Symptoms that have not yet appeared:
- I CAN STILL perform a Google search without being redirected.
- I CAN STILL run security tools and other EXE files.
- I DO have a file called consrv.dll sitting in my C:\Windows\system32 folder.
- I DO have a file called kwrd.dll sitting in C:\Windows\assembly\temp.
- I DO get virus alerts from my security software (COMODO Internet Security) stating that viruses are trying to run from that same folder.
- I DO have a random PING.exe process created from C:\Windows\svchost.exe every time I start my computer. This worries me.
I was thinking it could be a rootkit, but COMODO hasn't picked up anything. I've also run scans with Malwarebytes, Hitman Pro, Norton Power Eraser, and the Kaspersky Virus Removal Tool. None of them find anything malicious, which suggests either this is zero-day malware or that I am not (yet) "fully" infected. My computer also doesn't seem to be slowing down any. Perhaps (hopefully) I only have "half" an infection?
I've run a quick scan with OTL as per the board rules. The scan log is pasted below.
OTL logfile created on: 10/22/2011 11:52:03 AM - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Jay\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 5.98 Gb Total Physical Memory | 4.02 Gb Available Physical Memory | 67.19% Memory free 12.04 Gb Paging File | 10.01 Gb Available in Paging File | 83.14% Paging File free Paging file location(s): c:\pagefile.sys 6200 6200 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 906.34 Gb Total Space | 662.61 Gb Free Space | 73.11% Space Free | Partition Type: NTFS Computer Name: JAY-PC | User Name: Jay | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011/10/22 01:50:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Jay\Downloads\OTL.exe PRC - [2011/09/29 23:57:39 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2011/04/01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe PRC - [2010/09/26 15:30:52 | 000,163,840 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Power Dial\LitModeSwitch.exe PRC - [2010/09/13 21:32:32 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe PRC - [2010/09/13 21:32:30 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe PRC - [2010/09/09 14:46:14 | 000,081,920 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe PRC - [2010/01/21 01:40:59 | 000,040,960 | ---- | M] () -- C:\Windows\SysWOW64\UMonit.exe PRC - [2009/09/30 14:19:30 | 000,049,152 | ---- | M] (Lenovo) -- C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe PRC - [2009/07/16 12:05:10 | 000,114,688 | ---- | M] (JME) -- C:\Program Files (x86)\jmesoft\hotkey.exe PRC - [2009/07/13 20:14:28 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PING.EXE [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011/10/12 15:29:00 | 000,475,136 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\60c320dbe033e8ff4830cdc059933f2c\IAStorUtil.ni.dll MOD - [2011/10/12 15:29:00 | 000,014,336 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll MOD - [2011/10/12 14:28:47 | 000,771,584 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll MOD - [2011/10/12 14:28:28 | 012,433,408 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll MOD - [2011/10/12 14:28:23 | 001,587,200 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll MOD - [2011/10/12 14:28:14 | 003,347,968 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll MOD - [2011/10/12 14:28:11 | 005,453,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll MOD - [2011/10/12 14:28:08 | 007,963,648 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll MOD - [2011/10/12 14:28:08 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll MOD - [2011/10/12 14:28:04 | 011,490,304 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll MOD - [2011/10/04 18:09:32 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll MOD - [2011/09/29 23:57:39 | 001,833,944 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011/08/05 17:49:19 | 000,928,256 | ---- | M] () -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions\[email protected]\platform\WINNT_x86-msvc\components\lpxpcom.dll MOD - [2011/06/18 16:26:14 | 000,003,584 | ---- | M] () -- C:\Windows\SysWOW64\RemoveFocusRect.dll MOD - [2010/11/20 07:19:56 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll MOD - [2010/01/21 01:40:59 | 000,040,960 | ---- | M] () -- C:\Windows\SysWOW64\UMonit.exe MOD - [2009/10/26 02:52:38 | 000,139,264 | ---- | M] () -- C:\Windows\SysWOW64\ustor.dll MOD - [2009/07/16 12:20:38 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\jmesoft\KeyHook.dll MOD - [2008/12/30 14:09:34 | 002,088,960 | ---- | M] () -- C:\Program Files\Lenovo\Power Dial\LitModeSwitchRes.dll MOD - [2007/12/31 13:27:42 | 000,007,168 | ---- | M] () -- C:\Program Files (x86)\jmesoft\VistaVolume.