellaG\AppData\Local\{5F33D80C-AA61-4F48-8711-2C06ACEFD46F}<br />
2012-01-14 02:28:59	--------	d-----w-	C:\Users\StellaG\AppData\Local\{64CAAF06-E526-44EA-8A6F-7B484A732F1D}<br />
2012-01-14 02:28:48	--------	d-----w-	C:\Users\StellaG\AppData\Local\{FA124A86-087A-4F0B-B9A2-646F655A4A71}<br />
2012-01-14 02:28:08	--------	d-----w-	C:\Users\StellaG\AppData\Local\{387B6821-4CF7-4B4B-95F1-7CE43DAF1B10}<br />
2012-01-14 02:28:07	--------	d-----w-	C:\Users\StellaG\AppData\Local\{BE180405-C07F-419A-B0A7-3A9A35DDAC97}<br />
2012-01-12 23:29:22	--------	d-----w-	C:\Users\StellaG\AppData\Local\{9F24F10D-8A24-48A2-BE4E-8FC6F56C463F}<br />
2012-01-12 23:28:56	--------	d-----w-	C:\Users\StellaG\AppData\Local\{D412E0A9-FBF1-4CD0-B4EC-B452FFC268DC}<br />
2012-01-11 22:48:25	1328640	----a-w-	C:\Windows\SysWow64\quartz.dll<br />
2012-01-11 22:48:21	1572864	----a-w-	C:\Windows\System32\quartz.dll<br />
2012-01-11 22:48:18	514560	----a-w-	C:\Windows\SysWow64\qdvd.dll<br />
2012-01-11 22:48:17	366592	----a-w-	C:\Windows\System32\qdvd.dll<br />
2012-01-11 22:47:56	1739160	----a-w-	C:\Windows\System32\ntdll.dll<br />
2012-01-11 22:47:53	1292592	----a-w-	C:\Windows\SysWow64\ntdll.dll<br />
2012-01-11 22:47:49	77312	----a-w-	C:\Windows\System32\packager.dll<br />
2012-01-11 22:47:48	67072	----a-w-	C:\Windows\SysWow64\packager.dll<br />
2012-01-10 02:30:44	--------	d-----w-	C:\Users\StellaG\AppData\Local\{4AB0EE59-E981-47AC-9731-B2051C69CE96}<br />
2012-01-10 02:30:32	--------	d-----w-	C:\Users\StellaG\AppData\Local\{81053FE3-2B39-47D7-A15B-166B6C828BD0}<br />
2012-01-09 05:17:28	--------	d-----w-	C:\Users\StellaG\AppData\Local\{39B8E3EA-F85A-401E-9927-D954163E3741}<br />
2012-01-09 05:17:09	--------	d-----w-	C:\Users\StellaG\AppData\Local\{708948A3-D639-479A-A982-042555B71D20}<br />
2012-01-07 22:01:26	--------	d-----w-	C:\Users\StellaG\AppData\Local\{77C6841B-8470-4249-936B-B8D7E0A145A4}<br />
2012-01-07 22:01:11	--------	d-----w-	C:\Users\StellaG\AppData\Local\{E836EF51-0851-47ED-944A-F9AC0095F36D}<br />
2012-01-07 07:45:37	--------	d-----w-	C:\Users\StellaG\AppData\Local\{2D615850-2ADD-45E1-AA01-FA3693AE1F9D}<br />
2012-01-07 07:32:25	--------	d-----w-	C:\Users\StellaG\AppData\Local\{4B9FE473-BC5B-4AD7-8F2D-48ADB0E7E830}<br />
2012-01-07 07:32:15	--------	d-----w-	C:\Users\StellaG\AppData\Local\{84361391-33A2-42E7-A52F-78AB389FDF4F}<br />
2012-01-07 07:31:58	--------	d-----w-	C:\Users\StellaG\Tracing<br />
2012-01-07 06:14:32	--------	d-----w-	C:\Windows\PCHEALTH<br />
2012-01-07 06:10:00	6260088	----a-w-	C:\Program Files (x86)\Common Files\Windows Live\.cache\fbfedced1cccd0203\Silverlight.4.0.exe<br />
2012-01-07 06:09:02	--------	d-----w-	C:\Users\StellaG\AppData\Local\Windows Live<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2011-12-04 20:21:33	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2011-11-24 05:00:47	3141632	----a-w-	C:\Windows\System32\win32k.sys<br />
2011-11-24 01:59:28	0	----a-w-	C:\Windows\SysWow64\sho2B7D.tmp<br />
2011-11-17 07:17:03	152432	----a-w-	C:\Windows\System32\drivers\ksecpkg.sys<br />
2011-11-17 07:17:02	95088	----a-w-	C:\Windows\System32\drivers\ksecdd.sys<br />
2011-11-17 07:15:08	460296	----a-w-	C:\Windows\System32\drivers\cng.sys<br />
2011-11-17 07:12:02	395776	----a-w-	C:\Windows\System32\webio.dll<br />
2011-11-17 07:11:33	28672	----a-w-	C:\Windows\System32\sspisrv.dll<br />
2011-11-17 07:11:33	136192	----a-w-	C:\Windows\System32\sspicli.dll<br />
2011-11-17 07:11:02	28160	----a-w-	C:\Windows\System32\secur32.dll<br />
2011-11-17 07:08:18	1446912	----a-w-	C:\Windows\System32\lsasrv.dll<br />
2011-11-17 07:05:16	31232	----a-w-	C:\Windows\System32\lsass.exe<br />
2011-11-17 05:39:28	314368	----a-w-	C:\Windows\SysWow64\webio.dll<br />
2011-11-17 05:39:21	224768	----a-w-	C:\Windows\SysWow64\schannel.dll<br />
2011-11-17 05:39:21	22016	----a-w-	C:\Windows\SysWow64\secur32.dll<br />
2011-11-17 05:35:13	96768	----a-w-	C:\Windows\SysWow64\sspicli.dll<br />
.<br />
============= FINISH: 22:05:59.31 ===============.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume2<br />
Install Date: 11/16/2010 5:44:30 PM<br />
System Uptime: 2/3/2012 12:30:13 AM (46 hours ago)<br />
.<br />
Motherboard: Dell Inc. |  | 0G939P<br />
Processor: Intel&reg; Core&#153; i5 CPU       M 460  @ 2.53GHz | U2E1 | 2508/133mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 283 GiB total, 134.51 GiB free.<br />
D: is CDROM (CDFS)<br />
E: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP116: 1/15/2012 3:00:38 AM - Windows Update<br />
RP117: 1/22/2012 11:26:28 AM - Scheduled Checkpoint<br />
RP118: 1/24/2012 3:01:06 AM - Windows Update<br />
.<br />
==== Installed Programs ======================<br />
.<br />
.<br />
 Leawo Video2FLV Converter version  4.0.0.0<br />
Accelerometer<br />
Adobe Acrobat 5.0<br />
Adobe After Effects CS4<br />
Adobe After Effects CS4 Presets<br />
Adobe After Effects CS4 Template Projects &amp; Footage<br />
Adobe After Effects CS4 Third Party Content<br />
Adobe AIR<br />
Adobe Anchor Service CS4<br />
Adobe Bridge CS4<br />
Adobe CMaps CS4<br />
Adobe Color - Photoshop Specific CS4<br />
Adobe Color EU Extra Settings CS4<br />
Adobe Color JA Extra Settings CS4<br />
Adobe Color NA Recommended Settings CS4<br />
Adobe Color Video Profiles AE CS4<br />
Adobe Color Video Profiles CS CS4<br />
Adobe Creative Suite 4 Production Premium<br />
Adobe CS4 American English Speech Analysis Models<br />
Adobe CS4 French Speech Analysis Models<br />
Adobe CS4 German Speech Analysis Models<br />
Adobe CS4 International English Speech Analysis Models<br />
Adobe CS4 Italian Speech Analysis Models<br />
Adobe CS4 Japanese Speech Analysis Models<br />
Adobe CS4 Korean Speech Analysis Models<br />
Adobe CS4 Spanish Speech Analysis Models<br />
Adobe CSI CS4<br />
Adobe Default Language CS4<br />
Adobe Device Central CS4<br />
Adobe Drive CS4<br />
Adobe Dynamiclink Support<br />
Adobe Encore CS4<br />
Adobe Encore CS4 Codecs<br />
Adobe Encore CS4 Library<br />
Adobe ExtendScript Toolkit CS4<br />
Adobe Extension Manager CS4<br />
Adobe Flash CS4<br />
Adobe Flash CS4 Extension - Flash Lite STI en<br />
Adobe Flash CS4 STI-en<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Fonts All<br />
Adobe Illustrator CS4<br />
Adobe Linguistics CS4<br />
Adobe Media Encoder CS4<br />
Adobe Media Encoder CS4 Additional Exporter<br />
Adobe Media Encoder CS4 Dolby<br />
Adobe Media Encoder CS4 Exporter<br />
Adobe Media Encoder CS4 Importer<br />
Adobe Media Player<br />
Adobe MotionPicture Color Files CS4<br />
Adobe OnLocation CS4<br />
Adobe Output Module<br />
Adobe PDF Library Files CS4<br />
Adobe Photoshop CS4<br />
Adobe Photoshop CS4 Support<br />
Adobe Premiere Pro CS4<br />
Adobe Premiere Pro CS4 Functional Content<br />
Adobe Premiere Pro CS4 Third Party Content<br />
Adobe Reader X (10.0.1)<br />
Adobe Search for Help<br />
Adobe Service Manager Extension<br />
Adobe Setup<br />
Adobe Shockwave Player 11.6<br />
Adobe Soundbooth CS4<br />
Adobe Soundbooth CS4 Codecs<br />
Adobe Type Support CS4<br />
Adobe Update Manager CS4<br />
Adobe Version Cue CS4 Server<br />
Adobe WinSoft Linguistics Plugin<br />
Adobe XMP Panels CS4<br />
AdobeColorCommonSetCMYK<br />
AdobeColorCommonSetRGB<br />
Advanced Audio FX Engine<br />
Apple Application Support<br />
Apple Software Update<br />
BlueJ 3.0.5<br />
BYOB<br />
Canon Easy-PhotoPrint EX<br />
Canon Easy-WebPrint EX<br />
Canon IJ Network Scan Utility<br />
Canon IJ Network Tool<br />
Canon Inkjet Printer/Scanner/Fax Extended Survey Program<br />
Canon MG5200 series User Registration<br />
Canon MP Navigator EX 4.0<br />
Canon My Printer<br />
Canon Solution Menu EX<br />
Connect<br />
Cozi<br />
D3DX10<br />
Dell DataSafe Local Backup<br />
Dell DataSafe Local Backup - Support Software<br />
Dell DataSafe Online<br />
Dell Dock<br />
Dell Getting Started Guide<br />
Dell Webcam Central<br />
Freecorder 4<br />
Google Chrome<br />
Google Chrome Canary<br />
Google Talk (remove only)<br />
Google Talk Plugin<br />
Google Toolbar for Internet Explorer<br />
Google Update Helper<br />
GoToAssist 8.0.0.514<br />
Intel&reg; Control Center<br />
Intel&reg; Graphics Media Accelerator Driver<br />
Intel&reg; Management Engine Components<br />
Intel&reg; Rapid Storage Technology<br />
Internet Explorer<br />
Java Auto Updater<br />
Java&#153; 6 Update 20<br />
Java&#153; 7 Update 1<br />
Java&#153; SE Development Kit 7<br />
kuler<br />
Live! Cam Avatar Creator<br />
LiveUpdate 3.3 (Symantec Corporation)<br />
McAfee Security Scan Plus<br />
Microsoft Office 2010<br />
Microsoft Office Click-to-Run 2010<br />
Microsoft Office Starter 2010 - English<br />
Microsoft Silverlight<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Microsoft Visual C++ Run Time  Lib Setup<br />
Mozilla Firefox 4.0.1 (x86 en-US)<br />
MSVCRT<br />
MSVCRT Redists<br />
OpenOffice.org 3.2<br />
Pando Media Booster<br />
PDF Settings CS4<br />
Pen Tablet<br />
Photoshop Camera Raw<br />
Pixel Bender Toolkit<br />
Pokemon Online 1.0.00<br />
QuickTime<br />
RealNetworks - Microsoft Visual C++ 2008 Runtime<br />
RealPlayer<br />
RealUpgrade 1.1<br />
Rosetta Stone Ltd Services<br />
Rosetta Stone TOTALe<br />
Roxio Burn<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Skype Click to Call<br />
Skype? 5.5<br />
Starry??Sky?`in Spring?`<br />
Suite Shared Configuration CS4<br />
swMSM<br />
TeamSpeak 3 Client<br />
The KMPlayer (remove only)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Vegas Pro 10.0<br />
VirtualCloneDrive<br />
WebTablet IE Plugin<br />
WebTablet Netscape Plugin<br />
WildTangent Games<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Installer<br />
Windows Live Messenger<br />
Windows Live Photo Common<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live Sync<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
WinRAR archiver<br />
Youtube Downloader HD v. 2.8<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
2/4/2012 4:22:50 PM, Error: Service Control Manager [7031]  - The Symantec Endpoint Protection service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.<br />
2/4/2012 12:55:07 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TouchServicePen service.<br />
2/4/2012 12:08:40 PM, Error: NetBT [4321]  - The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.128. The computer with the IP address 192.168.1.143 did not allow the name to be claimed by this computer.<br />
2/4/2012 10:56:17 AM, Error: BROWSER [8020]  - The browser was unable to promote itself to master browser.  The computer that currently believes it is the master browser is unknown.<br />
2/4/2012 10:42:55 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Modules Installer service to connect.<br />
2/4/2012 10:42:55 AM, Error: Service Control Manager [7000]  - The Windows Modules Installer service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
2/4/2012 10:42:55 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service TrustedInstaller with arguments "" in order to run the server: {752073A1-23F2-4396-85F0-8FDB879ED0ED}<br />
2/4/2012 10:01:52 PM, Error: NetBT [4321]  - The name "WORKGROUP      :1d" could not be registered on the interface with IP address 192.168.1.128. The computer with the IP address 192.168.1.138 did not allow the name to be claimed by this computer.<br />
2/3/2012 5:11:19 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.<br />
2/3/2012 10:31:22 PM, Error: Service Control Manager [7031]  - The Symantec Endpoint Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.<br />
1/31/2012 8:15:56 PM, Error: BROWSER [8019]  - The browser was unable to promote itself to master browser.  The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer.<br />
1/31/2012 6:12:06 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrustedInstaller service.<br />
1/31/2012 3:39:39 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.<br />
1/31/2012 3:39:39 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.<br />
1/29/2012 5:07:09 PM, Error: BROWSER [8009]  - The browser was unable to promote itself to master browser.  The computer that currently believes it is the master browser is STELLAPC.<br />
1/29/2012 4:54:12 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MMCSS service.<br />
1/29/2012 4:54:12 PM, Error: Service Control Manager [7000]  - The Multimedia Class Scheduler service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
1/29/2012 4:52:20 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the eventlog service.<br />
1/29/2012 4:49:55 PM, Error: Service Control Manager [7022]  - The Windows Update service hung on starting.<br />
1/29/2012 4:47:55 PM, Error: Service Control Manager [7022]  - The Security Center service hung on starting.<br />
1/29/2012 4:45:54 PM, Error: Service Control Manager [7022]  - The Windows Defender service hung on starting.<br />
1/29/2012 4:40:17 PM, Error: VDS Basic Provider [1]  - Unexpected failure. Error code: 490@01010004<br />
1/28/2012 10:59:23 AM, Error: BROWSER [8009]  - The browser was unable to promote itself to master browser.  The computer that currently believes it is the master browser is CARLOS-PC.<br />
.<br />
==== End Of File ===========================]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[infected with DOS/Alureon.A on win7]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-infected-with-dos-alureon-a-on-win7</link>
			<pubDate>Sat, 04 Feb 2012 22:48:51 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-infected-with-dos-alureon-a-on-win7</guid>
			<description><![CDATA[Hello,<br />
I have a huge problem. Yesterday my son was playing some games and the laptop rebooted itself and from that point on, I can't do anything with it. I somehow managed to run a scan with MSE and it showed me that my laptop is infected with DOS/Alureon.A however, when I click to remove it, it says it did, but the problem is still there and additional scans show it's still there. I can't run any other anti virus program (ad-aware, malwarebytes) to help me remove it. Moreover, I can't run ANY .exe files on that laptop except for MSE and somehow Hitman Pro. I managed to scan the laptop with HitMan and I got this:<br />
<br />
Master Boot Record (Sector 0) Rootkit<br />
Rootkit. MBR.Pihar.D (Boot Image) (Engine A)<br />
Trojan.Tdlphaze.1<br />
Rootkit.Win32.Pihar!IK<br />
Win64/Bootkit<br />
<br />
From what I managed to find I know that Alureon rewrote my MBR.<br />
I've tried Safe Mode, Safe Mode with Networking, and nothing helps. For the life of me I can't run any .exe files (programs). I even tried to rename them and changing them to .com but still NOTHING. Can't even use Win Recovery Disc. It does not load. Can't even use internet<br />
I'm just lost. All info I found involves installing some programs, which are not an option to me (can't run them). Please help! Any help will be very appreciated.<br />
<br />
I'm on win7 64 bit<br />
<br />
Please forgive me if I posted in the wrong section, first time posting!<br />
<br />
Konrad]]></description>
			<content:encoded><![CDATA[Hello,<br />
I have a huge problem. Yesterday my son was playing some games and the laptop rebooted itself and from that point on, I can't do anything with it. I somehow managed to run a scan with MSE and it showed me that my laptop is infected with DOS/Alureon.A however, when I click to remove it, it says it did, but the problem is still there and additional scans show it's still there. I can't run any other anti virus program (ad-aware, malwarebytes) to help me remove it. Moreover, I can't run ANY .exe files on that laptop except for MSE and somehow Hitman Pro. I managed to scan the laptop with HitMan and I got this:<br />
<br />
Master Boot Record (Sector 0) Rootkit<br />
Rootkit. MBR.Pihar.D (Boot Image) (Engine A)<br />
Trojan.Tdlphaze.1<br />
Rootkit.Win32.Pihar!IK<br />
Win64/Bootkit<br />
<br />
From what I managed to find I know that Alureon rewrote my MBR.<br />
I've tried Safe Mode, Safe Mode with Networking, and nothing helps. For the life of me I can't run any .exe files (programs). I even tried to rename them and changing them to .com but still NOTHING. Can't even use Win Recovery Disc. It does not load. Can't even use internet<br />
I'm just lost. All info I found involves installing some programs, which are not an option to me (can't run them). Please help! Any help will be very appreciated.<br />
<br />
I'm on win7 64 bit<br />
<br />
Please forgive me if I posted in the wrong section, first time posting!<br />
<br />
Konrad]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[sending mass e-mails]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-sending-mass-e-mails</link>
			<pubDate>Sun, 29 Jan 2012 01:20:04 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-sending-mass-e-mails</guid>
			<description><![CDATA[So my son picked up some sort of virus off his computer, it is sending mad amounts of e-mails to anyone and everyone he has ever e-mailed with some link to something else. I ran AVG and it found some tracking cookies but didn't seem to completely fix the issue, please help!<br />
<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.6001.19088<br />
Run by Mia at 20:17:10 on 2012-01-28<br />
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3837.1483 [GMT -5:00&#93;<br />
.<br />
AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}<br />
SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\system32\Ati2evxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8adfd0a8\STacSV64.exe<br />
C:\Windows\system32\svchost.exe -k GPSvcGroup<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\Hpservice.exe<br />
C:\Windows\system32\Ati2evxx.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe<br />
C:\Windows\system32\agr64svc.exe<br />
C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe<br />
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
C:\Windows\SMINST\BLService.exe<br />
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe<br />
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe<br />
C:\Program Files\IDT\WDM\sttray64.exe<br />
C:\Windows\System32\wpcumi.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\System32\alg.exe<br />
C:\Program Files (x86)\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files (x86)\Internet Explorer\IELowutil.exe<br />
C:\Program Files (x86)\HP\QuickPlay\QPService.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files (x86)\AVG Secure Search\vprot.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe<br />
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe<br />
C:\Windows\splwow64.exe<br />
C:\Windows\System32\vds.exe<br />
C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe<br />
C:\PROGRA~2\AVG\AVG8\avgrsa.exe<br />
C:\PROGRA~2\AVG\AVG8\avgemc.exe<br />
C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\System32\mobsync.exe<br />
C:\Users\Mia\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Mia\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\PROGRA~2\AVG\AVG8\avgnsa.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\servicing\TrustedInstaller.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uSearch Page = <br />
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb<br />
uSearch Bar = <br />
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb<br />
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb<br />
uInternet Settings,ProxyOverride = *.local<br />
uURLSearchHooks: H - No File<br />
uURLSearchHooks: H - No File<br />
mURLSearchHooks: H - No File<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: &amp;Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
BHO: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO: WebExcellenceAdviceTool: {cd1a4f51-6371-6621-312a-b4cd3941f6de} - C:\Program Files (x86)\WebExcellenceAdviceTool\WebExcellenceAdviceTool.dll<br />
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
TB: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
TB: &amp;Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File<br />
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File<br />
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}<br />
uRun: [LightScribe Control Panel&#93; C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
uRun: [ehTray.exe&#93; C:\Windows\ehome\ehTray.exe<br />
uRun: [msnmsgr&#93; "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background<br />
uRun: [ComcastAntispyClient&#93; "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide<br />
uRun: [swg&#93; "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
uRun: [Steam&#93; "C:\Program Files (x86)\Steam\Steam.exe" -silent<br />
uRun: [Google Update&#93; "C:\Users\Mia\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
uRun: [Skype&#93; "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized<br />
mRun: [StartCCC&#93; "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"<br />
mRun: [UCam_Menu&#93; "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"<br />
mRun: [QPService&#93; "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"<br />
mRun: [QlbCtrl.exe&#93; "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start<br />
mRun: [hpqSRMon&#93; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
mRun: [HP Health Check Scheduler&#93; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
mRun: [hpWirelessAssistant&#93; C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
mRun: [AVG8_TRAY&#93; C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
mRun: [Adobe Reader Speed Launcher&#93; "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
mRun: [Adobe ARM&#93; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun: [Monitor&#93; "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"<br />
mRun: [SunJavaUpdateSched&#93; "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"<br />
mRun: [QuickTime Task&#93; "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun: [vProt&#93; "C:\Program Files (x86)\AVG Secure Search\vprot.exe"<br />
mRun: [APSDaemon&#93; "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"<br />
mRun: [iTunesHelper&#93; "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun: [HP Software Update&#93; C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
mRun: [<NO NAME>&#93; <br />
mRun: [ROC_roc_dec12&#93; "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
LSP: C:\Windows\system32\wpclsp.dll<br />
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab<br />
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab<br />
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Zuma/Images/stg_drm.ocx<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab<br />
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab<br />
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab<br />
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-us.cab<br />
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab<br />
DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab<br />
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab<br />
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files%20(x86)/Zuma/Images/armhelper.ocx<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
TCP: DhcpNameServer = 65.32.5.111 65.32.5.112<br />
TCP: Interfaces\{DD98F11F-AFBE-4C30-AD14-5D9C474C3AE2} : DhcpNameServer = 65.32.5.111 65.32.5.112<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\iEvony\Skype4COM.dll<br />
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll<br />
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"<br />
BHO-X64: &amp;Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
BHO-X64:     0x1 - No File<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
BHO-X64:     AskBar BHO - No File<br />
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
BHO-X64:     WormRadar.com IESiteBlocker.NavFilter - No File<br />
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
BHO-X64:     Search Helper - No File<br />
BHO-X64: Comcast Toolbar: {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
BHO-X64:     Comcast Toolbar - No File<br />
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO-X64: WebExcellenceAdviceTool: {CD1A4F51-6371-6621-312A-B4CD3941F6DE} - C:\Program Files (x86)\WebExcellenceAdviceTool\WebExcellenceAdviceTool.dll<br />
BHO-X64:     WebExcellenceAdviceTool - No File<br />
BHO-X64: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
BHO-X64: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO-X64: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
BHO-X64:     HP Smart BHO Class - No File<br />
TB-X64: MSN Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
TB-X64: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File<br />
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
TB-X64: Comcast Toolbar: {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
TB-X64: &amp;Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB-X64: {A057A204-BACC-4D26-9990-79A187E2698E} - No File<br />
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
TB-X64: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File<br />
mRun-x64: [StartCCC&#93; "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"<br />
mRun-x64: [UCam_Menu&#93; "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"<br />
mRun-x64: [QPService&#93; "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"<br />
mRun-x64: [QlbCtrl.exe&#93; "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start<br />
mRun-x64: [hpqSRMon&#93; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
mRun-x64: [HP Health Check Scheduler&#93; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
mRun-x64: [hpWirelessAssistant&#93; C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
mRun-x64: [AVG8_TRAY&#93; C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
mRun-x64: [Adobe Reader Speed Launcher&#93; "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
mRun-x64: [Adobe ARM&#93; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun-x64: [Monitor&#93; "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"<br />
mRun-x64: [SunJavaUpdateSched&#93; "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"<br />
mRun-x64: [QuickTime Task&#93; "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun-x64: [vProt&#93; "C:\Program Files (x86)\AVG Secure Search\vprot.exe"<br />
mRun-x64: [APSDaemon&#93; "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"<br />
mRun-x64: [iTunesHelper&#93; "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun-x64: [HP Software Update&#93; C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
mRun-x64: [(Default)&#93; <br />
mRun-x64: [ROC_roc_dec12&#93; "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys --&gt; C:\Windows\system32\DRIVERS\ahcix64s.sys [?&#93;<br />
R0 Amddfltr64;Amd Disk Lower Filter Driver;C:\Windows\system32\DRIVERS\Amddfltr64.sys --&gt; C:\Windows\system32\DRIVERS\Amddfltr64.sys [?&#93;<br />
R1 AvgLdx64;AVG Free AVI Loader Driver x64;C:\Windows\system32\Drivers\avgldx64.sys --&gt; C:\Windows\system32\Drivers\avgldx64.sys [?&#93;<br />
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;C:\Windows\system32\Drivers\avgmfx64.sys --&gt; C:\Windows\system32\Drivers\avgmfx64.sys [?&#93;<br />
R1 AvgTdiA;AVG8 Network Redirector;C:\Windows\system32\Drivers\avgtdia.sys --&gt; C:\Windows\system32\Drivers\avgtdia.sys [?&#93;<br />
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe --&gt; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe [?&#93;<br />
R2 AntiSpywareService;Comcast AntiSpyware;C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [2009-6-17 616408&#93;<br />
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~2\AVG\AVG8\avgemc.exe [2009-7-1 908056&#93;<br />
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe [2009-7-1 297752&#93;<br />
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --&gt; C:\Windows\system32\Hpservice.exe [?&#93;<br />
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-5-21 193840&#93;<br />
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --&gt; C:\Windows\system32\DRIVERS\enecir.sys [?&#93;<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-28 135664&#93;<br />
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG8\Toolbar\ToolbarBroker.exe [2011-11-3 167264&#93;<br />
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-21 93184&#93;<br />
S3 FlyUsb;FLY Fusion;C:\Windows\system32\DRIVERS\FlyUsb.sys --&gt; C:\Windows\system32\DRIVERS\FlyUsb.sys [?&#93;<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-28 135664&#93;<br />
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968&#93;<br />
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --&gt; C:\Windows\system32\DRIVERS\ssadbus.sys [?&#93;<br />
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --&gt; C:\Windows\system32\DRIVERS\ssadmdfl.sys [?&#93;<br />
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --&gt; C:\Windows\system32\DRIVERS\ssadmdm.sys [?&#93;<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?&#93;<br />
.<br />
=============== File Associations ===============<br />
.<br />
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-28 03:13:03	8602168	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA384536-C76E-4228-B1E4-4588BEB3F310}\mpengine.dll<br />
2012-01-09 00:24:05	--------	d-----r-	C:\Program Files (x86)\Skype<br />
2012-01-06 06:14:47	--------	d-----w-	C:\Users\Mia\AppData\Roaming\HpUpdate<br />
2012-01-06 06:14:33	--------	d-----w-	C:\Windows\Hewlett-Packard<br />
2012-01-04 15:29:40	--------	d-----w-	C:\Users\Mia\AppData\Roaming\com.Shutterfly.ExpressUploader<br />
2012-01-04 15:29:14	--------	d-----w-	C:\Program Files (x86)\Shutterfly<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2011-12-07 15:39:10	279096	------w-	C:\Windows\System32\MpSigStub.exe<br />
2011-11-17 01:33:24	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2011-11-02 21:30:13	427016	----a-w-	C:\Windows\System32\drivers\avgldx64.sys<br />
.<br />
============= FINISH: 20:18:48.93 ===============<br />
<br />
<br />
<br />
<br />
<br />
********************************************************<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft® Windows Vista™ Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 9/20/2008 5:39:11 AM<br />
System Uptime: 1/27/2012 11:03:41 PM (21 hours ago)<br />
.<br />
Motherboard: HP |  | 30F2<br />
Processor: AMD Turion&#153; X2 Dual-Core Mobile RM-70 | Socket M2/S1G1 | 500/1800mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 222 GiB total, 126.303 GiB free.<br />
D: is FIXED (NTFS) - 11 GiB total, 1.839 GiB free.<br />
E: is CDROM ()<br />
G: is Removable<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP389: 1/6/2012 9:34:42 AM - Windows Update<br />
RP390: 1/9/2012 11:42:22 PM - Scheduled Checkpoint<br />
RP391: 1/10/2012 4:48:52 PM - Windows Update<br />
RP392: 1/11/2012 8:25:22 PM - Windows Update<br />
RP393: 1/14/2012 7:17:27 PM - Windows Update<br />
RP394: 1/15/2012 7:52:20 PM - Scheduled Checkpoint<br />
RP395: 1/15/2012 8:24:45 PM - Device Driver Package Install: SAMSUNG Electronics Co., Ltd.  Universal Serial Bus controllers<br />
RP396: 1/15/2012 8:27:43 PM - Device Driver Package Install: SAMSUNG Electronics Co., Ltd.  Modems<br />
RP397: 1/17/2012 5:55:17 PM - Windows Update<br />
RP398: 1/19/2012 10:06:46 PM - Scheduled Checkpoint<br />
RP399: 1/20/2012 10:06:52 PM - Windows Update<br />
RP400: 1/23/2012 8:50:50 PM - Scheduled Checkpoint<br />
RP401: 1/24/2012 6:04:49 PM - Windows Update<br />
RP402: 1/27/2012 10:12:18 PM - Windows Update<br />
.<br />
==== Installed Programs ======================<br />
.<br />
 Update for Microsoft Office 2007 (KB2508958)<br />
Acrobat.com<br />
Activation Assistant for the 2007 Microsoft Office suites<br />
Adobe AIR<br />
Adobe Flash Player 10 Plugin<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Reader 9.2<br />
Adobe Shockwave Player 11.5<br />
Algebrator 4.0<br />
Apple Application Support<br />
Apple Software Update<br />
Ask Toolbar<br />
Atheros Driver Installation Program<br />
AVG Free 8.5<br />
CA Pest Patrol Realtime Protection<br />
Cards_Calendar_OrderGift_DoMorePlugout<br />
Catalyst Control Center - Branding<br />
Catalyst Control Center Core Implementation<br />
Catalyst Control Center Graphics Full Existing<br />
Catalyst Control Center Graphics Full New<br />
Catalyst Control Center Graphics Light<br />
Catalyst Control Center Graphics Previews Vista<br />
Catalyst Control Center Localization Chinese Standard<br />
Catalyst Control Center Localization Chinese Traditional<br />
Catalyst Control Center Localization Czech<br />
Catalyst Control Center Localization Danish<br />
Catalyst Control Center Localization Dutch<br />
Catalyst Control Center Localization Finnish<br />
Catalyst Control Center Localization French<br />
Catalyst Control Center Localization German<br />
Catalyst Control Center Localization Greek<br />
Catalyst Control Center Localization Hungarian<br />
Catalyst Control Center Localization Italian<br />
Catalyst Control Center Localization Japanese<br />
Catalyst Control Center Localization Korean<br />
Catalyst Control Center Localization Norwegian<br />
Catalyst Control Center Localization Polish<br />
Catalyst Control Center Localization Portuguese<br />
Catalyst Control Center Localization Russian<br />
Catalyst Control Center Localization Spanish<br />
Catalyst Control Center Localization Swedish<br />
Catalyst Control Center Localization Thai<br />
Catalyst Control Center Localization Turkish<br />
ccc-core-static<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
Comcast Access<br />
Comcast Toolbar 3.0<br />
Compatibility Pack for the 2007 Office system<br />
CyberLink DVD Suite<br />
CyberLink YouCam<br />
Defense Grid: The Awakening<br />
Google Chrome<br />
Google Toolbar for Internet Explorer<br />
Google Update Helper<br />
Hewlett-Packard Active Check for Health Check<br />
Hewlett-Packard Asset Agent for Health Check<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
HP Active Support Library<br />
HP Customer Experience Enhancements<br />
HP Doc Viewer<br />
HP Help and Support<br />
HP MULTIPLE MODEM INSTALLER for VISTA<br />
HP Photosmart Essential 2.5<br />
HP Quick Launch Buttons 6.40 D3<br />
HP QuickPlay 3.7<br />
HP Smart Web Printing<br />
HP Total Care Advisor<br />
HP Update<br />
HP User Guides 0102<br />
HP Wireless Assistant<br />
HPPhotoSmartDiscLabel_PaperLabel<br />
HPPhotoSmartDiscLabel_PrintOnDisc<br />
HPPhotoSmartDiscLabel_Tattoo<br />
HPPhotoSmartDiscLabelContent1<br />
hpphotosmartdisclabelplugin<br />
HPPhotoSmartPhotobookHolidayPack1<br />
HPPhotoSmartPhotobookModernPack1<br />
HPPhotoSmartPhotobookPlayfulPack1<br />
HPPhotoSmartPhotobookScrapbookPack1<br />
HPPhotoSmartPhotobookWebPack1<br />
HPTCSSetup<br />
IDT Audio<br />
InterActual Player<br />
Java&#153; 6 Update 17<br />
Java&#153; 6 Update 5<br />
JumpStart Advanced PreSchool Explore and Learn<br />
Junk Mail filter update<br />
LabelPrint<br />
LeapFrog Connect<br />
LeapFrog My Pals Plugin<br />
LeapFrog Tag Junior Plugin<br />
LightScribe System Software  1.12.33.2<br />
McAfee Security Scan<br />
Microsoft .NET Framework 1.1<br />
Microsoft .NET Framework 1.1 Security Update (KB2416447)<br />
Microsoft Choice Guard<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office Live Add-in 1.3<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Search Enhancement Pack<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU&#93;<br />
Microsoft Sync Framework Runtime Native v1.0 (x86)<br />
Microsoft Sync Framework Services Native v1.0 (x86)<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Microsoft Works<br />
Move Media Player<br />
MSN Toolbar<br />
MSVCRT<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
muvee autoProducer 6.1<br />
My HP Games<br />
Overlord<br />
Pando Media Booster<br />
Power2Go<br />
PowerDirector<br />
PSSWCORE<br />
QuickPlay SlingPlayer 0.4.6<br />
QuickTime<br />
Realtek 8169 8168 8101E 8102E Ethernet Driver<br />
Realtek USB 2.0 Card Reader<br />
Security Update for 2007 Microsoft Office System (KB2288621)<br />
Security Update for 2007 Microsoft Office System (KB2288931)<br />
Security Update for 2007 Microsoft Office System (KB2345043)<br />
Security Update for 2007 Microsoft Office System (KB2553089)<br />
Security Update for 2007 Microsoft Office System (KB2553090)<br />
Security Update for 2007 Microsoft Office System (KB2584063)<br />
Security Update for 2007 Microsoft Office System (KB969559)<br />
Security Update for 2007 Microsoft Office System (KB976321)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)<br />
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition<br />
Security Update for Microsoft Office InfoPath 2007 (KB979441)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition<br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition<br />
Security Update for Microsoft Office system 2007 (972581)<br />
Security Update for Microsoft Office system 2007 (KB974234)<br />
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)<br />
Security Update for Microsoft Office Word 2007 (KB2344993)<br />
Shutterfly Express Uploader<br />
Skins<br />
Skype™ 5.5<br />
Slingbox Flash Tour<br />
SlingPlayer<br />
SmartMusic 2012<br />
Steam<br />
Torchlight<br />
Unity Web Player<br />
Update for 2007 Microsoft Office System (KB2284654)<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Microsoft Office 2007 Help for Common Features (KB957244)<br />
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition<br />
Update for Microsoft Office 2007 System (KB2539530)<br />
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition<br />
Update for Microsoft Office Excel 2007 Help (KB957242)<br />
Update for Microsoft Office OneNote 2007 (KB980729)<br />
Update for Microsoft Office OneNote 2007 Help (KB957245)<br />
Update for Microsoft Office PowerPoint 2007 Help (KB957247)<br />
Update for Microsoft Office Script Editor Help (KB963671)<br />
Update for Microsoft Office Word 2007 Help (KB957252)<br />
Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)<br />
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Junior Plugin)<br />
VideoToolkit01<br />
Viewpoint Media Player<br />
Visual C++ 8.0 Runtime Setup Package (x64)<br />
VitalSource Bookshelf<br />
VLC media player 0.9.2<br />
WebExcellenceAdviceTool<br />
Windows Live Call<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Mail<br />
Windows Live Messenger<br />
Windows Live Movie Maker<br />
Windows Live Photo Gallery<br />
Windows Live Sign-in Assistant<br />
Windows Live Sync<br />
Windows Live Toolbar<br />
Windows Live Upload Tool<br />
Windows Live Writer<br />
WinRAR archiver<br />
Yahoo! Messenger<br />
Yahoo! Software Update<br />
Yahoo! Toolbar<br />
.<br />
==== End Of File ===========================]]></description>
			<content:encoded><![CDATA[So my son picked up some sort of virus off his computer, it is sending mad amounts of e-mails to anyone and everyone he has ever e-mailed with some link to something else. I ran AVG and it found some tracking cookies but didn't seem to completely fix the issue, please help!<br />
<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.6001.19088<br />
Run by Mia at 20:17:10 on 2012-01-28<br />
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3837.1483 [GMT -5:00]<br />
.<br />
AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82}<br />
SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k rpcss<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Windows\system32\Ati2evxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8adfd0a8\STacSV64.exe<br />
C:\Windows\system32\svchost.exe -k GPSvcGroup<br />
C:\Windows\system32\SLsvc.exe<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\Hpservice.exe<br />
C:\Windows\system32\Ati2evxx.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\WLANExt.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe<br />
C:\Windows\system32\agr64svc.exe<br />
C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe<br />
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe<br />
C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe<br />
C:\Windows\SMINST\BLService.exe<br />
C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe<br />
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe<br />
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Windows\system32\WUDFHost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Windows Defender\MSASCui.exe<br />
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe<br />
C:\Program Files\IDT\WDM\sttray64.exe<br />
C:\Windows\System32\wpcumi.exe<br />
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe<br />
C:\Windows\ehome\ehtray.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe<br />
C:\Windows\ehome\ehmsas.exe<br />
C:\Windows\System32\alg.exe<br />
C:\Program Files (x86)\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files (x86)\Internet Explorer\IELowutil.exe<br />
C:\Program Files (x86)\HP\QuickPlay\QPService.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe<br />
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br />
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files (x86)\Java\jre6\bin\jusched.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files (x86)\AVG Secure Search\vprot.exe<br />
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br />
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe<br />
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe<br />
C:\Program Files\iPod\bin\iPodService.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files\Windows Media Player\WMPNSCFG.exe<br />
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe<br />