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2011/10/10 08:32:14 | 000,341,296 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe -- (NitroReaderDriverReadSpool2) SRV:[b]64bit:[/b] - [2011/10/07 18:47:16 | 002,663,568 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent) SRV:[b]64bit:[/b] - [2011/07/28 16:35:34 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2010/09/09 14:46:14 | 000,081,920 | ---- | M] (Lenovo) [On_Demand | Running] -- C:\Program Files\Lenovo\Power Dial\LitModeCtrl.exe -- (LitModeCtrl) SRV:[b]64bit:[/b] - [2010/08/19 17:43:24 | 000,386,344 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64) SRV:[b]64bit:[/b] - [2009/09/30 14:19:30 | 000,049,152 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\Lenovo\Power Dial\LenovoCOMSvc.exe -- (LenovoCOMSvc) SRV:[b]64bit:[/b] - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2011/09/22 11:47:20 | 000,712,520 | ---- | M] (Mister Group) [Auto | Running] -- C:\Program Files (x86)\System Explorer\SystemExplorerService64.exe -- (SystemExplorerHelpService) SRV - [2011/08/04 14:25:22 | 000,551,352 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\USB Safely Remove\USBSRService.exe -- (USBSafelyRemoveService) SRV - [2011/06/18 17:14:14 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011/04/01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv) SRV - [2010/09/13 21:32:32 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2011/10/21 23:42:24 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\71051577.sys -- (71051577) DRV:[b]64bit:[/b] - [2011/10/07 18:47:56 | 000,016,528 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd) DRV:[b]64bit:[/b] - [2011/08/05 17:37:15 | 000,270,912 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2011/07/28 17:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2011/07/28 17:23:16 | 009,980,416 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2011/07/28 15:54:10 | 000,309,248 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2011/06/06 17:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:[b]64bit:[/b] - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:[b]64bit:[/b] - [2011/04/01 00:07:54 | 004,184,672 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) Logitech Webcam C210(UVC) DRV:[b]64bit:[/b] - [2011/04/01 00:06:22 | 000,341,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64) DRV:[b]64bit:[/b] - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010/09/21 01:34:18 | 000,313,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel(R) DRV:[b]64bit:[/b] - [2010/09/20 20:59:38 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel(R) DRV:[b]64bit:[/b] - [2010/09/13 21:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2010/05/07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon) DRV:[b]64bit:[/b] - [2010/05/07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64) DRV:[b]64bit:[/b] - [2010/05/07 13:42:46 | 000,271,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvpopf64.sys -- (lvpopf64) DRV:[b]64bit:[/b] - [2010/04/13 04:57:26 | 001,631,264 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192u.sys -- (RTL8192U) DRV:[b]64bit:[/b] - [2010/02/21 21:49:58 | 000,052,224 | ---- | M] (Genesys Logic) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ustor2k.sys -- (USTOR2K) DRV:[b]64bit:[/b] - [2009/12/30 11:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt) DRV:[b]64bit:[/b] - [2009/07/21 17:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd) DRV:[b]64bit:[/b] - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/07/13 19:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc) DRV:[b]64bit:[/b] - [2009/06/10 15:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2009/06/10 15:35:53 | 000,051,712 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rtnic64.sys -- (RTL8023x64) DRV:[b]64bit:[/b] - [2009/06/10 15:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:[b]64bit:[/b] - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV - [2011/10/22 10:58:30 | 000,000,298 | -HS- | M] () [File_System | Unknown | Running] -- C:\windows\6821560drv.spi -- (6821560drv) DRV - [2010/03/22 21:13:08 | 000,015,712 | ---- | M] (Nicomsoft Ltd.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\DDCDrv.sys -- (WinI2C-DDC) DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2009/02/24 05:08:34 | 000,011,576 | ---- | M] (Samsung Electronics) [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\SSPORT.SYS -- (SSPORT) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: File not found FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( ) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/12 15:13:02 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/12 15:08:10 | 000,000,000 | ---D | M] [2011/06/18 16:44:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jay\AppData\Roaming\Mozilla\Extensions [2011/10/16 14:38:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions [2011/09/24 00:29:18 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2011/08/18 23:44:15 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011/10/15 19:57:00 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2011/08/25 22:12:47 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions\[email protected] [2011/08/06 19:31:53 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\gzqv13n3.Jay\extensions\[email protected] [2011/10/21 01:10:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2011/09/29 23:57:39 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011/10/21 01:03:24 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml O1 HOSTS File: ([2011/10/22 01:44:50 | 000,000,760 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:[b]64bit:[/b] - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO) O4:[b]64bit:[/b] - HKLM..