C:\Windows\splwow64.exe<br />
C:\Windows\System32\vds.exe<br />
C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe<br />
C:\PROGRA~2\AVG\AVG8\avgrsa.exe<br />
C:\PROGRA~2\AVG\AVG8\avgemc.exe<br />
C:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe<br />
C:\Windows\system32\wuauclt.exe<br />
C:\Windows\System32\mobsync.exe<br />
C:\Users\Mia\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\Users\Mia\AppData\Local\Google\Chrome\Application\chrome.exe<br />
C:\PROGRA~2\AVG\AVG8\avgnsa.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\servicing\TrustedInstaller.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Internet Explorer\iexplore.exe<br />
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe<br />
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\system32\DllHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uSearch Page = <br />
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb<br />
uSearch Bar = <br />
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb<br />
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;tp=iehome&amp;locale=en_us&amp;c=83&amp;bd=Pavilion&amp;pf=cnnb<br />
uInternet Settings,ProxyOverride = *.local<br />
uURLSearchHooks: H - No File<br />
uURLSearchHooks: H - No File<br />
mURLSearchHooks: H - No File<br />
mWinlogon: Userinit=userinit.exe<br />
BHO: &amp;Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
BHO: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO: WebExcellenceAdviceTool: {cd1a4f51-6371-6621-312a-b4cd3941f6de} - C:\Program Files (x86)\WebExcellenceAdviceTool\WebExcellenceAdviceTool.dll<br />
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File<br />
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
TB: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
TB: &amp;Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File<br />
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File<br />
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}<br />
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden<br />
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe<br />
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background<br />
uRun: [ComcastAntispyClient] "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide<br />
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"<br />
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent<br />
uRun: [Google Update] "C:\Users\Mia\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br />
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized<br />
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"<br />
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"<br />
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"<br />
mRun: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start<br />
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
mRun: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
mRun: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
mRun: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"<br />
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"<br />
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"<br />
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"<br />
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
mRun: [<NO NAME>] <br />
mRun: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12<br />
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\1.0.150\SSScheduler.exe<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL<br />
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
LSP: C:\Windows\system32\wpclsp.dll<br />
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab<br />
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab<br />
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files%20(x86)/Zuma/Images/stg_drm.ocx<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab<br />
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab<br />
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab<br />
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-us.cab<br />
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab<br />
DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab<br />
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab<br />
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab<br />
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files%20(x86)/Zuma/Images/armhelper.ocx<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab<br />
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab<br />
TCP: DhcpNameServer = 65.32.5.111 65.32.5.112<br />
TCP: Interfaces\{DD98F11F-AFBE-4C30-AD14-5D9C474C3AE2} : DhcpNameServer = 65.32.5.111 65.32.5.112<br />
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\iEvony\Skype4COM.dll<br />
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll<br />
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"<br />
BHO-X64: &amp;Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
BHO-X64:     0x1 - No File<br />
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO-X64:     AcroIEHelperStub - No File<br />
BHO-X64: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
BHO-X64:     AskBar BHO - No File<br />
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll<br />
BHO-X64:     WormRadar.com IESiteBlocker.NavFilter - No File<br />
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File<br />
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll<br />
BHO-X64:     Search Helper - No File<br />
BHO-X64: Comcast Toolbar: {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
BHO-X64:     Comcast Toolbar - No File<br />
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll<br />
BHO-X64: WebExcellenceAdviceTool: {CD1A4F51-6371-6621-312A-B4CD3941F6DE} - C:\Program Files (x86)\WebExcellenceAdviceTool\WebExcellenceAdviceTool.dll<br />
BHO-X64:     WebExcellenceAdviceTool - No File<br />
BHO-X64: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
BHO-X64: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO-X64: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll<br />
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll<br />
BHO-X64:     HP Smart BHO Class - No File<br />
TB-X64: MSN Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.0988.2\msneshellx.dll<br />
TB-X64: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll<br />
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File<br />
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll<br />
TB-X64: Comcast Toolbar: {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files (x86)\comcasttb\comcastdx.dll<br />
TB-X64: &amp;Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll<br />
TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll<br />
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll<br />
TB-X64: {A057A204-BACC-4D26-9990-79A187E2698E} - No File<br />
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File<br />
TB-X64: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File<br />
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"<br />
mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"<br />
mRun-x64: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"<br />
mRun-x64: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start<br />
mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe<br />
mRun-x64: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe<br />
mRun-x64: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe<br />
mRun-x64: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe<br />
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br />
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br />
mRun-x64: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"<br />
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"<br />
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br />
mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"<br />
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"<br />
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br />
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe<br />
mRun-x64: [(Default)] <br />
mRun-x64: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys --&gt; C:\Windows\system32\DRIVERS\ahcix64s.sys [?]<br />
R0 Amddfltr64;Amd Disk Lower Filter Driver;C:\Windows\system32\DRIVERS\Amddfltr64.sys --&gt; C:\Windows\system32\DRIVERS\Amddfltr64.sys [?]<br />
R1 AvgLdx64;AVG Free AVI Loader Driver x64;C:\Windows\system32\Drivers\avgldx64.sys --&gt; C:\Windows\system32\Drivers\avgldx64.sys [?]<br />
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;C:\Windows\system32\Drivers\avgmfx64.sys --&gt; C:\Windows\system32\Drivers\avgmfx64.sys [?]<br />
R1 AvgTdiA;AVG8 Network Redirector;C:\Windows\system32\Drivers\avgtdia.sys --&gt; C:\Windows\system32\Drivers\avgtdia.sys [?]<br />
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe --&gt; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_a02f3f3d\AESTSr64.exe [?]<br />
R2 AntiSpywareService;Comcast AntiSpyware;C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [2009-6-17 616408]<br />
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~2\AVG\AVG8\avgemc.exe [2009-7-1 908056]<br />
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe [2009-7-1 297752]<br />
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --&gt; C:\Windows\system32\Hpservice.exe [?]<br />
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-5-21 193840]<br />
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --&gt; C:\Windows\system32\DRIVERS\enecir.sys [?]<br />
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-28 135664]<br />
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG8\Toolbar\ToolbarBroker.exe [2011-11-3 167264]<br />
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-8-21 93184]<br />
S3 FlyUsb;FLY Fusion;C:\Windows\system32\DRIVERS\FlyUsb.sys --&gt; C:\Windows\system32\DRIVERS\FlyUsb.sys [?]<br />
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-28 135664]<br />
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]<br />
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --&gt; C:\Windows\system32\DRIVERS\ssadbus.sys [?]<br />
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --&gt; C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]<br />
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --&gt; C:\Windows\system32\DRIVERS\ssadmdm.sys [?]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --&gt; C:\Windows\system32\Drivers\usbaapl64.sys [?]<br />
.<br />
=============== File Associations ===============<br />
.<br />
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-28 03:13:03	8602168	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{DA384536-C76E-4228-B1E4-4588BEB3F310}\mpengine.dll<br />
2012-01-09 00:24:05	--------	d-----r-	C:\Program Files (x86)\Skype<br />
2012-01-06 06:14:47	--------	d-----w-	C:\Users\Mia\AppData\Roaming\HpUpdate<br />
2012-01-06 06:14:33	--------	d-----w-	C:\Windows\Hewlett-Packard<br />
2012-01-04 15:29:40	--------	d-----w-	C:\Users\Mia\AppData\Roaming\com.Shutterfly.ExpressUploader<br />
2012-01-04 15:29:14	--------	d-----w-	C:\Program Files (x86)\Shutterfly<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2011-12-07 15:39:10	279096	------w-	C:\Windows\System32\MpSigStub.exe<br />
2011-11-17 01:33:24	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2011-11-02 21:30:13	427016	----a-w-	C:\Windows\System32\drivers\avgldx64.sys<br />
.<br />
============= FINISH: 20:18:48.93 ===============<br />
<br />
<br />
<br />
<br />
<br />
********************************************************<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft® Windows Vista™ Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 9/20/2008 5:39:11 AM<br />
System Uptime: 1/27/2012 11:03:41 PM (21 hours ago)<br />
.<br />
Motherboard: HP |  | 30F2<br />
Processor: AMD Turion&#153; X2 Dual-Core Mobile RM-70 | Socket M2/S1G1 | 500/1800mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 222 GiB total, 126.303 GiB free.<br />
D: is FIXED (NTFS) - 11 GiB total, 1.839 GiB free.<br />
E: is CDROM ()<br />
G: is Removable<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP389: 1/6/2012 9:34:42 AM - Windows Update<br />
RP390: 1/9/2012 11:42:22 PM - Scheduled Checkpoint<br />
RP391: 1/10/2012 4:48:52 PM - Windows Update<br />
RP392: 1/11/2012 8:25:22 PM - Windows Update<br />
RP393: 1/14/2012 7:17:27 PM - Windows Update<br />
RP394: 1/15/2012 7:52:20 PM - Scheduled Checkpoint<br />
RP395: 1/15/2012 8:24:45 PM - Device Driver Package Install: SAMSUNG Electronics Co., Ltd.  Universal Serial Bus controllers<br />
RP396: 1/15/2012 8:27:43 PM - Device Driver Package Install: SAMSUNG Electronics Co., Ltd.  Modems<br />
RP397: 1/17/2012 5:55:17 PM - Windows Update<br />
RP398: 1/19/2012 10:06:46 PM - Scheduled Checkpoint<br />
RP399: 1/20/2012 10:06:52 PM - Windows Update<br />
RP400: 1/23/2012 8:50:50 PM - Scheduled Checkpoint<br />
RP401: 1/24/2012 6:04:49 PM - Windows Update<br />
RP402: 1/27/2012 10:12:18 PM - Windows Update<br />
.<br />
==== Installed Programs ======================<br />
.<br />
 Update for Microsoft Office 2007 (KB2508958)<br />
Acrobat.com<br />
Activation Assistant for the 2007 Microsoft Office suites<br />
Adobe AIR<br />
Adobe Flash Player 10 Plugin<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Reader 9.2<br />
Adobe Shockwave Player 11.5<br />
Algebrator 4.0<br />
Apple Application Support<br />
Apple Software Update<br />
Ask Toolbar<br />
Atheros Driver Installation Program<br />
AVG Free 8.5<br />
CA Pest Patrol Realtime Protection<br />
Cards_Calendar_OrderGift_DoMorePlugout<br />
Catalyst Control Center - Branding<br />
Catalyst Control Center Core Implementation<br />
Catalyst Control Center Graphics Full Existing<br />
Catalyst Control Center Graphics Full New<br />
Catalyst Control Center Graphics Light<br />
Catalyst Control Center Graphics Previews Vista<br />
Catalyst Control Center Localization Chinese Standard<br />
Catalyst Control Center Localization Chinese Traditional<br />
Catalyst Control Center Localization Czech<br />
Catalyst Control Center Localization Danish<br />
Catalyst Control Center Localization Dutch<br />
Catalyst Control Center Localization Finnish<br />
Catalyst Control Center Localization French<br />
Catalyst Control Center Localization German<br />
Catalyst Control Center Localization Greek<br />
Catalyst Control Center Localization Hungarian<br />
Catalyst Control Center Localization Italian<br />
Catalyst Control Center Localization Japanese<br />
Catalyst Control Center Localization Korean<br />
Catalyst Control Center Localization Norwegian<br />
Catalyst Control Center Localization Polish<br />
Catalyst Control Center Localization Portuguese<br />
Catalyst Control Center Localization Russian<br />
Catalyst Control Center Localization Spanish<br />
Catalyst Control Center Localization Swedish<br />
Catalyst Control Center Localization Thai<br />
Catalyst Control Center Localization Turkish<br />
ccc-core-static<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
Comcast Access<br />
Comcast Toolbar 3.0<br />
Compatibility Pack for the 2007 Office system<br />
CyberLink DVD Suite<br />
CyberLink YouCam<br />
Defense Grid: The Awakening<br />
Google Chrome<br />
Google Toolbar for Internet Explorer<br />
Google Update Helper<br />
Hewlett-Packard Active Check for Health Check<br />
Hewlett-Packard Asset Agent for Health Check<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
HP Active Support Library<br />
HP Customer Experience Enhancements<br />
HP Doc Viewer<br />
HP Help and Support<br />
HP MULTIPLE MODEM INSTALLER for VISTA<br />
HP Photosmart Essential 2.5<br />
HP Quick Launch Buttons 6.40 D3<br />
HP QuickPlay 3.7<br />
HP Smart Web Printing<br />
HP Total Care Advisor<br />
HP Update<br />
HP User Guides 0102<br />
HP Wireless Assistant<br />
HPPhotoSmartDiscLabel_PaperLabel<br />
HPPhotoSmartDiscLabel_PrintOnDisc<br />
HPPhotoSmartDiscLabel_Tattoo<br />
HPPhotoSmartDiscLabelContent1<br />
hpphotosmartdisclabelplugin<br />
HPPhotoSmartPhotobookHolidayPack1<br />
HPPhotoSmartPhotobookModernPack1<br />
HPPhotoSmartPhotobookPlayfulPack1<br />
HPPhotoSmartPhotobookScrapbookPack1<br />
HPPhotoSmartPhotobookWebPack1<br />
HPTCSSetup<br />
IDT Audio<br />
InterActual Player<br />
Java&#153; 6 Update 17<br />
Java&#153; 6 Update 5<br />
JumpStart Advanced PreSchool Explore and Learn<br />
Junk Mail filter update<br />
LabelPrint<br />
LeapFrog Connect<br />
LeapFrog My Pals Plugin<br />
LeapFrog Tag Junior Plugin<br />
LightScribe System Software  1.12.33.2<br />
McAfee Security Scan<br />
Microsoft .NET Framework 1.1<br />
Microsoft .NET Framework 1.1 Security Update (KB2416447)<br />
Microsoft Choice Guard<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office Live Add-in 1.3<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office PowerPoint Viewer 2007 (English)<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Search Enhancement Pack<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Sync Framework Runtime Native v1.0 (x86)<br />
Microsoft Sync Framework Services Native v1.0 (x86)<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Microsoft Works<br />
Move Media Player<br />
MSN Toolbar<br />
MSVCRT<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
muvee autoProducer 6.1<br />
My HP Games<br />
Overlord<br />
Pando Media Booster<br />
Power2Go<br />
PowerDirector<br />
PSSWCORE<br />
QuickPlay SlingPlayer 0.4.6<br />
QuickTime<br />
Realtek 8169 8168 8101E 8102E Ethernet Driver<br />
Realtek USB 2.0 Card Reader<br />
Security Update for 2007 Microsoft Office System (KB2288621)<br />
Security Update for 2007 Microsoft Office System (KB2288931)<br />
Security Update for 2007 Microsoft Office System (KB2345043)<br />
Security Update for 2007 Microsoft Office System (KB2553089)<br />
Security Update for 2007 Microsoft Office System (KB2553090)<br />
Security Update for 2007 Microsoft Office System (KB2584063)<br />
Security Update for 2007 Microsoft Office System (KB969559)<br />
Security Update for 2007 Microsoft Office System (KB976321)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)<br />
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition<br />
Security Update for Microsoft Office InfoPath 2007 (KB979441)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition<br />
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition<br />
Security Update for Microsoft Office system 2007 (972581)<br />
Security Update for Microsoft Office system 2007 (KB974234)<br />
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)<br />
Security Update for Microsoft Office Word 2007 (KB2344993)<br />
Shutterfly Express Uploader<br />
Skins<br />
Skype™ 5.5<br />
Slingbox Flash Tour<br />
SlingPlayer<br />
SmartMusic 2012<br />
Steam<br />
Torchlight<br />
Unity Web Player<br />
Update for 2007 Microsoft Office System (KB2284654)<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Microsoft Office 2007 Help for Common Features (KB957244)<br />
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition<br />
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition<br />
Update for Microsoft Office 2007 System (KB2539530)<br />
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition<br />
Update for Microsoft Office Excel 2007 Help (KB957242)<br />
Update for Microsoft Office OneNote 2007 (KB980729)<br />
Update for Microsoft Office OneNote 2007 Help (KB957245)<br />
Update for Microsoft Office PowerPoint 2007 Help (KB957247)<br />
Update for Microsoft Office Script Editor Help (KB963671)<br />
Update for Microsoft Office Word 2007 Help (KB957252)<br />
Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)<br />
Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Junior Plugin)<br />
VideoToolkit01<br />
Viewpoint Media Player<br />
Visual C++ 8.0 Runtime Setup Package (x64)<br />
VitalSource Bookshelf<br />
VLC media player 0.9.2<br />
WebExcellenceAdviceTool<br />
Windows Live Call<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Mail<br />
Windows Live Messenger<br />
Windows Live Movie Maker<br />
Windows Live Photo Gallery<br />
Windows Live Sign-in Assistant<br />
Windows Live Sync<br />
Windows Live Toolbar<br />
Windows Live Upload Tool<br />
Windows Live Writer<br />
WinRAR archiver<br />
Yahoo! Messenger<br />
Yahoo! Software Update<br />
Yahoo! Toolbar<br />
.<br />
==== End Of File ===========================]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Why is SOPA/PIPA a bad thing?]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-why-is-sopa-pipa-a-bad-thing</link>
			<pubDate>Thu, 19 Jan 2012 17:52:20 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-why-is-sopa-pipa-a-bad-thing</guid>