\Run: [StartupDelayer] C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe (r2 Studios) O4:[b]64bit:[/b] - HKLM..\Run: [UMonit] C:\Windows\SysWOW64\UMonit.exe () O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) O4 - HKLM..\Run: [jmekey] C:\Program Files (x86)\jmesoft\hotkey.exe (JME) O4 - HKLM..\Run: [ModeSwitch] C:\Program Files\Lenovo\Power Dial\LitModeSwitch.exe (Lenovo) O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe () O4 - HKLM..\RunOnce: [GrpConv] C:\windows\SysWow64\grpconv.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideRunAsVerb = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Disallow.Cpl = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Sync Center = Sync Center O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Credential Manager = Credential Manager O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: HomeGroup = HomeGroup O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Windows CardSpace = Windows CardSpace O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Speech Recognition = Speech Recognition O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Location and Other Sensors = Location and Other Sensors O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Backup and Restore = Backup and Restore O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Phone and Modem = Phone and Modem O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Parental Controls = Parental Controls O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Getting Started = Getting Started O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Windows Anytime Upgrade = Windows Anytime Upgrade O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: Revo Uninstaller Pro = Revo Uninstaller Pro O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 1 O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: samsungsetup.com ([www] http in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 10.1.0) O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1BCA482E-2CAA-4932-AB96-E1275DDCB765}: DhcpNameServer = 10.50.0.1 10.50.0.2 10.50.0.3 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{78529EC1-4EFE-445D-BE2B-2EB18A79AA84}: DhcpNameServer = 192.168.11.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87D4461F-91BD-4EFB-B24D-EA18E6E81D80}: NameServer = 8.8.8.8,8.8.4.4 O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O20:[b]64bit:[/b] - AppInit_DLLs: (RemoveFocusRect.dll) - C:\windows\SysNative\RemoveFocusRect.dll () O20:[b]64bit:[/b] - AppInit_DLLs: (C:\windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO) O20 - AppInit_DLLs: (RemoveFocusRect.dll) -C:\windows\SysWow64\RemoveFocusRect.dll () O20 - AppInit_DLLs: (C:\windows\SysWOW64\guard32.dll) -C:\Windows\SysWOW64\guard32.dll (COMODO) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O27:[b]64bit:[/b] - HKLM IFEO\taskmgr.exe: Debugger - C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Mister Group) O27 - HKLM IFEO\taskmgr.exe: Debugger - C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Mister Group) O28:[b]64bit:[/b] - HKLM ShellExecuteHooks: {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll (GP Software) O28 - HKLM ShellExecuteHooks: {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\GPSoftware\Directory Opus\dopuslib32.dll (GP Software) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011/10/22 11:08:54 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Local\ElevatedDiagnostics [2011/10/22 10:31:17 | 000,460,888 | ---- | C] (Kaspersky Lab ZAO) -- C:\windows\SysNative\drivers\71051577.sys [2011/10/22 01:32:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab [2011/10/22 01:24:00 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Local\NPE [2011/10/22 01:24:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton [2011/10/22 01:01:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro [2011/10/21 21:56:37 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Malwarebytes [2011/10/21 21:56:33 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/10/21 21:56:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/10/21 21:56:30 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys [2011/10/21 21:56:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011/10/21 20:31:14 | 000,000,000 | ---D | C] -- C:\windows\system64 [2011/10/21 01:03:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java [2011/10/19 20:03:31 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Local\COMODO [2011/10/13 13:55:59 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Local\28050 [2011/10/12 18:20:51 | 000,000,000 | -H-D | C] -- C:\VritualRoot [2011/10/12 16:48:21 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\COMODO [2011/10/12 16:48:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo [2011/10/12 16:48:15 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO [2011/10/12 16:45:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2011/10/12 16:45:49 