			<description><![CDATA[Beenhearing a lot about SOPA/PIPA lately? Been wondering what it's about and why it's a bad thing? This video gives a clear explanation:  <a href="http://bit.ly/ABBDIJ" rel="nofollow nofollow" target="_blank">http://bit.ly/ABBDIJ</a><br />
<br />
Once you have watched that, then go here and sign the UK petition against the SOPA/PIPA act:<a href="http://bit.ly/AkbmB4" rel="nofollow nofollow" target="_blank">http://bit.ly/AkbmB4</a><br />
<br />
Finally, share this with as many people as possible. Trust me it's more important than tending to your herd on farmville or that funny cat picture you were about to post. (which you may be sued for should this act go ahead).<br />
<br />
Also for an amusing take on why this  is a bad thing, watch this vid:<br />
<br />
&amp;nbsp;<br />
<iframe width="560" height="315" src="http://www.youtube.com/embed/1p-TV4jaCMk" frameborder="0" allowfullscreen></iframe><br />
&amp;nbsp;<br /><a class="wordbb-full-post" href="http://blog.techmonkeys.co.uk/internet-websites/why-is-sopapipa-a-bad-thing/" title="Why is SOPA/PIPA a bad thing?">Read Full Post: Why is SOPA/PIPA a bad thing?</a>]]></description>
			<content:encoded><![CDATA[Beenhearing a lot about SOPA/PIPA lately? Been wondering what it's about and why it's a bad thing? This video gives a clear explanation:  <a href="http://bit.ly/ABBDIJ" rel="nofollow nofollow" target="_blank">http://bit.ly/ABBDIJ</a><br />
<br />
Once you have watched that, then go here and sign the UK petition against the SOPA/PIPA act:<a href="http://bit.ly/AkbmB4" rel="nofollow nofollow" target="_blank">http://bit.ly/AkbmB4</a><br />
<br />
Finally, share this with as many people as possible. Trust me it's more important than tending to your herd on farmville or that funny cat picture you were about to post. (which you may be sued for should this act go ahead).<br />
<br />
Also for an amusing take on why this  is a bad thing, watch this vid:<br />
<br />
&amp;nbsp;<br />
<iframe width="560" height="315" src="http://www.youtube.com/embed/1p-TV4jaCMk" frameborder="0" allowfullscreen></iframe><br />
&amp;nbsp;<br /><a class="wordbb-full-post" href="http://blog.techmonkeys.co.uk/internet-websites/why-is-sopapipa-a-bad-thing/" title="Why is SOPA/PIPA a bad thing?">Read Full Post: Why is SOPA/PIPA a bad thing?</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Spotify and WMP glitch Win7]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-spotify-and-wmp-glitch-win7</link>
			<pubDate>Mon, 16 Jan 2012 16:49:33 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-spotify-and-wmp-glitch-win7</guid>
			<description><![CDATA[Hi guys<br />
<br />
For the last month I've been experiencing some weird glitches/malfunctions on my Win 7. Approximately once a day my computer starts repeatedly opening the Windows Media Player window and music starts playing. Same thing happens with Spotify. And since the apps always come up on top I can't work. Only a reset seems to be of any help.<br />
<br />
What can it be? could it be connected to the fact that we recently changed the keyboard to a razer gaming keyboard (my son insisted<img src="http://www.techmonkeys.co.uk/images/smilies/huh.gif" style="vertical-align: middle;" border="0" alt="Huh" title="Huh" />)? how can i deal with it?]]></description>
			<content:encoded><![CDATA[Hi guys<br />
<br />
For the last month I've been experiencing some weird glitches/malfunctions on my Win 7. Approximately once a day my computer starts repeatedly opening the Windows Media Player window and music starts playing. Same thing happens with Spotify. And since the apps always come up on top I can't work. Only a reset seems to be of any help.<br />
<br />
What can it be? could it be connected to the fact that we recently changed the keyboard to a razer gaming keyboard (my son insisted<img src="http://www.techmonkeys.co.uk/images/smilies/huh.gif" style="vertical-align: middle;" border="0" alt="Huh" title="Huh" />)? how can i deal with it?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[far cry 3]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-far-cry-3</link>
			<pubDate>Sat, 14 Jan 2012 13:42:50 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-far-cry-3</guid>
			<description><![CDATA[andbody know when far cry 3 is out?]]></description>
			<content:encoded><![CDATA[andbody know when far cry 3 is out?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[looking to buy a new custom pc]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-looking-to-buy-a-new-custom-pc</link>
			<pubDate>Sat, 14 Jan 2012 13:41:13 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-looking-to-buy-a-new-custom-pc</guid>
			<description><![CDATA[looking to buy a new PC but dont want to go to amajor supplier like PC world has ive had problems in the past. Found this site <a href="http://www.buildyourbox.co.uk/" target="_blank">Build your box</a> any body got any other suggestions?<hr />
oh and it will be mainly for gaming]]></description>
			<content:encoded><![CDATA[looking to buy a new PC but dont want to go to amajor supplier like PC world has ive had problems in the past. Found this site <a href="http://www.buildyourbox.co.uk/" target="_blank">Build your box</a> any body got any other suggestions?<hr />
oh and it will be mainly for gaming]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Win 7 antivirus scam]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-win-7-antivirus-scam</link>
			<pubDate>Sat, 07 Jan 2012 19:24:19 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-win-7-antivirus-scam</guid>
			<description><![CDATA[I just got infected with the fake windows antivirus errr virus? It installs a fake 'virus scanner' that purports to show all the threats to your system which it will 'fix' if you submit your credit card details etc etc. It also stopped me acessing the internet- instead redirecting to register the phony antivirus software. I ran a malwarebytes scan after disconnecting from the internet (it wasn't possible before) which found 5 threats and successfully deleted them after a reboot.<br />
<br />
everything seems fairly normal now but I just wanted to check that my system was in the clear- I ran a full system scan with avast after rebooting and that found nothing...<br />
<br />
here are the dds files:<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7601.17514  BrowserJavaVersion: 1.6.0_26<br />
Run by Bitey at 19:13:43 on 2012-01-07<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.8099.5242 [GMT 0:00&#93;<br />
.<br />
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}<br />
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Program Files (x86)\Hotkey\PowerBiosServer.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Program Files (x86)\Steam\steam.exe<br />
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe<br />
C:\Program Files (x86)\BitTorrent\BitTorrent.exe<br />
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe<br />
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe<br />
C:\Windows\system32\svchost.exe -k SDRSVC<br />
C:\Windows\system32\DllHost.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe<br />
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
Q:\140066.enu\Office14\WINWORDC.EXE<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.pcspecialist.co.uk/<br />
uDefault_Page_URL = hxxp://www.pcspecialist.co.uk/<br />
uInternet Settings,ProxyOverride = *.local<br />
mWinlogon: Userinit=userinit.exe,<br />
BHO: AutorunsDisabled - No File<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
uRun: [Steam&#93; "C:\Program Files (x86)\Steam\Steam.exe" -silent<br />
uRun: [Advanced SystemCare 5&#93; "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart<br />
uRun: [BitTorrent&#93; "C:\Program Files (x86)\BitTorrent\BitTorrent.exe"  /MINIMIZED<br />
mRun: [NUSB3MON&#93; "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"<br />
mRun: [avast&#93; "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui<br />
mRunOnce: [aswAhAScr.dll&#93; "C:\Program Files\AVAST Software\Avast\aswRegSvr.exe" "C:\Program Files\AVAST Software\Avast\AhAScr.dll"<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100<br />
TCP: Interfaces\{A23E193E-F80C-4417-91CA-00A72835A680} : DhcpNameServer = 194.168.4.100 194.168.8.100<br />
TCP: Interfaces\{A23E193E-F80C-4417-91CA-00A72835A680}\244564F4E4 : DhcpNameServer = 192.168.22.22 192.168.22.23<br />
TCP: Interfaces\{A23E193E-F80C-4417-91CA-00A72835A680}\4656661657C647 : DhcpNameServer = 194.168.4.100 192.168.123.254<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll<br />
BHO-X64: AutorunsDisabled - No File<br />
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
mRun-x64: [NUSB3MON&#93; "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"<br />
mRun-x64: [avast&#93; "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui<br />
mRunOnce-x64: [aswAhAScr.dll&#93; "C:\Program Files\AVAST Software\Avast\aswRegSvr.exe" "C:\Program Files\AVAST Software\Avast\AhAScr.dll"<br />
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\Bitey\AppData\Roaming\Mozilla\Firefox\Profiles\9qdgkg8b.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.blackle.com/<br />
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --&gt; C:\Windows\system32\DRIVERS\nvpciflt.sys [?&#93;<br />
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\system32\Drivers\SmartDefragDrive&#8203;r.sys --&gt; C:\Windows\system32\Drivers\SmartDefragDriver.sys [?&#93;<br />
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --&gt; C:\Windows\system32\drivers\aswSnx.sys [?&#93;<br />
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --&gt; C:\Windows\system32\drivers\aswSP.sys [?&#93;<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --&gt; C:\Windows\system32\DRIVERS\vwififlt.sys [?&#93;<br />
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2011-12-25 494424&#93;<br />
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --&gt; C:\Windows\system32\drivers\aswFsBlk.sys [?&#93;<br />
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --&gt; C:\Windows\system32\drivers\aswMonFlt.sys [?&#93;<br />
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-9-20 44768&#93;<br />
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664&#93;<br />
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2011-12-20 2348864&#93;<br />
R2 PowerBiosServer;PowerBiosServer;C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [2011-1-27 33792&#93;<br />
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264&#93;<br />
R2 UNS;Intel&reg; Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe [2011-4-8 2656280&#93;<br />
R3 IntcDAud;Intel&reg; Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --&gt; C:\Windows\system32\DRIVERS\IntcDAud.sys [?&#93;<br />
R3 MEIx64;Intel&reg; Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?&#93;<br />
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --&gt; C:\Windows\system32\DRIVERS\nusb3hub.sys [?&#93;<br />
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --&gt; C:\Windows\system32\DRIVERS\nusb3xhc.sys [?&#93;<br />
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184&#93;<br />
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\system32\DRIVERS\rtl8192Ce.sys --&gt; C:\Windows\system32\DRIVERS\rtl8192Ce.sys [?&#93;<br />
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --&gt; C:\Windows\system32\DRIVERS\Sftfslh.sys [?&#93;<br />
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --&gt; C:\Windows\system32\DRIVERS\Sftplaylh.sys [?&#93;<br />
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --&gt; C:\Windows\system32\DRIVERS\Sftredirlh.sys [?&#93;<br />
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --&gt; C:\Windows\system32\DRIVERS\Sftvollh.sys [?&#93;<br />
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496&#93;<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --&gt; C:\Windows\system32\DRIVERS\vwifimp.sys [?&#93;<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384&#93;<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576&#93;<br />
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --&gt; C:\Windows\system32\DRIVERS\fssfltr.sys [?&#93;<br />
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840&#93;<br />
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-12-19 135584&#93;<br />
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --&gt; C:\Windows\system32\DRIVERS\jmcr.sys [?&#93;<br />
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);C:\Windows\system32\DRIVERS\JME.sys --&gt; C:\Windows\system32\DRIVERS\JME.sys [?&#93;<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-1-5 340240&#93;<br />
S3 NETwNs64;___ Intel&reg; Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --&gt; C:\Windows\system32\DRIVERS\NETwNs64.sys [?&#93;<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --&gt; C:\Windows\system32\drivers\tsusbflt.sys [?&#93;<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --&gt; C:\Windows\system32\drivers\TsUsbGD.sys [?&#93;<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?&#93;<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184&#93;<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-07 18:20:46	69000	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1C97246F-29EA-45C9-909D-25BBF7BA02F3}\offreg.dll<br />
2012-01-07 17:23:54	--------	d-----w-	C:\Program Files (x86)\BitTorrent<br />
2012-01-07 17:22:45	--------	d-----w-	C:\Users\Bitey\AppData\Roaming\BitTorrent<br />
2012-01-05 15:41:59	--------	d-----w-	C:\Users\Bitey\AppData\Local\{1F48A284-5E85-450E-99DB-14ACD544750C}<br />
2012-01-05 15:41:47	--------	d-----w-	C:\Users\Bitey\AppData\Local\{AA6EF762-DEC7-498F-8686-EDBB9C24E9C6}<br />
2012-01-03 17:52:10	--------	d-----w-	C:\Users\Bitey\AppData\Local\{08DF3F40-3841-4896-9DB3-0BAE8A8542AB}<br />
2012-01-03 17:51:53	--------	d-----w-	C:\Users\Bitey\AppData\Local\{1980ABC5-A9A4-4365-A27D-10183E6F7EE1}<br />
2012-01-03 11:25:53	--------	d-----w-	C:\Program Files (x86)\GTK2-Runtime<br />
2012-01-03 11:11:59	--------	d-----w-	C:\Users\Bitey\AppData\Roaming\deluge<br />
2012-01-02 11:26:20	--------	d-----w-	C:\Users\Bitey\AppData\Local\{D3FE32F2-481E-46F1-A007-7F171B7FF89A}<br />
2012-01-02 11:26:04	--------	d-----w-	C:\Users\Bitey\AppData\Local\{EA8474E7-9141-4688-B015-4327E9EEA056}<br />
2011-12-31 10:49:18	--------	d-----w-	C:\Users\Bitey\AppData\Local\{0BF782FC-7068-4C80-90B4-56CD2179F491}<br />
2011-12-31 10:49:02	--------	d-----w-	C:\Users\Bitey\AppData\Local\{B7B41B3B-43D1-4F98-8BA2-FD76B441EC11}<br />
2011-12-30 11:56:02	--------	d-----w-	C:\Users\Bitey\AppData\Local\{FAB131B3-1B2E-4B6A-87D5-1B84453D3886}<br />
2011-12-30 11:55:50	--------	d-----w-	C:\Users\Bitey\AppData\Local\{DF3FA54D-25C7-45D2-BC5D-BA038EB31286}<br />
2011-12-30 11:46:41	8822856	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1C97246F-29EA-45C9-909D-25BBF7BA02F3}\mpengine.dll<br />
2011-12-29 19:33:46	--------	d-----w-	C:\Users\Bitey\AppData\Local\{88AF1506-5BE6-47FE-B6A5-35447DEBB599}<br />
2011-12-29 19:33:35	--------	d-----w-	C:\Users\Bitey\AppData\Local\{70FEF605-A015-479A-95C2-6DAAC3E8982A}<br />
2011-12-29 14:23:47	626688	----a-w-	C:\Program Files (x86)\Mozilla Firefox\msvcr80.dll<br />
2011-12-29 14:23:47	548864	----a-w-	C:\Program Files (x86)\Mozilla Firefox\msvcp80.dll<br />
2011-12-29 14:23:47	479232	----a-w-	C:\Program Files (x86)\Mozilla Firefox\msvcm80.dll<br />
2011-12-29 14:23:47	43992	----a-w-	C:\Program Files (x86)\Mozilla Firefox\mozutils.dll<br />
2011-12-28 09:36:14	--------	d-----w-	C:\Users\Bitey\AppData\Local\{06CBEDF2-5E76-4E40-B5B2-66BC6DD07C07}<br />
2011-12-28 09:35:52	--------	d-----w-	C:\Users\Bitey\AppData\Local\{8F14D8D3-825E-4FD6-AF4B-159078505D73}<br />
2011-12-26 14:16:38	--------	d-----w-	C:\Users\Bitey\AppData\Local\{DF18B29D-9995-4739-B097-75423B6966D9}<br />
2011-12-26 14:16:20	--------	d-----w-	C:\Users\Bitey\AppData\Local\{216AEFD2-F7E9-4181-85D9-953D563EF24A}<br />
2011-12-26 10:39:16	--------	d-----w-	C:\Program Files (x86)\DVD Shrink<br />
2011-12-25 21:06:08	--------	d-----w-	C:\Program Files (x86)\DVD Decrypter<br />
2011-12-25 21:03:40	--------	d-----w-	C:\Users\Bitey\AppData\Local\Ilivid Player<br />
2011-12-25 21:03:14	--------	d-----w-	C:\Program Files (x86)\iLivid<br />
2011-12-25 21:02:53	--------	d-----w-	C:\Users\Bitey\AppData\Local\PackageAware<br />
2011-12-25 20:31:30	--------	d-----w-	C:\Program Files (x86)\Elaborate Bytes<br />
2011-12-25 20:23:52	--------	d-----w-	C:\Program Files (x86)\SlySoft<br />
2011-12-25 18:18:28	--------	d-----w-	C:\Program Files (x86)\DVDFab 8 Qt<br />
2011-12-25 11:55:20	22872	----a-w-	C:\Windows\System32\RegistryDefragBootTime.exe<br />
2011-12-25 11:45:11	27992	----a-w-	C:\Windows\System32\SmartDefragBootTime.exe<br />
2011-12-25 11:45:11	17720	----a-w-	C:\Windows\System32\drivers\SmartDefragDriver.sys<br />
2011-12-25 11:43:45	--------	d-----w-	C:\Users\Bitey\AppData\Roaming\IObit<br />
2011-12-25 11:40:49	--------	d-----w-	C:\ProgramData\IObit<br />
2011-12-25 11:40:49	--------	d-----w-	C:\Program Files (x86)\IObit<br />
2011-12-25 10:01:50	--------	d-----w-	C:\Users\Bitey\AppData\Local\{BE7533B5-3769-47DB-92C3-86327EF3394E}<br />
2011-12-25 10:01:36	--------	d-----w-	C:\Users\Bitey\AppData\Local\{41BC883D-14CF-475B-B423-177E0DE04620}<br />
2011-12-24 09:16:41	--------	d-----w-	C:\Users\Bitey\AppData\Local\{63175224-73F0-4BBA-8D78-0A1FC24D5D50}<br />
2011-12-24 09:16:21	--------	d-----w-	C:\Users\Bitey\AppData\Local\{E188D8A0-7F33-474D-9C74-596C74F7188D}<br />
2011-12-23 12:56:35	--------	d-----w-	C:\Users\Bitey\AppData\Local\{1AA89AAF-288A-43A1-92C1-D00DDBEA881C}<br />
2011-12-23 12:56:23	--------	d-----w-	C:\Users\Bitey\AppData\Local\{9C74F76E-C4FA-492D-9852-4A461CE1256F}<br />
2011-12-22 18:29:16	--------	d-----w-	C:\Users\Bitey\AppData\Local\{19C039F7-6C8E-44C4-9ED9-685538A6AD3E}<br />
2011-12-22 18:29:00	--------	d-----w-	C:\Users\Bitey\AppData\Local\{FD15EEBE-5592-4714-8149-10224DDED0C0}<br />
2011-12-21 17:41:30	--------	d-----w-	C:\Program Files (x86)\Hamster Soft<br />
2011-12-21 17:19:57	--------	d-----w-	C:\Program Files (x86)\Nero<br />
2011-12-21 10:12:24	--------	d-----w-	C:\Program Files (x86)\Enterbrain<br />
2011-12-21 09:20:34	--------	d-----w-	C:\Users\Bitey\AppData\Local\{2089122D-1B73-4DB4-91D9-AA96BFB08094}<br />
2011-12-21 09:20:20	--------	d-----w-	C:\Users\Bitey\AppData\Local\{D7FC9A58-BBC8-4D56-98F3-C6A720F33481}<br />
2011-12-20 19:59:56	--------	d-----w-	C:\Users\Bitey\AppData\Local\{8F6AFA77-D5A6-4529-BCC4-50D446D03A62}<br />
2011-12-20 19:59:44	--------	d-----w-	C:\Users\Bitey\AppData\Local\{723ECBCD-5B6B-4B0C-B893-DF7FDF5B5C03}<br />
2011-12-20 19:30:08	--------	d-----w-	C:\Windows\SysWow64\NV<br />
2011-12-20 19:30:08	--------	d-----w-	C:\Windows\System32\NV<br />
2011-12-20 19:28:06	889664	----a-w-	C:\Windows\System32\nvvsvc.exe<br />
2011-12-20 19:28:06	839488	----a-w-	C:\Windows\System32\nv3dappshext.dll<br />
2011-12-20 19:28:06	63296	----a-w-	C:\Windows\System32\nvshext.dll<br />
2011-12-20 19:28:06	6004544	----a-w-	C:\Windows\System32\nvcpl.dll<br />
2011-12-20 19:28:06	55616	----a-w-	C:\Windows\System32\nv3dappshextr.dll<br />
2011-12-20 19:28:06	3028800	----a-w-	C:\Windows\System32\nvsvc64.dll<br />
2011-12-20 19:28:06	2562368	----a-w-	C:\Windows\System32\nvsvcr.dll<br />
2011-12-20 19:28:06	2417322	----a-w-	C:\Windows\System32\nvcoproc.bin<br />
2011-12-20 19:28:06	118080	----a-w-	C:\Windows\System32\nvmctray.dll<br />
2011-12-20 19:27:26	--------	d-----w-	C:\ProgramData\NVIDIA Corporation<br />
2011-12-19 22:55:48	--------	d-----w-	C:\Users\Bitey\AppData\Local\{82B665DA-EA34-4A7E-BBA4-19936374D528}<br />
2011-12-19 22:55:31	--------	d-----w-	C:\Users\Bitey\AppData\Local\{51079892-F4F9-4A1D-ABBE-30EAD9D95759}<br />
2011-12-19 17:50:11	--------	d-----w-	C:\Program Files (x86)\Futuremark<br />
2011-12-19 09:24:45	--------	d-----w-	C:\Users\Bitey\AppData\Local\{0DA9A610-74BD-4554-A411-4C7DEEBDE052}<br />
2011-12-19 09:24:25	--------	d-----w-	C:\Users\Bitey\AppData\Local\{64FBAAF2-454A-44D5-BAF7-44156641CCC9}<br />
2011-12-18 16:16:54	--------	d-----w-	C:\Program Files (x86)\Common Files\Enterbrain<br />
2011-12-18 10:44:03	--------	d-----w-	C:\Windows\SysWow64\Adobe<br />
2011-12-18 10:02:57	2048	----a-w-	C:\Windows\SysWow64\tzres.dll<br />
2011-12-18 10:02:57	2048	----a-w-	C:\Windows\System32\tzres.dll<br />
2011-12-18 10:02:16	--------	d-----w-	C:\Users\Bitey\AppData\Local\{7C1BF810-000F-411B-9EBB-19B9F7CC2592}<br />
2011-12-18 10:01:37	--------	d-----w-	C:\Users\Bitey\AppData\Local\{81ED20DB-CECB-4270-ADC2-B67400FB38CB}<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2011-12-19 12:59:13	88480	----a-w-	C:\Windows\System32\drivers\atksgt.sys<br />
2011-12-19 12:59:12	46400	----a-w-	C:\Windows\System32\drivers\lirsgt.sys<br />
2011-12-18 12:51:54	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2011-12-10 15:24:08	23152	----a-w-	C:\Windows\System32\drivers\mbam.sys<br />
2011-11-28 18:01:25	41184	----a-w-	C:\Windows\avastSS.scr<br />
2011-11-28 17:54:06	591192	----a-w-	C:\Windows\System32\drivers\aswSnx.sys<br />
2011-11-28 17:52:11	66904	----a-w-	C:\Windows\System32\drivers\aswMonFlt.sys<br />
2011-11-24 04:52:09	3145216	----a-w-	C:\Windows\System32\win32k.sys<br />
2011-11-15 14:29:56	270720	------w-	C:\Windows\System32\MpSigStub.exe<br />
2011-11-05 05:41:43	1188864	----a-w-	C:\Windows\System32\wininet.dll<br />
2011-11-05 04:35:00	981504	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2011-11-05 03:32:47	1638912	----a-w-	C:\Windows\System32\mshtml.tlb<br />
2011-11-05 02:48:51	1638912	----a-w-	C:\Windows\SysWow64\mshtml.tlb<br />
2011-10-26 05:21:20	43520	----a-w-	C:\Windows\System32\csrsrv.dll<br />
2011-10-24 14:29:02	94208	----a-w-	C:\Windows\SysWow64\QuickTimeVR.qtx<br />
2011-10-24 14:29:02	69632	----a-w-	C:\Windows\SysWow64\QuickTime.qts<br />
2011-10-15 06:31:56	723456	----a-w-	C:\Windows\System32\EncDec.dll<br />
2011-10-15 05:38:59	534528	----a-w-	C:\Windows\SysWow64\EncDec.dll<br />
.<br />
============= FINISH: 19:15:36.56 ===============<br />
<br />
<br />
<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 20/05/2011 15:28:21<br />
System Uptime: 07/01/2012 18:18:06 (1 hours ago)<br />
.<br />
Motherboard: CLEVO CO.                        |  | W150HRM                         <br />
Processor: Intel&reg; Core&#153; i5-2520M CPU @ 2.50GHz | SOCKET 0 | 2501/100mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 244 GiB total, 55.841 GiB free.<br />
D: is CDROM ()<br />
E: is FIXED (NTFS) - 454 GiB total, 365.037 GiB free.<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP175: 01/01/2012 17:44:14 - IObit Uninstaller restore point<br />
RP176: 01/01/2012 18:02:30 - Windows Modules Installer<br />
RP177: 03/01/2012 11:20:37 - IObit Uninstaller restore point<br />
RP178: 07/01/2012 17:01:22 - IObit Uninstaller restore point<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Reader 8.3.1<br />
Advanced SystemCare 5<br />
Apple Application Support<br />
Apple Software Update<br />
avast! Free Antivirus<br />
BBC iPlayer Desktop<br />
BisonCam<br />
BitTorrent<br />
ChiconyCam<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
Crysis® 2<br />
D3DX10<br />
Dawn of War - Soulstorm<br />
DVD Decrypter (Remove Only)<br />
DVD Shrink 3.2<br />
DVDFab 8.1.3.8 (09/12/2011) Qt<br />
Empire: Total War<br />
Forsaken World <br />
Futuremark SystemInfo<br />
Game Booster 3<br />
GTK2-Runtime<br />
Hamster Free Video Converter<br />
Hotkey 3.3023<br />
Intel&reg; Management Engine Components<br />
Intel&reg; Processor Graphics<br />
Java Auto Updater<br />
Java&#153; 6 Update 26<br />
JMicron Ethernet Adapter NDIS Driver<br />
JMicron Flash Media Controller Driver<br />
Junk Mail filter update<br />
Malwarebytes Anti-Malware version 1.60.0.1800<br />
Mesh Runtime<br />
Messenger Companion<br />
Microsoft Office 2010<br />
Microsoft Office Click-to-Run 2010<br />
Microsoft Office Starter 2010 - English<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU&#93;<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Mount&amp;Blade With Fire and Sword<br />
Mozilla Firefox 8.0.1 (x86 en-GB)<br />
MSVCRT<br />
MSVCRT_amd64<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
MSXML 4.0 SP2 Parser and SDK<br />
Napoleon: Total War<br />
Nero Burning ROM 10<br />
Nero BurningROM 10 Help (CHM)<br />
Nero BurnRights 10 Help (CHM)<br />
Nero Control Center 10<br />
Nero ControlCenter 10 Help (CHM)<br />
Nero Core Components 10<br />
NVIDIA 3D Vision Controller Driver<br />
NVIDIA PhysX<br />
OLYMPUS Master 2<br />
Portal<br />
QuickTime<br />
Realtek High Definition Audio Driver<br />
REALTEK Wireless LAN Driver<br />
Renesas Electronics USB 3.0 Host Controller Driver<br />
RGSS-RTP Standard<br />
RPGXP<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Sid Meier's Civilization V - Demo<br />
Smart Defrag 2<br />
SoulSeek 157 NS 13e<br />
Steam<br />
System Requirements Lab<br />
System Requirements Lab CYRI<br />
The Witcher<br />
Total War: SHOGUN 2 Demo<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
VLC media player 1.1.11<br />
Waves Demo<br />
WebCam Installer<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Installer<br />
Windows Live Mail<br />
Windows Live Mesh<br />
Windows Live Mesh ActiveX Control for Remote Connections<br />
Windows Live Messenger<br />
Windows Live Messenger Companion Core<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
WinZip 15.5<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
06/01/2012 11:01:27, Error: Service Control Manager [7009&#93;  - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.<br />
06/01/2012 11:01:27, Error: Service Control Manager [7000&#93;  - The Steam Client Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
.<br />
==== End Of File ===========================<br />
<br />
<br />
<br />
<br />
thanks for any help, Ralph]]></description>
			<content:encoded><![CDATA[I just got infected with the fake windows antivirus errr virus? It installs a fake 'virus scanner' that purports to show all the threats to your system which it will 'fix' if you submit your credit card details etc etc. It also stopped me acessing the internet- instead redirecting to register the phony antivirus software. I ran a malwarebytes scan after disconnecting from the internet (it wasn't possible before) which found 5 threats and successfully deleted them after a reboot.<br />
<br />
everything seems fairly normal now but I just wanted to check that my system was in the clear- I ran a full system scan with avast after rebooting and that found nothing...<br />
<br />
here are the dds files:<br />
<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSAMD64 <br />
Internet Explorer: 8.0.7601.17514  BrowserJavaVersion: 1.6.0_26<br />
Run by Bitey at 19:13:43 on 2012-01-07<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.8099.5242 [GMT 0:00]<br />
.<br />
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}<br />
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\wininit.exe<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe<br />
C:\Windows\system32\nvvsvc.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br />
C:\Program Files (x86)\Hotkey\PowerBiosServer.exe<br />
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe<br />
C:\Windows\system32\svchost.exe -k imgsvc<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe<br />
C:\Program Files (x86)\Steam\steam.exe<br />
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe<br />
C:\Program Files (x86)\BitTorrent\BitTorrent.exe<br />
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br />
C:\Windows\system32\wbem\unsecapp.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br />
C:\Windows\system32\svchost.exe -k bthsvcs<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe<br />
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe<br />
C:\Windows\system32\svchost.exe -k SDRSVC<br />
C:\Windows\system32\DllHost.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe<br />
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
Q:\140066.enu\Office14\WINWORDC.EXE<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\SysWOW64\cmd.exe<br />
C:\Windows\system32\conhost.exe<br />
C:\Windows\SysWOW64\cscript.exe<br />
C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.pcspecialist.co.uk/<br />
uDefault_Page_URL = hxxp://www.pcspecialist.co.uk/<br />
uInternet Settings,ProxyOverride = *.local<br />
mWinlogon: Userinit=userinit.exe,<br />
BHO: AutorunsDisabled - No File<br />
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent<br />
uRun: [Advanced SystemCare 5] "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart<br />
uRun: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe"  /MINIMIZED<br />
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"<br />
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui<br />
mRunOnce: [aswAhAScr.dll] "C:\Program Files\AVAST Software\Avast\aswRegSvr.exe" "C:\Program Files\AVAST Software\Avast\AhAScr.dll"<br />
mPolicies-explorer: NoActiveDesktop = 1 (0x1)<br />
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)<br />
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)<br />
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)<br />
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)<br />
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100<br />
TCP: Interfaces\{A23E193E-F80C-4417-91CA-00A72835A680} : DhcpNameServer = 194.168.4.100 194.168.8.100<br />
TCP: Interfaces\{A23E193E-F80C-4417-91CA-00A72835A680}\244564F4E4 : DhcpNameServer = 192.168.22.22 192.168.22.23<br />
TCP: Interfaces\{A23E193E-F80C-4417-91CA-00A72835A680}\4656661657C647 : DhcpNameServer = 194.168.4.100 192.168.123.254<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll<br />
BHO-X64: AutorunsDisabled - No File<br />
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO-X64: Java&#153; Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"<br />
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui<br />
mRunOnce-x64: [aswAhAScr.dll] "C:\Program Files\AVAST Software\Avast\aswRegSvr.exe" "C:\Program Files\AVAST Software\Avast\AhAScr.dll"<br />
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\Bitey\AppData\Roaming\Mozilla\Firefox\Profiles\9qdgkg8b.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.blackle.com/<br />
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL<br />
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll<br />
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll<br />
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --&gt; C:\Windows\system32\DRIVERS\nvpciflt.sys [?]<br />
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\system32\Drivers\SmartDefragDrive&#8203;r.sys --&gt; C:\Windows\system32\Drivers\SmartDefragDriver.sys [?]<br />
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --&gt; C:\Windows\system32\drivers\aswSnx.sys [?]<br />
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --&gt; C:\Windows\system32\drivers\aswSP.sys [?]<br />
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --&gt; C:\Windows\system32\DRIVERS\vwififlt.sys [?]<br />
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2011-12-25 494424]<br />
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --&gt; C:\Windows\system32\drivers\aswFsBlk.sys [?]<br />
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --&gt; C:\Windows\system32\drivers\aswMonFlt.sys [?]<br />
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-9-20 44768]<br />
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]<br />
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2011-12-20 2348864]<br />
R2 PowerBiosServer;PowerBiosServer;C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [2011-1-27 33792]<br />
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]<br />
R2 UNS;Intel&reg; Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe [2011-4-8 2656280]<br />
R3 IntcDAud;Intel&reg; Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --&gt; C:\Windows\system32\DRIVERS\IntcDAud.sys [?]<br />
R3 MEIx64;Intel&reg; Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --&gt; C:\Windows\system32\DRIVERS\HECIx64.sys [?]<br />
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --&gt; C:\Windows\system32\DRIVERS\nusb3hub.sys [?]<br />
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --&gt; C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]<br />
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]<br />
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\system32\DRIVERS\rtl8192Ce.sys --&gt; C:\Windows\system32\DRIVERS\rtl8192Ce.sys [?]<br />
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --&gt; C:\Windows\system32\DRIVERS\Sftfslh.sys [?]<br />
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --&gt; C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]<br />
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --&gt; C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]<br />
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --&gt; C:\Windows\system32\DRIVERS\Sftvollh.sys [?]<br />
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]<br />
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --&gt; C:\Windows\system32\DRIVERS\vwifimp.sys [?]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --&gt; C:\Windows\system32\DRIVERS\fssfltr.sys [?]<br />
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]<br />
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-12-19 135584]<br />
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --&gt; C:\Windows\system32\DRIVERS\jmcr.sys [?]<br />
S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);C:\Windows\system32\DRIVERS\JME.sys --&gt; C:\Windows\system32\DRIVERS\JME.sys [?]<br />
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-1-5 340240]<br />
S3 NETwNs64;___ Intel&reg; Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --&gt; C:\Windows\system32\DRIVERS\NETwNs64.sys [?]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --&gt; C:\Windows\system32\drivers\tsusbflt.sys [?]<br />
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --&gt; C:\Windows\system32\drivers\TsUsbGD.sys [?]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --&gt; C:\Windows\system32\Wat\WatAdminSvc.exe [?]<br />
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-07 18:20:46	69000	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1C97246F-29EA-45C9-909D-25BBF7BA02F3}\offreg.dll<br />
2012-01-07 17:23:54	--------	d-----w-	C:\Program Files (x86)\BitTorrent<br />
2012-01-07 17:22:45	--------	d-----w-	C:\Users\Bitey\AppData\Roaming\BitTorrent<br />
2012-01-05 15:41:59	--------	d-----w-	C:\Users\Bitey\AppData\Local\{1F48A284-5E85-450E-99DB-14ACD544750C}<br />
2012-01-05 15:41:47	--------	d-----w-	C:\Users\Bitey\AppData\Local\{AA6EF762-DEC7-498F-8686-EDBB9C24E9C6}<br />
2012-01-03 17:52:10	--------	d-----w-	C:\Users\Bitey\AppData\Local\{08DF3F40-3841-4896-9DB3-0BAE8A8542AB}<br />
2012-01-03 17:51:53	--------	d-----w-	C:\Users\Bitey\AppData\Local\{1980ABC5-A9A4-4365-A27D-10183E6F7EE1}<br />
2012-01-03 11:25:53	--------	d-----w-	C:\Program Files (x86)\GTK2-Runtime<br />
2012-01-03 11:11:59	--------	d-----w-	C:\Users\Bitey\AppData\Roaming\deluge<br />
2012-01-02 11:26:20	--------	d-----w-	C:\Users\Bitey\AppData\Local\{D3FE32F2-481E-46F1-A007-7F171B7FF89A}<br />
2012-01-02 11:26:04	--------	d-----w-	C:\Users\Bitey\AppData\Local\{EA8474E7-9141-4688-B015-4327E9EEA056}<br />
2011-12-31 10:49:18	--------	d-----w-	C:\Users\Bitey\AppData\Local\{0BF782FC-7068-4C80-90B4-56CD2179F491}<br />
2011-12-31 10:49:02	--------	d-----w-	C:\Users\Bitey\AppData\Local\{B7B41B3B-43D1-4F98-8BA2-FD76B441EC11}<br />
2011-12-30 11:56:02	--------	d-----w-	C:\Users\Bitey\AppData\Local\{FAB131B3-1B2E-4B6A-87D5-1B84453D3886}<br />
2011-12-30 11:55:50	--------	d-----w-	C:\Users\Bitey\AppData\Local\{DF3FA54D-25C7-45D2-BC5D-BA038EB31286}<br />
2011-12-30 11:46:41	8822856	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1C97246F-29EA-45C9-909D-25BBF7BA02F3}\mpengine.dll<br />
2011-12-29 19:33:46	--------	d-----w-	C:\Users\Bitey\AppData\Local\{88AF1506-5BE6-47FE-B6A5-35447DEBB599}<br />
2011-12-29 19:33:35	--------	d-----w-	C:\Users\Bitey\AppData\Local\{70FEF605-A015-479A-95C2-6DAAC3E8982A}<br />
2011-12-29 14:23:47	626688	----a-w-	C:\Program Files (x86)\Mozilla Firefox\msvcr80.dll<br />
2011-12-29 14:23:47	548864	----a-w-	C:\Program Files (x86)\Mozilla Firefox\msvcp80.dll<br />
2011-12-29 14:23:47	479232	----a-w-	C:\Program Files (x86)\Mozilla Firefox\msvcm80.dll<br />
2011-12-29 14:23:47	43992	----a-w-	C:\Program Files (x86)\Mozilla Firefox\mozutils.dll<br />
2011-12-28 09:36:14	--------	d-----w-	C:\Users\Bitey\AppData\Local\{06CBEDF2-5E76-4E40-B5B2-66BC6DD07C07}<br />
2011-12-28 09:35:52	--------	d-----w-	C:\Users\Bitey\AppData\Local\{8F14D8D3-825E-4FD6-AF4B-159078505D73}<br />
2011-12-26 14:16:38	--------	d-----w-	C:\Users\Bitey\AppData\Local\{DF18B29D-9995-4739-B097-75423B6966D9}<br />
2011-12-26 14:16:20	--------	d-----w-	C:\Users\Bitey\AppData\Local\{216AEFD2-F7E9-4181-85D9-953D563EF24A}<br />
2011-12-26 10:39:16	--------	d-----w-	C:\Program Files (x86)\DVD Shrink<br />
2011-12-25 21:06:08	--------	d-----w-	C:\Program Files (x86)\DVD Decrypter<br />
2011-12-25 21:03:40	--------	d-----w-	C:\Users\Bitey\AppData\Local\Ilivid Player<br />
2011-12-25 21:03:14	--------	d-----w-	C:\Program Files (x86)\iLivid<br />
2011-12-25 21:02:53	--------	d-----w-	C:\Users\Bitey\AppData\Local\PackageAware<br />
2011-12-25 20:31:30	--------	d-----w-	C:\Program Files (x86)\Elaborate Bytes<br />
2011-12-25 20:23:52	--------	d-----w-	C:\Program Files (x86)\SlySoft<br />
2011-12-25 18:18:28	--------	d-----w-	C:\Program Files (x86)\DVDFab 8 Qt<br />
2011-12-25 11:55:20	22872	----a-w-	C:\Windows\System32\RegistryDefragBootTime.exe<br />
2011-12-25 11:45:11	27992	----a-w-	C:\Windows\System32\SmartDefragBootTime.exe<br />
2011-12-25 11:45:11	17720	----a-w-	C:\Windows\System32\drivers\SmartDefragDriver.sys<br />
2011-12-25 11:43:45	--------	d-----w-	C:\Users\Bitey\AppData\Roaming\IObit<br />
2011-12-25 11:40:49	--------	d-----w-	C:\ProgramData\IObit<br />
2011-12-25 11:40:49	--------	d-----w-	C:\Program Files (x86)\IObit<br />
2011-12-25 10:01:50	--------	d-----w-	C:\Users\Bitey\AppData\Local\{BE7533B5-3769-47DB-92C3-86327EF3394E}<br />
2011-12-25 10:01:36	--------	d-----w-	C:\Users\Bitey\AppData\Local\{41BC883D-14CF-475B-B423-177E0DE04620}<br />
2011-12-24 09:16:41	--------	d-----w-	C:\Users\Bitey\AppData\Local\{63175224-73F0-4BBA-8D78-0A1FC24D5D50}<br />
2011-12-24 09:16:21	--------	d-----w-	C:\Users\Bitey\AppData\Local\{E188D8A0-7F33-474D-9C74-596C74F7188D}<br />
2011-12-23 12:56:35	--------	d-----w-	C:\Users\Bitey\AppData\Local\{1AA89AAF-288A-43A1-92C1-D00DDBEA881C}<br />
2011-12-23 12:56:23	--------	d-----w-	C:\Users\Bitey\AppData\Local\{9C74F76E-C4FA-492D-9852-4A461CE1256F}<br />
2011-12-22 18:29:16	--------	d-----w-	C:\Users\Bitey\AppData\Local\{19C039F7-6C8E-44C4-9ED9-685538A6AD3E}<br />
2011-12-22 18:29:00	--------	d-----w-	C:\Users\Bitey\AppData\Local\{FD15EEBE-5592-4714-8149-10224DDED0C0}<br />
2011-12-21 17:41:30	--------	d-----w-	C:\Program Files (x86)\Hamster Soft<br />
2011-12-21 17:19:57	--------	d-----w-	C:\Program Files (x86)\Nero<br />
2011-12-21 10:12:24	--------	d-----w-	C:\Program Files (x86)\Enterbrain<br />
2011-12-21 09:20:34	--------	d-----w-	C:\Users\Bitey\AppData\Local\{2089122D-1B73-4DB4-91D9-AA96BFB08094}<br />
2011-12-21 09:20:20	--------	d-----w-	C:\Users\Bitey\AppData\Local\{D7FC9A58-BBC8-4D56-98F3-C6A720F33481}<br />
2011-12-20 19:59:56	--------	d-----w-	C:\Users\Bitey\AppData\Local\{8F6AFA77-D5A6-4529-BCC4-50D446D03A62}<br />
2011-12-20 19:59:44	--------	d-----w-	C:\Users\Bitey\AppData\Local\{723ECBCD-5B6B-4B0C-B893-DF7FDF5B5C03}<br />
2011-12-20 19:30:08	--------	d-----w-	C:\Windows\SysWow64\NV<br />
2011-12-20 19:30:08	--------	d-----w-	C:\Windows\System32\NV<br />
2011-12-20 19:28:06	889664	----a-w-	C:\Windows\System32\nvvsvc.exe<br />
2011-12-20 19:28:06	839488	----a-w-	C:\Windows\System32\nv3dappshext.dll<br />
2011-12-20 19:28:06	63296	----a-w-	C:\Windows\System32\nvshext.dll<br />
2011-12-20 19:28:06	6004544	----a-w-	C:\Windows\System32\nvcpl.dll<br />
2011-12-20 19:28:06	55616	----a-w-	C:\Windows\System32\nv3dappshextr.dll<br />
2011-12-20 19:28:06	3028800	----a-w-	C:\Windows\System32\nvsvc64.dll<br />
2011-12-20 19:28:06	2562368	----a-w-	C:\Windows\System32\nvsvcr.dll<br />
2011-12-20 19:28:06	2417322	----a-w-	C:\Windows\System32\nvcoproc.bin<br />
2011-12-20 19:28:06	118080	----a-w-	C:\Windows\System32\nvmctray.dll<br />
2011-12-20 19:27:26	--------	d-----w-	C:\ProgramData\NVIDIA Corporation<br />
2011-12-19 22:55:48	--------	d-----w-	C:\Users\Bitey\AppData\Local\{82B665DA-EA34-4A7E-BBA4-19936374D528}<br />
2011-12-19 22:55:31	--------	d-----w-	C:\Users\Bitey\AppData\Local\{51079892-F4F9-4A1D-ABBE-30EAD9D95759}<br />
2011-12-19 17:50:11	--------	d-----w-	C:\Program Files (x86)\Futuremark<br />
2011-12-19 09:24:45	--------	d-----w-	C:\Users\Bitey\AppData\Local\{0DA9A610-74BD-4554-A411-4C7DEEBDE052}<br />
2011-12-19 09:24:25	--------	d-----w-	C:\Users\Bitey\AppData\Local\{64FBAAF2-454A-44D5-BAF7-44156641CCC9}<br />
2011-12-18 16:16:54	--------	d-----w-	C:\Program Files (x86)\Common Files\Enterbrain<br />
2011-12-18 10:44:03	--------	d-----w-	C:\Windows\SysWow64\Adobe<br />
2011-12-18 10:02:57	2048	----a-w-	C:\Windows\SysWow64\tzres.dll<br />
2011-12-18 10:02:57	2048	----a-w-	C:\Windows\System32\tzres.dll<br />
2011-12-18 10:02:16	--------	d-----w-	C:\Users\Bitey\AppData\Local\{7C1BF810-000F-411B-9EBB-19B9F7CC2592}<br />
2011-12-18 10:01:37	--------	d-----w-	C:\Users\Bitey\AppData\Local\{81ED20DB-CECB-4270-ADC2-B67400FB38CB}<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2011-12-19 12:59:13	88480	----a-w-	C:\Windows\System32\drivers\atksgt.sys<br />