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2011/10/12 16:32:10 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Nitro PDF Reader [2011/10/12 16:07:40 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Nitro PDF [2011/10/12 16:07:24 | 000,028,976 | ---- | C] (Nitro PDF Software) -- C:\windows\SysNative\nitrolocalmon2.dll [2011/10/12 16:07:24 | 000,017,200 | ---- | C] (Nitro PDF Software) -- C:\windows\SysNative\nitrolocalui2.dll [2011/10/12 16:07:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF [2011/10/12 16:07:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF [2011/10/12 16:07:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nitro PDF [2011/10/12 16:07:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nitro PDF [2011/10/12 16:06:53 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Downloaded Installations [2011/10/12 16:01:30 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ [2011/10/12 16:01:29 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Notepad++ [2011/10/12 16:01:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Notepad++ [2011/10/12 15:52:46 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iTunes [2011/10/12 15:52:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011/10/12 15:52:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2011/10/12 15:52:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2011/10/12 10:44:31 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro [2011/10/12 10:44:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro [2011/10/12 10:31:41 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2011/10/12 10:31:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2011/10/07 18:47:56 | 000,016,528 | ---- | C] (COMODO) -- C:\windows\SysNative\drivers\cmderd.sys [2011/10/07 18:47:14 | 000,041,200 | ---- | C] (COMODO) -- C:\windows\SysNative\cmdcsr.dll [2011/10/07 18:47:12 | 000,300,200 | ---- | C] (COMODO) -- C:\windows\SysWow64\guard32.dll [2011/10/07 18:47:10 | 000,388,280 | ---- | C] (COMODO) -- C:\windows\SysNative\guard64.dll [2011/09/30 10:20:54 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Daum [2011/09/30 10:20:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum [2011/09/28 13:47:55 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Speccy [2011/09/28 13:47:55 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy [2011/09/24 11:10:18 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rainmeter [2011/09/22 17:35:12 | 000,000,000 | ---D | C] -- C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Explorer [2011/09/22 17:35:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011/10/22 11:49:01 | 001,474,832 | ---- | M] () -- C:\windows\SysNative\drivers\sfi.dat [2011/10/22 11:26:31 | 000,025,160 | ---- | M] () -- C:\windows\SysNative\drivers\hitmanpro35.sys [2011/10/22 10:58:30 | 000,000,298 | -HS- | M] () -- C:\windows\6821560drv.spi [2011/10/22 10:36:17 | 000,017,952 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/10/22 10:36:17 | 000,017,952 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/10/22 10:33:21 | 000,726,316 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI [2011/10/22 10:33:21 | 000,623,940 | ---- | M] () -- C:\windows\SysNative\perfh009.dat [2011/10/22 10:33:21 | 000,106,316 | ---- | M] () -- C:\windows\SysNative\perfc009.dat [2011/10/22 10:29:04 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2011/10/22 10:24:27 | 000,000,238 | ---- | M] () -- C:\windows\tasks\RunAsStdUser Task.job [2011/10/22 01:44:50 | 000,000,760 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts [2011/10/21 23:42:24 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) -- C:\windows\SysNative\drivers\71051577.sys [2011/10/16 00:11:25 | 000,008,704 | ---- | M] () -- C:\Users\Jay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/10/12 16:48:21 | 000,001,846 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk [2011/10/12 16:07:22 | 000,002,001 | ---- | M] () -- C:\Users\Public\Desktop\Nitro PDF Reader.lnk [2011/10/12 14:24:22 | 000,381,664 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT [2011/10/10 08:31:18 | 000,017,200 | ---- | M] (Nitro PDF Software) -- C:\windows\SysNative\nitrolocalui2.dll [2011/10/10 08:31:16 | 000,028,976 | ---- | M] (Nitro PDF Software) -- C:\windows\SysNative\nitrolocalmon2.dll [2011/10/07 18:47:56 | 000,016,528 | ---- | M] (COMODO) -- C:\windows\SysNative\drivers\cmderd.sys [2011/10/07 18:47:14 | 000,041,200 | ---- | M] (COMODO) -- C:\windows\SysNative\cmdcsr.dll [2011/10/07 18:47:12 | 000,300,200 | ---- | M] (COMODO) -- C:\windows\SysWow64\guard32.dll [2011/10/07 18:47:10 | 000,388,280 | ---- | M] (COMODO) -- C:\windows\SysNative\guard64.dll [2011/09/22 17:48:35 | 000,156,556 | -H-- | M] () -- C:\windows\SysWow64\mlfcache.dat [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011/10/22 10:36:16 | 000,000,298 | -HS- | C] () -- C:\windows\6821560drv.spi [2011/10/22 10:24:27 | 000,000,238 | ---- | C] () -- C:\windows\tasks\RunAsStdUser Task.job [2011/10/22 01:10:27 | 000,025,160 | ---- | C] () -- C:\windows\SysNative\drivers\hitmanpro35.sys [2011/10/12 16:48:21 | 000,001,846 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk [2011/10/12 16:07:22 | 000,002,001 | ---- | C] () -- C:\Users\Public\Desktop\Nitro PDF Reader.lnk [2011/08/22 09:54:54 | 000,258,864 | ---- | C] () -- C:\windows\SUPDRun.exe [2011/08/18 23:39:46 | 000,000,017 | ---- | C] () -- C:\Users\Jay\AppData\Local\resmon.resmoncfg [2011/07/14 15:50:25 | 000,156,556 | -H-- | C] () -- C:\windows\SysWow64\mlfcache.dat [2011/06/22 22:33:22 | 000,008,704 | ---- | C] () -- C:\Users\Jay\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/06/19 11:52:08 | 000,000,262 | ---- | C] () -- C:\windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini [2011/06/18 23:36:15 | 000,057,344 | ---- | C] () -- C:\windows\SysWow64\ArmAccess.dll [2011/06/18 20:44:25 | 000,743,066 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI [2011/06/18 19:04:17 | 000,000,022 | -HS- | C] () -- C:\Users\Jay\AppData\Roaming\Sys2662.Config.Repository.bin [2011/06/18 17:58:30 | 000,482,408 | ---- | C] () -- C:\windows\ssndii.exe [2011/06/18 16:26:14 | 000,003,584 | ---- | C] () -- C:\windows\SysWow64\RemoveFocusRect.dll [2011/04/01 00:07:02 | 010,877,272 | ---- | C] () -- C:\windows\SysWow64\LogiDPP.dll [2011/04/01 00:07:02 | 000,102,744 | ---- | C] () -- C:\windows\SysWow64\LogiDPPApp.exe [2011/04/01 00:06:56 | 000,331,608 | ---- | C] () -- C:\windows\SysWow64\DevManagerCore.dll [2011/03/17 12:51:44 | 000,003,929 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat [2011/01/08 07:30:02 | 000,139,264 | ---- | C] () -- C:\windows\SysWow64\ustor.dll [2011/01/08 07:30:02 | 000,040,960 | ---- | C] () -- C:\windows\SysWow64\UMonit.exe [2011/01/08 07:30:00 | 000,001,393 | ---- | C] () -- C:\windows\SysWow64\IconCfg0.ini [2011/01/08 07:30:00 | 000,000,722 | ---- | C] () -- C:\windows\SysWow64\ProductName.ini [2011/01/08 07:27:23 | 000,008,192 | ---- | C] () -- C:\windows\SysWow64\drivers\IntelMEFWVer.dll [2011/01/08 07:21:31 | 000,201,728 | ---- | C] () -- C:\windows\SetDrive.exe [2011/01/08 07:21:30 | 000,036,864 | ---- | C] () -- C:\windows\WinWait.exe [2010/11/22 22:04:40 | 000,097,121 | ---- | C] () -- C:\windows\SysWow64\atxaux64.exe [2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\windows\SysWow64\physxcudart_20.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelTraditionalChinese.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelSwedish.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelSpanish.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelSimplifiedChinese.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelPortugese.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelKorean.dll [2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelJapanese.dll [2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelGerman.dll [2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\windows\SysWow64\AgCPanelFrench.dll [2009/07/26 16:07:52 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin [2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat [2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT [2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat [2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin [2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll [2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll [2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat [color=#E56717]========== LOP Check ==========[/color] [2011/06/19 17:37:47 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Auslogics [2011/09/22 18:23:29 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Design Science [2011/10/12 16:06:53 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Downloaded Installations [2011/10/21 22:14:14 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Dropbox [2011/09/15 23:03:06 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\GPSoftware [2011/06/18 17:37:45 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\johnsadventures.com [2011/06/18 18:07:04 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Leadertech [2011/07/26 16:09:02 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\LolClient [2011/08/09 22:57:31 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Mp3tag [2011/10/17 00:50:39 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Nitro PDF [2011/10/12 16:02:06 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Notepad++ [2011/09/12 10:27:34 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\PotPlayerMini64 [2011/08/23 21:06:56 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Rainmeter [2011/06/18 22:32:09 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\SoftGrid Client [2011/08/23 20:52:07 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\Stickies [2011/08/18 21:59:49 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\USBSafelyRemove [2011/10/21 18:29:27 | 000,000,000 | ---D | M] -- C:\Users\Jay\AppData\Roaming\uTorrent [2011/10/22 10:24:27 | 000,000,238 | ---- | M] () -- C:\windows\Tasks\RunAsStdUser Task.job [2011/09/27 11:37:04 | 000,032,540 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 178 bytes -> C:\ProgramData\Temp:58A5270D @Alternate Data Stream - 176 bytes -> C:\ProgramData\Temp:07BF512B < End of report >How do I rid myself of this infection?