2011-12-19 12:59:12	46400	----a-w-	C:\Windows\System32\drivers\lirsgt.sys<br />
2011-12-18 12:51:54	414368	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2011-12-10 15:24:08	23152	----a-w-	C:\Windows\System32\drivers\mbam.sys<br />
2011-11-28 18:01:25	41184	----a-w-	C:\Windows\avastSS.scr<br />
2011-11-28 17:54:06	591192	----a-w-	C:\Windows\System32\drivers\aswSnx.sys<br />
2011-11-28 17:52:11	66904	----a-w-	C:\Windows\System32\drivers\aswMonFlt.sys<br />
2011-11-24 04:52:09	3145216	----a-w-	C:\Windows\System32\win32k.sys<br />
2011-11-15 14:29:56	270720	------w-	C:\Windows\System32\MpSigStub.exe<br />
2011-11-05 05:41:43	1188864	----a-w-	C:\Windows\System32\wininet.dll<br />
2011-11-05 04:35:00	981504	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2011-11-05 03:32:47	1638912	----a-w-	C:\Windows\System32\mshtml.tlb<br />
2011-11-05 02:48:51	1638912	----a-w-	C:\Windows\SysWow64\mshtml.tlb<br />
2011-10-26 05:21:20	43520	----a-w-	C:\Windows\System32\csrsrv.dll<br />
2011-10-24 14:29:02	94208	----a-w-	C:\Windows\SysWow64\QuickTimeVR.qtx<br />
2011-10-24 14:29:02	69632	----a-w-	C:\Windows\SysWow64\QuickTime.qts<br />
2011-10-15 06:31:56	723456	----a-w-	C:\Windows\System32\EncDec.dll<br />
2011-10-15 05:38:59	534528	----a-w-	C:\Windows\SysWow64\EncDec.dll<br />
.<br />
============= FINISH: 19:15:36.56 ===============<br />
<br />
<br />
<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 20/05/2011 15:28:21<br />
System Uptime: 07/01/2012 18:18:06 (1 hours ago)<br />
.<br />
Motherboard: CLEVO CO.                        |  | W150HRM                         <br />
Processor: Intel&reg; Core&#153; i5-2520M CPU @ 2.50GHz | SOCKET 0 | 2501/100mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 244 GiB total, 55.841 GiB free.<br />
D: is CDROM ()<br />
E: is FIXED (NTFS) - 454 GiB total, 365.037 GiB free.<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP175: 01/01/2012 17:44:14 - IObit Uninstaller restore point<br />
RP176: 01/01/2012 18:02:30 - Windows Modules Installer<br />
RP177: 03/01/2012 11:20:37 - IObit Uninstaller restore point<br />
RP178: 07/01/2012 17:01:22 - IObit Uninstaller restore point<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe AIR<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Reader 8.3.1<br />
Advanced SystemCare 5<br />
Apple Application Support<br />
Apple Software Update<br />
avast! Free Antivirus<br />
BBC iPlayer Desktop<br />
BisonCam<br />
BitTorrent<br />
ChiconyCam<br />
Cisco EAP-FAST Module<br />
Cisco LEAP Module<br />
Cisco PEAP Module<br />
Crysis® 2<br />
D3DX10<br />
Dawn of War - Soulstorm<br />
DVD Decrypter (Remove Only)<br />
DVD Shrink 3.2<br />
DVDFab 8.1.3.8 (09/12/2011) Qt<br />
Empire: Total War<br />
Forsaken World <br />
Futuremark SystemInfo<br />
Game Booster 3<br />
GTK2-Runtime<br />
Hamster Free Video Converter<br />
Hotkey 3.3023<br />
Intel&reg; Management Engine Components<br />
Intel&reg; Processor Graphics<br />
Java Auto Updater<br />
Java&#153; 6 Update 26<br />
JMicron Ethernet Adapter NDIS Driver<br />
JMicron Flash Media Controller Driver<br />
Junk Mail filter update<br />
Malwarebytes Anti-Malware version 1.60.0.1800<br />
Mesh Runtime<br />
Messenger Companion<br />
Microsoft Office 2010<br />
Microsoft Office Click-to-Run 2010<br />
Microsoft Office Starter 2010 - English<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Mount&amp;Blade With Fire and Sword<br />
Mozilla Firefox 8.0.1 (x86 en-GB)<br />
MSVCRT<br />
MSVCRT_amd64<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
MSXML 4.0 SP2 Parser and SDK<br />
Napoleon: Total War<br />
Nero Burning ROM 10<br />
Nero BurningROM 10 Help (CHM)<br />
Nero BurnRights 10 Help (CHM)<br />
Nero Control Center 10<br />
Nero ControlCenter 10 Help (CHM)<br />
Nero Core Components 10<br />
NVIDIA 3D Vision Controller Driver<br />
NVIDIA PhysX<br />
OLYMPUS Master 2<br />
Portal<br />
QuickTime<br />
Realtek High Definition Audio Driver<br />
REALTEK Wireless LAN Driver<br />
Renesas Electronics USB 3.0 Host Controller Driver<br />
RGSS-RTP Standard<br />
RPGXP<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Sid Meier's Civilization V - Demo<br />
Smart Defrag 2<br />
SoulSeek 157 NS 13e<br />
Steam<br />
System Requirements Lab<br />
System Requirements Lab CYRI<br />
The Witcher<br />
Total War: SHOGUN 2 Demo<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
VLC media player 1.1.11<br />
Waves Demo<br />
WebCam Installer<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live Installer<br />
Windows Live Mail<br />
Windows Live Mesh<br />
Windows Live Mesh ActiveX Control for Remote Connections<br />
Windows Live Messenger<br />
Windows Live Messenger Companion Core<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
WinZip 15.5<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
06/01/2012 11:01:27, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.<br />
06/01/2012 11:01:27, Error: Service Control Manager [7000]  - The Steam Client Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
.<br />
==== End Of File ===========================<br />
<br />
<br />
<br />
<br />
thanks for any help, Ralph]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Something has my computer going crazy]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-something-has-my-computer-going-crazy</link>
			<pubDate>Sat, 07 Jan 2012 01:17:48 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-something-has-my-computer-going-crazy</guid>
			<description><![CDATA[I had a couple of major viruses that totally destroyed my computer. My hard drive was replaced, two days ago, and some weird things are still happening. I try to use programs and I am told they are not legitimate win32 applications (like Microsoft Office) and there isnt enough space to open a simple file or email. My computer keeps freezing and it is running extremely slow at times. Also, when I am modifying documents it tells me I don't have access or permission to save the file. I ran antivirus in safe mode and it found <br />
Disabled.SecurityCenterOption<br />
	HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#FIREWALLDISABLENOTIFY<br />
<br />
The program said it was high risk. Please help....here are my dds logs<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.6001.18702<br />
Run by csnelson at 20:05:01 on 2012-01-06<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1015.497 [GMT -5:00&#93;<br />
.<br />
AV: Trend Micro OfficeScan Antivirus *Disabled/Outdated* {CBD502AB-690F-41FF-97C6-0A4A8A8064F0}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {81CB9BD4-C366-49EE-AA6D-44256FDA0462}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {4D306A9F-9175-4EE6-BAC0-193286B12F1C}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {91B8283B-1122-440B-BCD8-0A367B4F89E4}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {F42D1785-3F4C-46CC-B6B0-0DFD4B5F9E89}<br />
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}<br />
FW: Symantec Client Firewall *Enabled* <br />
FW: Trend Micro Personal Firewall *Disabled* <br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCservice.exe<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE<br />
C:\Program Files\Dell\KACE\AMPAgent.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe<br />
C:\WINDOWS\system32\IFXSPMGT.exe<br />
C:\WINDOWS\system32\IFXTCS.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe<br />
C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE<br />
C:\Program Files\TightVNC\WinVNC.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe<br />
C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCgui.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\eInstruction\Device Manager\Launch.exe<br />
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.clayton.k12.ga.us/<br />
uInternet Settings,ProxyOverride = evserver01.clayton.k12.ga.us;SEVSERVER01;evserver02.clayton.k12.ga.us;SEVSERVER02;evserver03.clayton.k12.ga.us;SEVSERVER03;<br />
mWinlogon: Userinit=c:\windows\system32\KUsrInit.exe,<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL<br />
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\19.2.0.10\ips\IPSBHO.DLL<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
uRun: [ctfmon.exe&#93; c:\windows\system32\ctfmon.exe<br />
uRun: [updateMgr&#93; c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0<br />
uRun: [SUPERAntiSpyware&#93; c:\program files\superantispyware\SUPERAntiSpyware.exe<br />
uRunOnce: [Shockwave Updater&#93; c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; InfoPath.2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.explorelearning.com/index.cfm?method=cResource.dspView&amp;ResourceID=129&amp;ClassID=2088514"<br />
mRun: [igfxtray&#93; c:\windows\system32\igfxtray.exe<br />
mRun: [igfxhkcmd&#93; c:\windows\system32\hkcmd.exe<br />
mRun: [igfxpers&#93; c:\windows\system32\igfxpers.exe<br />
mRun: [SynTPEnh&#93; c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [SoundMAXPnP&#93; c:\program files\analog devices\core\smax4pnp.exe<br />
mRun: [SoundMAX&#93; c:\program files\analog devices\soundmax\Smax4.exe /tray<br />
mRun: [AGRSMMSG&#93; AGRSMMSG.exe<br />
mRun: [QlbCtrl&#93; %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
mRun: [IAAnotif&#93; c:\program files\intel\intel matrix storage manager\iaanotif.exe<br />
mRun: [PTHOSTTR&#93; c:\program files\hpq\hp protecttools security manager\PTHOSTTR.EXE /Start<br />
mRun: [Client Access Service&#93; "c:\program files\ibm\client access\cwbsvstr.exe"<br />
mRun: [WatchDog&#93; c:\program files\intervideo\dvd check\DVDCheck.exe<br />
mRun: [DLA&#93; c:\windows\system32\dla\DLACTRLW.EXE<br />
mRun: [Adobe Reader Speed Launcher&#93; "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"<br />
mRun: [SunJavaUpdateSched&#93; "c:\program files\common files\java\java update\jusched.exe"<br />
mRun: [QuickTime Task&#93; "c:\program files\quicktime\qttask.exe" -atboottime<br />
mRun: [Trend OfficeScan ImageSetup&#93; "C:\ImgSetup.exe" "/0017083fd604" -HideWindow<br />
mRun: [CiscoCSSCgui&#93; "c:\program files\cisco\cisco secure services client\Cisco_SSCgui.exe"<br />
mRun: [<NO NAME>&#93; <br />
mRun: [OfficeScanNT Monitor&#93; "c:\program files\trend micro\officescan client\pccntmon.exe" -HideWindow<br />
mRun: [Client Access PWD Cache&#93; "c:\program files\ibm\client access\cwblogon.exe" Cpu1 /u QCASignOn /p pcsupport<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\einstr~1.lnk - c:\program files\einstruction\device manager\Launch.exe<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: Send To &amp;Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
Trusted Zone: k12.ga.us\*.clayton<br />
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab<br />
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://media3.keytrain.com/player/IE/awswaxd.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab<br />
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab<br />
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL<br />
Notify: csscsso - csscsso.dll<br />
Notify: IfxWlxEN - IfxWlxEN.dll<br />
Notify: igfxcui - igfxdev.dll<br />
Notify: kwinhook - kwinhook.dll<br />
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\csnelson\application data\mozilla\firefox\profiles\53ic4riv.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.clayton.k12.ga.us/<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768&#93;<br />
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880&#93;<br />
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664&#93;<br />
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608&#93;<br />
R2 AMPAgent;Dell KACE Agent;c:\program files\dell\kace\AMPAgent.exe [2011-9-21 2753640&#93;<br />
R2 Cisco Secure Services Client;Cisco Secure Services Client;c:\program files\cisco\cisco secure services client\Cisco_SSCservice.exe [2008-10-7 1232896&#93;<br />
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2011-6-23 51792&#93;<br />
R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\TmXpflt.sys [2009-9-30 262416&#93;<br />
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\TmPreflt.sys [2009-9-30 36624&#93;<br />
R2 VNC Server;VNC Server;c:\program files\tightvnc\WinVNC.exe [2003-11-13 469504&#93;<br />
R3 CiscoSSD;Cisco Secure Services Miniport Driver;c:\windows\system32\drivers\css_drv.sys [2011-6-23 42240&#93;<br />
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-8-31 88192&#93;<br />
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005-10-21 36352&#93;<br />
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2010-1-4 340496&#93;<br />
R3 TmProxy;OfficeScan NT Proxy Service;c:\program files\trend micro\officescan client\TmProxy.exe [2009-7-15 689416&#93;<br />
S3 TmPfw;OfficeScan NT Firewall;c:\program files\trend micro\officescan client\TmPfw.exe [2009-7-15 497008&#93;<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-06 17:37:51	--------	d-----w-	c:\documents and settings\csnelson\application data\SUPERAntiSpyware.com<br />
2012-01-06 17:37:26	--------	d-----w-	c:\program files\SUPERAntiSpyware<br />
2012-01-06 17:37:26	--------	d-----w-	c:\documents and settings\all users\application data\SUPERAntiSpyware.com<br />
2012-01-05 21:08:59	--------	d-----w-	c:\program files\Turning Technologies<br />
2012-01-05 21:06:55	--------	d-----w-	c:\documents and settings\csnelson\local settings\application data\Mozilla<br />
2012-01-04 23:23:37	--------	d-----w-	c:\documents and settings\all users\application data\Norton<br />
2012-01-04 23:23:25	--------	d-----w-	c:\documents and settings\all users\application data\NortonInstaller<br />
2012-01-04 22:54:56	--------	d-----w-	c:\documents and settings\all users\application data\Kaspersky Lab Setup Files<br />
2012-01-04 22:50:55	--------	d-----w-	c:\windows\system32\LogFiles<br />
2012-01-04 19:51:07	--------	d-----w-	c:\documents and settings\csnelson\application data\Turning Technologies<br />
2012-01-04 18:02:37	52288	----a-r-	c:\documents and settings\csnelson\application data\microsoft\installer\{81baf04c-52d6-44ed-a516-da12e97886fb}\ARPPRODUCTICON.exe<br />
2012-01-04 17:28:50	102400	----a-w-	c:\windows\system32\tsccvid.dll<br />
2012-01-04 17:28:50	--------	d-----w-	c:\documents and settings\csnelson\local settings\application data\Adobe<br />
2012-01-04 17:26:48	--------	d-----w-	c:\documents and settings\csnelson\application data\eInstruction<br />
2012-01-04 17:22:56	--------	d-----w-	c:\program files\eInstruction<br />
2012-01-04 17:22:49	--------	d--h--w-	c:\documents and settings\csnelson\InstallAnywhere<br />
2012-01-04 17:05:49	--------	d-----w-	c:\documents and settings\all users\application data\Turning Technologies<br />
2012-01-04 17:04:19	311296	----a-w-	c:\windows\system32\lexlog.dll<br />
2012-01-04 17:04:19	--------	d-----w-	c:\program files\Dell_HostCD<br />
2012-01-04 17:04:09	131072	----a-w-	c:\windows\system32\LEXDRVX.DLL<br />
2012-01-04 17:04:09	106496	----a-w-	c:\windows\system32\LEXCFI.DLL<br />
2012-01-04 17:04:06	41984	----a-w-	c:\windows\system32\DKAAP2BJ.DLL<br />
2012-01-04 17:04:04	--------	d-----w-	C:\1700<br />
2012-01-04 16:50:34	--------	d-----w-	c:\program files\RM Content Access Tool<br />
2012-01-04 16:47:11	--------	d-----w-	c:\documents and settings\all users\application data\Research Machines<br />
2012-01-04 16:47:03	--------	d-----w-	c:\program files\directx<br />
2012-01-04 16:45:55	--------	d-----w-	c:\program files\Research Machines<br />
2012-01-04 16:45:31	--------	d-----w-	C:\STARRead<br />
2012-01-04 16:42:46	--------	d-----w-	C:\AccReadr<br />
2012-01-04 16:37:37	--------	d-----w-	c:\program files\Enterprise Vault<br />
2012-01-04 16:37:25	--------	d-----w-	c:\program files\Dell<br />
2012-01-04 16:37:23	--------	d-----w-	c:\documents and settings\all users\Dell<br />
2012-01-04 16:26:41	745472	----a-w-	c:\windows\system32\NETw4c32.dll<br />
2012-01-04 16:26:40	2777088	----a-w-	c:\windows\system32\NETw4r32.dll<br />
2012-01-04 16:26:40	2236544	----a-w-	c:\windows\system32\drivers\NETw4x32.sys<br />
2012-01-04 16:24:23	--------	d-----w-	c:\documents and settings\all users\application data\Renaissance Learning<br />
.<br />
==================== Find3M  ====================<br />
.<br />
.<br />
============= FINISH: 20:05:44.84 ===============<hr />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft Windows XP Professional<br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 1/4/2012 10:21:39 AM<br />
System Uptime: 1/6/2012 8:00:38 PM (0 hours ago)<br />
.<br />
Motherboard: Hewlett-Packard |  | 30AA<br />
Processor: Genuine Intel&reg; CPU           T2500  @ 2.00GHz | U10 | 1995/166mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 75 GiB total, 58.167 GiB free.<br />
D: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
No restore point in system.<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Acapela Speech Engine for Easiteach (US)<br />
Accelerated Reader 6.3<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Reader 9<br />
Adobe Shockwave Player 11<br />
Agere Systems HDA Modem<br />
Broadcom NetXtreme Ethernet Controller<br />
Cisco Secure Services Client<br />
Dell KACE Agent<br />
Dell Printer Software Uninstall<br />
DeviceManager<br />
Easiteach Geography Licence<br />
Easiteach Literacy Licence<br />
Easiteach Maths Licence<br />
Easiteach Science Licence<br />
Easiteach Starter Licence<br />
Fingerprint Sensor Minimum Install<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Windows XP (KB954550-v5)<br />
HP Embedded Security for ProtectTools<br />
HP Integrated Module with Bluetooth wireless technology<br />
HP ProtectTools Security Manager 2.00 C3<br />
HP Quick Launch Buttons 6.00 D2<br />
IBM iSeries Access for Windows<br />
Intel Matrix Storage Manager<br />
Intel&reg; Graphics Media Accelerator Driver<br />
InterVideo DVD Check<br />
InterVideo WinDVD<br />
J2SE Runtime Environment 5.0 Update 4<br />
Java Auto Updater<br />
Java&#153; 6 Update 26<br />
Java&#153; SE Runtime Environment 6 Update 1<br />
Microsoft .NET Framework 2.0 Service Pack 2<br />
Microsoft .NET Framework 3.0 Service Pack 2<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Internationalized Domain Names Mitigation APIs<br />
Microsoft National Language Support Downlevel APIs<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office Access MUI (English) 2007<br />
Microsoft Office Access Setup Metadata MUI (English) 2007<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office FrontPage 2003<br />
Microsoft Office InfoPath MUI (English) 2007<br />
Microsoft Office Outlook MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office Professional Plus 2007<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Publisher MUI (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Software Update for Web Folders  (English) 12<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Mozilla Firefox 7.0.1 (x86 en-US)<br />
Norton AntiVirus<br />
QuickTime<br />
RM Content Access Tool<br />
RM Easiteach<br />
RM Easiteach Resources (North America)<br />
RM Easiteach Secondary Content<br />
Security Update for 2007 Microsoft Office System (KB2277947)<br />
Security Update for 2007 Microsoft Office System (KB969559)<br />
Security Update for 2007 Microsoft Office System (KB976321)<br />
Security Update for 2007 Microsoft Office System (KB982312)<br />
Security Update for 2007 Microsoft Office System (KB982331)<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for Microsoft Office Access 2007 (KB979440)<br />
Security Update for Microsoft Office Excel 2007 (KB982308)<br />
Security Update for Microsoft Office InfoPath 2007 (KB979441)<br />
Security Update for Microsoft Office Outlook 2007 (KB980376)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB982158)<br />
Security Update for Microsoft Office Publisher 2007 (KB982124)<br />
Security Update for Microsoft Office system 2007 (972581)<br />
Security Update for Microsoft Office system 2007 (KB974234)<br />
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)<br />
Security Update for Microsoft Office Word 2007 (KB2251419)<br />
Security Update for Windows Media Player (KB911564)<br />
Security Update for Windows Media Player 9 (KB917734)<br />
Security Update for Windows XP (KB913433)<br />
SmartWeb Classroom Management System (SwCMS)<br />
Sonic Audio Module<br />
Sonic Copy Module<br />
Sonic Data Module<br />
Sonic DLA<br />
Sonic Express Labeler<br />
Sonic Update Manager<br />
SoundMAX<br />
Star Reading<br />
Symantec Enterprise Vault HTTP-only Outlook Add-In<br />
Synaptics Pointing Device Driver<br />
Texas Instruments PCIxx21/x515/xx12 drivers.<br />
TIPCI<br />
Trend Micro OfficeScan Client<br />
TurningPoint 2008<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Outlook 2007 Junk Email Filter (KB2536413)<br />
Update for Windows XP (KB951072-v2)<br />
WebFldrs XP<br />
Windows Driver Package - Intel (NETw4x32) net  (10/31/2007 11.5.0.34)<br />
Windows Driver Package - Intel (w29n51) net  (07/25/2007 9.0.4.37)<br />
Windows Driver Package - Intel net  (10/31/2007 11.5.0.34)<br />
Windows Internet Explorer 7<br />
Windows Internet Explorer 8<br />
Windows XP Service Pack 3<br />
Workspace<br />
Workspace Content<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
1/6/2012 1:04:13 PM, error: Service Control Manager [7026&#93;  - The following boot-start or system-start driver(s) failed to load:  Fips intelppm SASDIFSV SASKUTIL tmtdi<br />
1/5/2012 7:45:34 AM, error: SRTSP [4&#93;  - <br />
1/5/2012 7:15:58 AM, error: DCOM [10016&#93;  - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18).  This security permission can be modified using the Component Services administrative tool.<br />
1/4/2012 9:08:56 PM, error: NETLOGON [5719&#93;  - No Domain Controller is available for domain CLAYTON due to the following:  There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.<br />
1/4/2012 9:07:34 PM, error: DCOM [10005&#93;  - DCOM got error "%1084" attempting to start the service IFXSpMgtSrv with arguments "-Service" in order to run the server: {FBCD9C6A-72CB-47BB-99DD-2317551491DE}<br />
1/4/2012 9:07:34 PM, error: DCOM [10005&#93;  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
1/4/2012 8:30:17 PM, error: DCOM [10005&#93;  - DCOM got error "%1084" attempting to start the service IFXSpMgtSrv with arguments "-Service" in order to run the server: {FBCD9C66-72CB-47BB-99DD-2317551491DE}<br />
1/4/2012 8:29:40 PM, error: Service Control Manager [7026&#93;  - The following boot-start or system-start driver(s) failed to load:  BHDrvx86 ccSet_NAV eeCtrl Fips intelppm SRTSPX SymIRON SYMTDI tmtdi<br />
1/4/2012 5:33:53 PM, error: Dhcp [1002&#93;  - The IP address lease 10.29.20.194 for the Network Card with network address 0018DE803BA1 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).<br />
1/4/2012 10:26:07 AM, error: Service Control Manager [7022&#93;  - The Cisco Secure Services Client service hung on starting.<br />
.<br />
==== End Of File ===========================]]></description>
			<content:encoded><![CDATA[I had a couple of major viruses that totally destroyed my computer. My hard drive was replaced, two days ago, and some weird things are still happening. I try to use programs and I am told they are not legitimate win32 applications (like Microsoft Office) and there isnt enough space to open a simple file or email. My computer keeps freezing and it is running extremely slow at times. Also, when I am modifying documents it tells me I don't have access or permission to save the file. I ran antivirus in safe mode and it found <br />
Disabled.SecurityCenterOption<br />
	HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#FIREWALLDISABLENOTIFY<br />
<br />
The program said it was high risk. Please help....here are my dds logs<br />
<br />
.<br />
DDS (Ver_2011-08-26.01) - NTFSx86 <br />
Internet Explorer: 8.0.6001.18702<br />
Run by csnelson at 20:05:01 on 2012-01-06<br />
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1015.497 [GMT -5:00]<br />
.<br />
AV: Trend Micro OfficeScan Antivirus *Disabled/Outdated* {CBD502AB-690F-41FF-97C6-0A4A8A8064F0}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {81CB9BD4-C366-49EE-AA6D-44256FDA0462}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {4D306A9F-9175-4EE6-BAC0-193286B12F1C}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {91B8283B-1122-440B-BCD8-0A367B4F89E4}<br />
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {F42D1785-3F4C-46CC-B6B0-0DFD4B5F9E89}<br />
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}<br />
FW: Symantec Client Firewall *Enabled* <br />
FW: Trend Micro Personal Firewall *Disabled* <br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\WINDOWS\system32\svchost -k DcomLaunch<br />
svchost.exe<br />
C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCservice.exe<br />
svchost.exe<br />
svchost.exe<br />
C:\WINDOWS\system32\spoolsv.exe<br />
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE<br />
C:\Program Files\Dell\KACE\AMPAgent.exe<br />
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe<br />
C:\WINDOWS\system32\IFXSPMGT.exe<br />
C:\WINDOWS\system32\IFXTCS.exe<br />
C:\Program Files\Java\jre6\bin\jqs.exe<br />
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br />
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe<br />
C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE<br />
C:\Program Files\TightVNC\WinVNC.exe<br />
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe<br />
C:\WINDOWS\system32\wuauclt.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe<br />
C:\Program Files\Trend Micro\BM\TMBMSRV.exe<br />
C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe<br />
C:\WINDOWS\Explorer.EXE<br />
C:\WINDOWS\System32\svchost.exe -k HTTPFilter<br />
C:\WINDOWS\system32\hkcmd.exe<br />
C:\WINDOWS\system32\igfxpers.exe<br />
C:\WINDOWS\system32\igfxsrvc.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files\Analog Devices\Core\smax4pnp.exe<br />
C:\WINDOWS\AGRSMMSG.exe<br />
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe<br />
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe<br />
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE<br />
C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br />
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe<br />
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCgui.exe<br />
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe<br />
C:\WINDOWS\system32\ctfmon.exe<br />
C:\Program Files\eInstruction\Device Manager\Launch.exe<br />
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
C:\Program Files\Internet Explorer\iexplore.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uStart Page = hxxp://www.clayton.k12.ga.us/<br />
uInternet Settings,ProxyOverride = evserver01.clayton.k12.ga.us;SEVSERVER01;evserver02.clayton.k12.ga.us;SEVSERVER02;evserver03.clayton.k12.ga.us;SEVSERVER03;<br />
mWinlogon: Userinit=c:\windows\system32\KUsrInit.exe,<br />
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll<br />
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL<br />
BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\19.2.0.10\ips\IPSBHO.DLL<br />
BHO: Java&#153; Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll<br />
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll<br />
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe<br />
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0<br />
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe<br />
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; InfoPath.2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.explorelearning.com/index.cfm?method=cResource.dspView&amp;ResourceID=129&amp;ClassID=2088514"<br />
mRun: [igfxtray] c:\windows\system32\igfxtray.exe<br />
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe<br />
mRun: [igfxpers] c:\windows\system32\igfxpers.exe<br />
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe<br />
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe<br />
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray<br />
mRun: [AGRSMMSG] AGRSMMSG.exe<br />
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start<br />
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe<br />
mRun: [PTHOSTTR] c:\program files\hpq\hp protecttools security manager\PTHOSTTR.EXE /Start<br />
mRun: [Client Access Service] "c:\program files\ibm\client access\cwbsvstr.exe"<br />
mRun: [WatchDog] c:\program files\intervideo\dvd check\DVDCheck.exe<br />
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE<br />
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"<br />
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"<br />
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime<br />
mRun: [Trend OfficeScan ImageSetup] "C:\ImgSetup.exe" "/0017083fd604" -HideWindow<br />
mRun: [CiscoCSSCgui] "c:\program files\cisco\cisco secure services client\Cisco_SSCgui.exe"<br />
mRun: [<NO NAME>] <br />
mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\pccntmon.exe" -HideWindow<br />
mRun: [Client Access PWD Cache] "c:\program files\ibm\client access\cwblogon.exe" Cpu1 /u QCASignOn /p pcsupport<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe<br />
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\einstr~1.lnk - c:\program files\einstruction\device manager\Launch.exe<br />
IE: E&amp;xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000<br />
IE: Send To &amp;Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm<br />
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe<br />
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe<br />
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL<br />
Trusted Zone: k12.ga.us\*.clayton<br />
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab<br />
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://media3.keytrain.com/player/IE/awswaxd.cab<br />
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab<br />
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab<br />
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab<br />
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab<br />
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab<br />
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL<br />
Notify: csscsso - csscsso.dll<br />
Notify: IfxWlxEN - IfxWlxEN.dll<br />
Notify: igfxcui - igfxdev.dll<br />
Notify: kwinhook - kwinhook.dll<br />
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - c:\documents and settings\csnelson\application data\mozilla\firefox\profiles\53ic4riv.default\<br />
FF - prefs.js: browser.startup.homepage - hxxp://www.clayton.k12.ga.us/<br />
FF - prefs.js: network.proxy.type - 0<br />
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768]<br />
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]<br />
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]<br />
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]<br />
R2 AMPAgent;Dell KACE Agent;c:\program files\dell\kace\AMPAgent.exe [2011-9-21 2753640]<br />
R2 Cisco Secure Services Client;Cisco Secure Services Client;c:\program files\cisco\cisco secure services client\Cisco_SSCservice.exe [2008-10-7 1232896]<br />
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2011-6-23 51792]<br />
R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\TmXpflt.sys [2009-9-30 262416]<br />
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\TmPreflt.sys [2009-9-30 36624]<br />
R2 VNC Server;VNC Server;c:\program files\tightvnc\WinVNC.exe [2003-11-13 469504]<br />
R3 CiscoSSD;Cisco Secure Services Miniport Driver;c:\windows\system32\drivers\css_drv.sys [2011-6-23 42240]<br />
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-8-31 88192]<br />
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005-10-21 36352]<br />
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2010-1-4 340496]<br />
R3 TmProxy;OfficeScan NT Proxy Service;c:\program files\trend micro\officescan client\TmProxy.exe [2009-7-15 689416]<br />
S3 TmPfw;OfficeScan NT Firewall;c:\program files\trend micro\officescan client\TmPfw.exe [2009-7-15 497008]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2012-01-06 17:37:51	--------	d-----w-	c:\documents and settings\csnelson\application data\SUPERAntiSpyware.com<br />
2012-01-06 17:37:26	--------	d-----w-	c:\program files\SUPERAntiSpyware<br />
2012-01-06 17:37:26	--------	d-----w-	c:\documents and settings\all users\application data\SUPERAntiSpyware.com<br />
2012-01-05 21:08:59	--------	d-----w-	c:\program files\Turning Technologies<br />
2012-01-05 21:06:55	--------	d-----w-	c:\documents and settings\csnelson\local settings\application data\Mozilla<br />
2012-01-04 23:23:37	--------	d-----w-	c:\documents and settings\all users\application data\Norton<br />
2012-01-04 23:23:25	--------	d-----w-	c:\documents and settings\all users\application data\NortonInstaller<br />
2012-01-04 22:54:56	--------	d-----w-	c:\documents and settings\all users\application data\Kaspersky Lab Setup Files<br />
2012-01-04 22:50:55	--------	d-----w-	c:\windows\system32\LogFiles<br />
2012-01-04 19:51:07	--------	d-----w-	c:\documents and settings\csnelson\application data\Turning Technologies<br />
2012-01-04 18:02:37	52288	----a-r-	c:\documents and settings\csnelson\application data\microsoft\installer\{81baf04c-52d6-44ed-a516-da12e97886fb}\ARPPRODUCTICON.exe<br />
2012-01-04 17:28:50	102400	----a-w-	c:\windows\system32\tsccvid.dll<br />
2012-01-04 17:28:50	--------	d-----w-	c:\documents and settings\csnelson\local settings\application data\Adobe<br />
2012-01-04 17:26:48	--------	d-----w-	c:\documents and settings\csnelson\application data\eInstruction<br />
2012-01-04 17:22:56	--------	d-----w-	c:\program files\eInstruction<br />
2012-01-04 17:22:49	--------	d--h--w-	c:\documents and settings\csnelson\InstallAnywhere<br />
2012-01-04 17:05:49	--------	d-----w-	c:\documents and settings\all users\application data\Turning Technologies<br />
2012-01-04 17:04:19	311296	----a-w-	c:\windows\system32\lexlog.dll<br />
2012-01-04 17:04:19	--------	d-----w-	c:\program files\Dell_HostCD<br />
2012-01-04 17:04:09	131072	----a-w-	c:\windows\system32\LEXDRVX.DLL<br />
2012-01-04 17:04:09	106496	----a-w-	c:\windows\system32\LEXCFI.DLL<br />
2012-01-04 17:04:06	41984	----a-w-	c:\windows\system32\DKAAP2BJ.DLL<br />
2012-01-04 17:04:04	--------	d-----w-	C:\1700<br />
2012-01-04 16:50:34	--------	d-----w-	c:\program files\RM Content Access Tool<br />
2012-01-04 16:47:11	--------	d-----w-	c:\documents and settings\all users\application data\Research Machines<br />
2012-01-04 16:47:03	--------	d-----w-	c:\program files\directx<br />
2012-01-04 16:45:55	--------	d-----w-	c:\program files\Research Machines<br />
2012-01-04 16:45:31	--------	d-----w-	C:\STARRead<br />
2012-01-04 16:42:46	--------	d-----w-	C:\AccReadr<br />
2012-01-04 16:37:37	--------	d-----w-	c:\program files\Enterprise Vault<br />
2012-01-04 16:37:25	--------	d-----w-	c:\program files\Dell<br />
2012-01-04 16:37:23	--------	d-----w-	c:\documents and settings\all users\Dell<br />
2012-01-04 16:26:41	745472	----a-w-	c:\windows\system32\NETw4c32.dll<br />
2012-01-04 16:26:40	2777088	----a-w-	c:\windows\system32\NETw4r32.dll<br />
2012-01-04 16:26:40	2236544	----a-w-	c:\windows\system32\drivers\NETw4x32.sys<br />
2012-01-04 16:24:23	--------	d-----w-	c:\documents and settings\all users\application data\Renaissance Learning<br />
.<br />
==================== Find3M  ====================<br />
.<br />
.<br />
============= FINISH: 20:05:44.84 ===============<hr />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2011-08-26.01)<br />
.<br />
Microsoft Windows XP Professional<br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 1/4/2012 10:21:39 AM<br />
System Uptime: 1/6/2012 8:00:38 PM (0 hours ago)<br />
.<br />
Motherboard: Hewlett-Packard |  | 30AA<br />
Processor: Genuine Intel&reg; CPU           T2500  @ 2.00GHz | U10 | 1995/166mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 75 GiB total, 58.167 GiB free.<br />
D: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
No restore point in system.<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Acapela Speech Engine for Easiteach (US)<br />
Accelerated Reader 6.3<br />
Adobe Flash Player 10 ActiveX<br />
Adobe Reader 9<br />
Adobe Shockwave Player 11<br />
Agere Systems HDA Modem<br />
Broadcom NetXtreme Ethernet Controller<br />
Cisco Secure Services Client<br />
Dell KACE Agent<br />
Dell Printer Software Uninstall<br />
DeviceManager<br />
Easiteach Geography Licence<br />
Easiteach Literacy Licence<br />
Easiteach Maths Licence<br />
Easiteach Science Licence<br />
Easiteach Starter Licence<br />
Fingerprint Sensor Minimum Install<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Windows XP (KB954550-v5)<br />
HP Embedded Security for ProtectTools<br />
HP Integrated Module with Bluetooth wireless technology<br />
HP ProtectTools Security Manager 2.00 C3<br />
HP Quick Launch Buttons 6.00 D2<br />
IBM iSeries Access for Windows<br />
Intel Matrix Storage Manager<br />
Intel&reg; Graphics Media Accelerator Driver<br />
InterVideo DVD Check<br />
InterVideo WinDVD<br />
J2SE Runtime Environment 5.0 Update 4<br />
Java Auto Updater<br />
Java&#153; 6 Update 26<br />
Java&#153; SE Runtime Environment 6 Update 1<br />
Microsoft .NET Framework 2.0 Service Pack 2<br />
Microsoft .NET Framework 3.0 Service Pack 2<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Internationalized Domain Names Mitigation APIs<br />
Microsoft National Language Support Downlevel APIs<br />
Microsoft Office 2007 Service Pack 2 (SP2)<br />
Microsoft Office Access MUI (English) 2007<br />
Microsoft Office Access Setup Metadata MUI (English) 2007<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office FrontPage 2003<br />
Microsoft Office InfoPath MUI (English) 2007<br />
Microsoft Office Outlook MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office Professional Plus 2007<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)<br />
Microsoft Office Publisher MUI (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Software Update for Web Folders  (English) 12<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
Mozilla Firefox 7.0.1 (x86 en-US)<br />
Norton AntiVirus<br />
QuickTime<br />
RM Content Access Tool<br />
RM Easiteach<br />
RM Easiteach Resources (North America)<br />
RM Easiteach Secondary Content<br />
Security Update for 2007 Microsoft Office System (KB2277947)<br />
Security Update for 2007 Microsoft Office System (KB969559)<br />
Security Update for 2007 Microsoft Office System (KB976321)<br />
Security Update for 2007 Microsoft Office System (KB982312)<br />
Security Update for 2007 Microsoft Office System (KB982331)<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for Microsoft Office Access 2007 (KB979440)<br />
Security Update for Microsoft Office Excel 2007 (KB982308)<br />
Security Update for Microsoft Office InfoPath 2007 (KB979441)<br />
Security Update for Microsoft Office Outlook 2007 (KB980376)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB982158)<br />
Security Update for Microsoft Office Publisher 2007 (KB982124)<br />
Security Update for Microsoft Office system 2007 (972581)<br />
Security Update for Microsoft Office system 2007 (KB974234)<br />
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)<br />
Security Update for Microsoft Office Word 2007 (KB2251419)<br />
Security Update for Windows Media Player (KB911564)<br />
Security Update for Windows Media Player 9 (KB917734)<br />
Security Update for Windows XP (KB913433)<br />
SmartWeb Classroom Management System (SwCMS)<br />
Sonic Audio Module<br />
Sonic Copy Module<br />
Sonic Data Module<br />
Sonic DLA<br />
Sonic Express Labeler<br />
Sonic Update Manager<br />
SoundMAX<br />
Star Reading<br />
Symantec Enterprise Vault HTTP-only Outlook Add-In<br />
Synaptics Pointing Device Driver<br />
Texas Instruments PCIxx21/x515/xx12 drivers.<br />
TIPCI<br />
Trend Micro OfficeScan Client<br />
TurningPoint 2008<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Outlook 2007 Junk Email Filter (KB2536413)<br />
Update for Windows XP (KB951072-v2)<br />
WebFldrs XP<br />
Windows Driver Package - Intel (NETw4x32) net  (10/31/2007 11.5.0.34)<br />
Windows Driver Package - Intel (w29n51) net  (07/25/2007 9.0.4.37)<br />
Windows Driver Package - Intel net  (10/31/2007 11.5.0.34)<br />
Windows Internet Explorer 7<br />
Windows Internet Explorer 8<br />
Windows XP Service Pack 3<br />
Workspace<br />
Workspace Content<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
1/6/2012 1:04:13 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  Fips intelppm SASDIFSV SASKUTIL tmtdi<br />
1/5/2012 7:45:34 AM, error: SRTSP [4]  - <br />
1/5/2012 7:15:58 AM, error: DCOM [10016]  - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18).  This security permission can be modified using the Component Services administrative tool.<br />
1/4/2012 9:08:56 PM, error: NETLOGON [5719]  - No Domain Controller is available for domain CLAYTON due to the following:  There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.<br />
1/4/2012 9:07:34 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service IFXSpMgtSrv with arguments "-Service" in order to run the server: {FBCD9C6A-72CB-47BB-99DD-2317551491DE}<br />
1/4/2012 9:07:34 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
1/4/2012 8:30:17 PM, error: DCOM [10005]  - DCOM got error "%1084" attempting to start the service IFXSpMgtSrv with arguments "-Service" in order to run the server: {FBCD9C66-72CB-47BB-99DD-2317551491DE}<br />
1/4/2012 8:29:40 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  BHDrvx86 ccSet_NAV eeCtrl Fips intelppm SRTSPX SymIRON SYMTDI tmtdi<br />
1/4/2012 5:33:53 PM, error: Dhcp [1002]  - The IP address lease 10.29.20.194 for the Network Card with network address 0018DE803BA1 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).<br />
1/4/2012 10:26:07 AM, error: Service Control Manager [7022]  - The Cisco Secure Services Client service hung on starting.<br />
.<br />
==== End Of File ===========================]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[yet another Redirect virus]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-yet-another-redirect-virus</link>
			<pubDate>Thu, 05 Jan 2012 22:24:38 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-yet-another-redirect-virus</guid>
			<description><![CDATA[Hi Guys<br />
Have picked up a virus that redirects mywebpage when I click google search results<br />
Happens in IE9 and Firefox<br />
Have tried to attach a hijack this log but cant seem to get it attached<br />
Have trendmicro titanium - does not show virus on scanning<br />
Currently scanning with trend micro rootkitbuster but it seems to have stalled( shows 11883 threats but no log -has been running all night)<br />
Hope you can help me<br />
Regards<br />
Styx]]></description>
			<content:encoded><![CDATA[Hi Guys<br />
Have picked up a virus that redirects mywebpage when I click google search results<br />
Happens in IE9 and Firefox<br />
Have tried to attach a hijack this log but cant seem to get it attached<br />
Have trendmicro titanium - does not show virus on scanning<br />
Currently scanning with trend micro rootkitbuster but it seems to have stalled( shows 11883 threats but no log -has been running all night)<br />
Hope you can help me<br />
Regards<br />
Styx]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Dell Drive Problemo]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-dell-drive-problemo</link>
			<pubDate>Wed, 28 Dec 2011 04:38:34 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-dell-drive-problemo</guid>
			<description><![CDATA[Hello, I do hope I'm posting in the correct section.<br />
<br />
I own an old Dell Dimension 5150. I've been relatively happy with it and save for a handful of minor viruses, I've had no problems. Until now. After being hit by a virus and after restarting the computer, a black screen popped up with a blue banner at the top which contained, <a href="http://www.dell.com" target="_blank">http://www.dell.com</a> and below that, the following; "<span style="font-weight: bold;">Loading PBR for descriptor 2...done</span>" Nothing happens after that and the only things I can access before the "Loading PBR..." screen are the System Setup (F2) and the Boot Menu (F12)<br />
<br />
You'll have to forgive my lack of computer knowledge, but from what I've gathered, it's a problem with the hard drive and partitions and the boot. (I have an identical Dell in my office and I see the same "Loading PBR for descriptor 2...done" for a split second before Windows opens up.) I've read everything from it'd be fine if I followed certain steps, that my data's lost forever, etc.<br />
<br />
All I care about is recovering the 3 years worth of photos of my little boy growing up from the drive (which to add insult to injury, I was in the process of FINALLY backing up.) Is this something I can attempt on my own? Should I give it to an expert? Should I try and fix the problem myself? Is the virus - still on there obviously - going to cause problems with any of the above?<br />
<br />
Thank you so much.]]></description>
			<content:encoded><![CDATA[Hello, I do hope I'm posting in the correct section.<br />
<br />
I own an old Dell Dimension 5150. I've been relatively happy with it and save for a handful of minor viruses, I've had no problems. Until now. After being hit by a virus and after restarting the computer, a black screen popped up with a blue banner at the top which contained, <a href="http://www.dell.com" target="_blank">http://www.dell.com</a> and below that, the following; "<span style="font-weight: bold;">Loading PBR for descriptor 2...done</span>" Nothing happens after that and the only things I can access before the "Loading PBR..." screen are the System Setup (F2) and the Boot Menu (F12)<br />
<br />
You'll have to forgive my lack of computer knowledge, but from what I've gathered, it's a problem with the hard drive and partitions and the boot. (I have an identical Dell in my office and I see the same "Loading PBR for descriptor 2...done" for a split second before Windows opens up.) I've read everything from it'd be fine if I followed certain steps, that my data's lost forever, etc.<br />
<br />
All I care about is recovering the 3 years worth of photos of my little boy growing up from the drive (which to add insult to injury, I was in the process of FINALLY backing up.) Is this something I can attempt on my own? Should I give it to an expert? Should I try and fix the problem myself? Is the virus - still on there obviously - going to cause problems with any of the above?<br />
<br />
Thank you so much.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Man sued for keeping company Twitter followers]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-man-sued-for-keeping-company-twitter-followers</link>
			<pubDate>Tue, 27 Dec 2011 19:26:59 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-man-sued-for-keeping-company-twitter-followers</guid>
			<description><![CDATA[<blockquote><cite>Quote:</cite>A man is being sued for keeping Twitter followers that he attracted while working for a US mobile news website.<br />
<br />
Noah Kravitz tweeted for Phonedog as @Phonedog_Noah, but later changed his username when he left the company - taking 17,000 followers with him.<br />
<br />
The company is now seeking damages of &#36;2.50 (£1.60) <span style="font-weight: bold;">per user</span>,<span style="font-weight: bold;"> per month </span>- a total of &#36;370,000.</blockquote>
Thats going to work out a lot of money until this gets all the legal arguements for and against sorted out, and then gets into court (if it makes it that far) if they are claiming rights by<span style="font-weight: bold;"> per person per month basis</span>??<br />
<br />
<a href="http://www.bbc.co.uk/news/technology-16338040" target="_blank">http://www.bbc.co.uk/news/technology-16338040</a>]]></description>
			<content:encoded><![CDATA[<blockquote><cite>Quote:</cite>A man is being sued for keeping Twitter followers that he attracted while working for a US mobile news website.<br />
<br />
Noah Kravitz tweeted for Phonedog as @Phonedog_Noah, but later changed his username when he left the company - taking 17,000 followers with him.<br />
<br />
The company is now seeking damages of &#36;2.50 (£1.60) <span style="font-weight: bold;">per user</span>,<span style="font-weight: bold;"> per month </span>- a total of &#36;370,000.</blockquote>
Thats going to work out a lot of money until this gets all the legal arguements for and against sorted out, and then gets into court (if it makes it that far) if they are claiming rights by<span style="font-weight: bold;"> per person per month basis</span>??<br />
<br />
<a href="http://www.bbc.co.uk/news/technology-16338040" target="_blank">http://www.bbc.co.uk/news/technology-16338040</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Changing back to an MS operating system, is this difficult?]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-changing-back-to-an-ms-operating-system-is-this-difficult</link>
			<pubDate>Tue, 27 Dec 2011 19:12:52 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-changing-back-to-an-ms-operating-system-is-this-difficult</guid>
			<description><![CDATA[Hello all,<br />
Hope you all had a good Christmas.<br />
<br />
For the last couple of months i have been using an Ubuntu O.S.<br />
This was put on after my MS Xp had received an infection that seemed almost impossible to get rid of.<br />
<br />
At first using ubuntu was Ok-ish, the normal learning curves had to be taught again and i began to get on ok with it.<br />
However as soon as i wanted to do anything other than surf the net, things began to deteriorate.<br />
My daughter found that recent CV's which she had attached to emails could not be opened by the recipient.?<br />
Libre office writer was used.?<br />
<br />
Online gaming was too much of a headache for my son, the whole system slowed down completely?  <br />
<br />
I have finally decided to go back to a Microsoft windows operating system,<br />
 this would be on the condition that i could do it myself <span style="font-weight: bold;">[please see my name&#93;?</span><br />
I wouldnt lose any of the documents on the pc at the moment?<br />
It wouldnt be too much of a headache to actually do?<br />
<br />
Given the above requirements is this possible?<br />
What would i need?<br />
<br />
Any advice would be greatly appreciated<br />
Cheers]]></description>
			<content:encoded><![CDATA[Hello all,<br />
Hope you all had a good Christmas.<br />
<br />
For the last couple of months i have been using an Ubuntu O.S.<br />
This was put on after my MS Xp had received an infection that seemed almost impossible to get rid of.<br />
<br />
At first using ubuntu was Ok-ish, the normal learning curves had to be taught again and i began to get on ok with it.<br />
However as soon as i wanted to do anything other than surf the net, things began to deteriorate.<br />
My daughter found that recent CV's which she had attached to emails could not be opened by the recipient.?<br />
Libre office writer was used.?<br />
<br />
Online gaming was too much of a headache for my son, the whole system slowed down completely?  <br />
<br />
I have finally decided to go back to a Microsoft windows operating system,<br />
 this would be on the condition that i could do it myself <span style="font-weight: bold;">[please see my name]?</span><br />
I wouldnt lose any of the documents on the pc at the moment?<br />
It wouldnt be too much of a headache to actually do?<br />
<br />
Given the above requirements is this possible?<br />
What would i need?<br />
<br />
Any advice would be greatly appreciated<br />
Cheers]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[XenApp 6 server with Windows Server 2008]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-xenapp-6-server-with-windows-server-2008</link>
			<pubDate>Tue, 20 Dec 2011 17:19:54 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-xenapp-6-server-with-windows-server-2008</guid>
			<description><![CDATA[Hello guys,<br />
<br />
Anyone running a XenApp 6 server with Windows Server 2008 R2 Service Pack 1 build 7601.17514.101119-1850 ?<br />
One my Clients cannot connect to such an updated terminal server, The error he is getting <span style="font-weight: bold;">Connection in progress</span><br />
<br />
Can anybody please help me on this?]]></description>
			<content:encoded><![CDATA[Hello guys,<br />
<br />
Anyone running a XenApp 6 server with Windows Server 2008 R2 Service Pack 1 build 7601.17514.101119-1850 ?<br />
One my Clients cannot connect to such an updated terminal server, The error he is getting <span style="font-weight: bold;">Connection in progress</span><br />
<br />
Can anybody please help me on this?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Error - "No Bootable Media"]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-error-no-bootable-media</link>
			<pubDate>Tue, 20 Dec 2011 17:09:54 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-error-no-bootable-media</guid>
			<description><![CDATA[Hey guys,<br />
<br />
We are using Virtual Box 2.2.4 since it's the version we have at uni and my debian file won't work on the newer versions. But when we try and get Server 2008 from dream spark to work it won't. It keeps saying <span style="font-weight: bold;">no bootable medium</span> when we first boot it up.<br />
<br />
Also help me on this - can we get server 2008 to work in virtual PC?]]></description>
			<content:encoded><![CDATA[Hey guys,<br />
<br />
We are using Virtual Box 2.2.4 since it's the version we have at uni and my debian file won't work on the newer versions. But when we try and get Server 2008 from dream spark to work it won't. It keeps saying <span style="font-weight: bold;">no bootable medium</span> when we first boot it up.<br />
<br />
Also help me on this - can we get server 2008 to work in virtual PC?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Ping test is fine but internet still wont load]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-ping-test-is-fine-but-internet-still-wont-load</link>
			<pubDate>Tue, 13 Dec 2011 15:38:31 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-ping-test-is-fine-but-internet-still-wont-load</guid>
			<description><![CDATA[Hi,<br />
<br />
Apologies if this is in the wrong forum but I need some advice with my laptop please.<br />
<br />
It operates from Windows 7 and for the past 4 days hasnt been able to load the internet properly. It's very slow and refuses to upload pictures and sometimes the green progress bar doesnt come up at all.<br />
<br />
I have made several phonecalls to Talk Talk as through previos experience I thought it was their error that I wasnt getting a signal but after what felt like hours on the phone I ran a ping test and it came back fine so he said its a problem with my operating system but couldnt offer me any help other than that statement.<br />
<br />
Has anyone come across this problem before and has advice, or if you need more info just ask.<br />
<br />
Cheers]]></description>
			<content:encoded><![CDATA[Hi,<br />
<br />
Apologies if this is in the wrong forum but I need some advice with my laptop please.<br />
<br />
It operates from Windows 7 and for the past 4 days hasnt been able to load the internet properly. It's very slow and refuses to upload pictures and sometimes the green progress bar doesnt come up at all.<br />
<br />
I have made several phonecalls to Talk Talk as through previos experience I thought it was their error that I wasnt getting a signal but after what felt like hours on the phone I ran a ping test and it came back fine so he said its a problem with my operating system but couldnt offer me any help other than that statement.<br />
<br />
Has anyone come across this problem before and has advice, or if you need more info just ask.<br />
<br />
Cheers]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Need analyses of this log from hijackthis]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-need-analyses-of-this-log-from-hijackthis</link>
			<pubDate>Fri, 02 Dec 2011 15:53:43 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-need-analyses-of-this-log-from-hijackthis</guid>
			<description><![CDATA[Also I am trying to remove a registry entry for an outdated Kodak easyshare install that wouldn't not remove. I get the Run DLL error all the time.]]></description>
			<content:encoded><![CDATA[Also I am trying to remove a registry entry for an outdated Kodak easyshare install that wouldn't not remove. I get the Run DLL error all the time.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[18 Reasons to use Office 365 – #7 Upfront costs of a server]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-18-reasons-to-use-office-365-%E2%80%93-7-upfront-costs-of-a-server</link>
			<pubDate>Thu, 01 Dec 2011 11:00:18 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-18-reasons-to-use-office-365-%E2%80%93-7-upfront-costs-of-a-server</guid>
			<description><![CDATA[18 Reasons to use Office 365 – #7 Upfront costs of a server ? Which would you choose ? <br /><a class="wordbb-full-post" href="http://blog.techmonkeys.co.uk/uncategorized/18-reasons-to-use-office-365-%e2%80%93-7-upfront-costs-of-a-server/" title="18 Reasons to use Office 365 – #7 Upfront costs of a server">Read Full Post: 18 Reasons to use Office 365 – #7 Upfront costs of a server</a>]]></description>
			<content:encoded><![CDATA[18 Reasons to use Office 365 – #7 Upfront costs of a server ? Which would you choose ? <br /><a class="wordbb-full-post" href="http://blog.techmonkeys.co.uk/uncategorized/18-reasons-to-use-office-365-%e2%80%93-7-upfront-costs-of-a-server/" title="18 Reasons to use Office 365 – #7 Upfront costs of a server">Read Full Post: 18 Reasons to use Office 365 – #7 Upfront costs of a server</a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Orphan Outlook OST - Free Recovery Tool]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-orphan-outlook-ost-free-recovery-tool</link>
			<pubDate>Wed, 30 Nov 2011 14:44:39 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-orphan-outlook-ost-free-recovery-tool</guid>
			<description><![CDATA[Anyone used or can recommend a free tool for recovering data from an orphaned OST file?<br />
<br />
If not, one I need to pay for?<br />
<br />
Looking at PST Walker and Stellar Phoenix atm..]]></description>
			<content:encoded><![CDATA[Anyone used or can recommend a free tool for recovering data from an orphaned OST file?<br />
<br />
If not, one I need to pay for?<br />
<br />
Looking at PST Walker and Stellar Phoenix atm..]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[UK cybersecurity plan a 'promising step' but with risks]]></title>
			<link>http://www.techmonkeys.co.uk/Thread-uk-cybersecurity-plan-a-promising-step-but-with-risks</link>
			<pubDate>Sun, 27 Nov 2011 09:45:56 +0000</pubDate>
			<guid isPermaLink="false">http://www.techmonkeys.co.uk/Thread-uk-cybersecurity-plan-a-promising-step-but-with-risks</guid>
			<description><![CDATA[<span style="font-weight: bold;">The UK government has released its 2011 Cyber Security Strategy. </span><br />
<br />
<blockquote><cite>Quote:</cite>With an increased focus on cybercrime, and renewed focus on cyberspace as an engine of economic and social prosperity, the strategy continues to hone Whitehall's understanding of this vibrant, complex and increasingly global domain.</blockquote>
<br />
<blockquote><cite>Quote:</cite>Cybercrime is topic that receives significant focus, in particular for the damage it does to the financial and social fabric of the country.<br />
One primary initiative will create a "national cyber crime capability as part of the new National Crime Agency by 2013".<br />
Another will create, by the end of 2011, a "single reporting system for citizens and small businesses to report cyber crime".</blockquote>
<a href="http://www.bbc.co.uk/news/technology-15893773" target="_blank">http://www.bbc.co.uk/news/technology-15893773</a><br />
<br />
<span style="font-weight: bold;">Also read this:</span><br />
GCHQ to take hub role in UK cybersecurity<br />
<a href="http://www.zdnet.co.uk/news/security/2011/11/25/gchq-to-take-hub-role-in-uk-cybersecurity-40094512/" target="_blank">http://www.zdnet.co.uk/news/security/201...-40094512/</a><br />
<br />
<span style="font-weight: bold;">and then this, a good read.</span><br />
CESG: How UK defends against cyberattacks<br />
<a href="http://www.zdnet.co.uk/news/security-management/2011/04/26/cesg-how-uk-defends-against-cyberattacks-400" target="_blank">http://www.zdnet.co.uk/news/security-man...ttacks-400</a>]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;">The UK government has released its 2011 Cyber Security Strategy. </span><br />
<br />
<blockquote><cite>Quote:</cite>With an increased focus on cybercrime, and renewed focus on cyberspace as an engine of economic and social prosperity, the strategy continues to hone Whitehall's understanding of this vibrant, complex and increasingly global domain.</blockquote>
<br />
<blockquote><cite>Quote:</cite>Cybercrime is topic that receives significant focus, in particular for the damage it does to the financial and social fabric of the country.<br />
One primary initiative will create a "national cyber crime capability as part of the new National Crime Agency by 2013".<br />
Another will create, by the end of 2011, a "single reporting system for citizens and small businesses to report cyber crime".</blockquote>
<a href="http://www.bbc.co.uk/news/technology-15893773" target="_blank">http://www.bbc.co.uk/news/technology-15893773</a><br />
<br />
<span style="font-weight: bold;">Also read this:</span><br />
GCHQ to take hub role in UK cybersecurity<br />
<a href="http://www.zdnet.co.uk/news/security/2011/11/25/gchq-to-take-hub-role-in-uk-cybersecurity-40094512/" target="_blank">http://www.zdnet.co.uk/news/security/201...-40094512/</a><br />
<br />
<span style="font-weight: bold;">and then this, a good read.</span><br />
CESG: How UK defends against cyberattacks<br />
<a href="http://www.zdnet.co.uk/news/security-management/2011/04/26/cesg-how-uk-defends-against-cyberattacks-400" target="_blank">http://www.zdnet.co.uk/news/security-man...ttacks-400</a>]]></content:encoded>
		</item>
	</channel>
</rss>
