Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-03-2014 01
Ran by james (administrator) on KIMCLARK on 03-03-2014 23:46:28
Running from C:\Users\james\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJ1YP7UL
Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(Nero AG) C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
() C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(SonicWALL Inc.) C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEService.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
() C:\Program Files\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(SonicWALL Inc.) C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe
() C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(TOSHIBA) C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
() C:\Program Files\Verizon Cloud\Verizon Cloud Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TOSHIBA CORPORATION) C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_70_ActiveX.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6037504 2008-04-08] (Realtek Semiconductor)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-04-15] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-08-14] (Synaptics, Inc.)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [431456 2008-02-06] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [505720 2008-06-02] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [716800 2008-05-09] (TOSHIBA Corporation)
HKLM\...\Run: [NDSTray.exe] - NDSTray.exe
HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [SonicWALLNetExtender] - C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEGui.exe [1103744 2010-04-01] (SonicWALL Inc.)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM\...\Run: [VMM Mode Selection] - C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe [43520 2011-02-14] ()
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-07] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-1036789798-630842878-1665978630-1000\...\Run: [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [430080 2008-04-24] (TOSHIBA)
HKU\S-1-5-21-1036789798-630842878-1665978630-1000\...\Run: [HLBackupScheduler] - C:\Program Files\Verizon Cloud\Verizon Cloud Service.exe [9384256 2014-02-05] ()
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [123392 2010-08-25] (Google)
Startup: C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=TSHB&bmod=TSHB
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {BC1383D9-01AE-4CC9-BEBC-5223028D7767} URL = http://www.google.co...ng}&rlz=1I7TSHB
SearchScopes: HKCU - DefaultScope {2E80422B-6D67-420D-9641-BC8FEE77ADA7} URL = http://delicious.com...p={searchTerms}
SearchScopes: HKCU - {2E80422B-6D67-420D-9641-BC8FEE77ADA7} URL = http://delicious.com...p={searchTerms}
SearchScopes: HKCU - {BC1383D9-01AE-4CC9-BEBC-5223028D7767} URL = http://www.google.co...TSHB_en___US342
SearchScopes: HKCU - {E233B837-D73B-4E17-9005-E3AC11578FC2} URL = http://www.flickr.co...q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
BHO: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files\AVAST Software\avast! Ad Blocker IE\Adblocker32.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab
DPF: {6EEFD7B1-B26C-440D-B55A-1EC677189F30} https://vpn.stardynamics.com/NELX.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
FireFox:
========
FF ProfilePath: C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\7y7jhqp3.default
FF DefaultSearchEngine: Google
FF Homepage: www.google.com
FF SelectedSearchEngine: Google
FF SearchEngineOrder.1: Google
FF Keyword.URL: https://www.google.com/search
FF NewTab: www.google.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tnt2ghost.com/Plugin - C:\Users\james\AppData\Local\TNT2\2.0.0.1250\npTNT2ghost.dll (Search.Us.com)
FF Plugin HKCU: @tnt2toolbar.com/Plugin - C:\Users\james\AppData\Local\TNT2\2.0.0.1250\npTNT2.dll (Search.Us.com)
FF Plugin HKCU: @yahoo.com/BrowserPlus,version=2.9.8 - C:\Users\james\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npWTHost.dll (WildTangent)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\googledesktop.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Yahooober26600900.gif
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Yahooober26600900.src
FF Extension: LavaFox V1-Blue - C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\7y7jhqp3.default\Extensions\djziggy@gmail(465).com [2011-02-13]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\7y7jhqp3.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-06-13]
FF Extension: DownloadHelper - C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\7y7jhqp3.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(466) [2011-02-13]
FF Extension: Download Statusbar - C:\Users\james\AppData\Roaming\Mozilla\Firefox\Profiles\7y7jhqp3.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2011-04-20]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-11]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR Extension: (YouTube) - C:\Users\james\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-01-13]
CHR Extension: (Google Search) - C:\Users\james\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-07]
CHR Extension: (Google Wallet) - C:\Users\james\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-21]
CHR Extension: (Gmail) - C:\Users\james\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-07]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-12-02]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-07] (AVAST Software)
R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION)
S4 GameConsoleService; C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe [246520 2010-04-16] (WildTangent, Inc.)
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-08-25] (Google)
R2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-10] (Nero AG)
R2 MotoHelper; C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe [223088 2011-04-26] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 SONICWALL_NetExtender; C:\Program Files\SonicWALL\SSL-VPN\NetExtender\NEService.exe [313216 2010-04-01] (SonicWALL Inc.)
R2 TOSHIBA SMART Log Service; C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [126976 2007-12-03] (TOSHIBA Corporation)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.)
S2 aswUpdSv; "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" [X]
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-02-07] (AVAST Software)
R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [54832 2014-02-07] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2013-12-02] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-02-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410784 2014-02-07] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2014-02-07] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2013-12-29] ()
R3 NxDrv; C:\Windows\System32\DRIVERS\NxDrv.sys [22600 2009-10-21] (SonicWALL Inc.)
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [347648 2009-06-10] (Realtek Semiconductor Corporation )
R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows ® Codename Longhorn DDK provider)
S3 SUSTUCAM; C:\Windows\System32\DRIVERS\sustucam.sys [47360 2009-01-07] ()
S3 SUSTUCAP; C:\Windows\System32\DRIVERS\sustucap.sys [47360 2009-01-07] ()
S3 SUSTUCAU; C:\Windows\System32\DRIVERS\sustucau.sys [28032 2009-01-07] (Susteen, Inc.)
S3 SVRPEDRV; C:\Windows\System32\sysprep\PEDrv.sys [9216 2008-01-18] (Inventec Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\james\AppData\Local\Temp\catchme.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 IO_Memory; \??\C:\WINDOWS\SYSTEM32\SYSPREP\Drivers\ioport.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PCTINDIS5; \??\C:\Windows\system32\PCTINDIS5.SYS [X]
S3 usbbus; system32\DRIVERS\lgusbbus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgusbdiag.sys [X]
S3 USBModem; system32\DRIVERS\lgusbmodem.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-03 23:46 - 2014-03-03 23:46 - 00000000 ____D () C:\FRST
2014-02-26 01:31 - 2014-02-26 01:31 - 00016386 _____ () C:\ComboFix.txt
2014-02-26 01:15 - 2011-06-26 01:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-26 01:15 - 2010-11-07 12:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-26 01:15 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-26 01:15 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-26 01:15 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-26 01:15 - 2000-08-30 19:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-26 01:15 - 2000-08-30 19:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-26 01:15 - 2000-08-30 19:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-26 01:14 - 2014-02-26 01:31 - 00000000 ____D () C:\Qoobox
2014-02-26 01:14 - 2014-02-26 01:29 - 00000000 ____D () C:\Windows\erdnt
2014-02-26 00:59 - 2014-02-26 00:59 - 00000000 ____D () C:\Program Files\QuickTime
2014-02-26 00:55 - 2014-02-26 00:55 - 05185084 ____R (Swearware) C:\Users\james\Desktop\ComboFix.exe
2014-02-22 13:47 - 2014-02-22 13:47 - 00056688 ____N () C:\Users\james\Desktop\hotelcoupons.com-hotels-ohio-dayton-hawthorn-suites-dayt.tif
2014-02-22 12:20 - 2014-02-22 12:20 - 00002259 _____ () C:\Users\james\Desktop\JRT.txt
2014-02-22 12:16 - 2014-02-22 12:16 - 00000000 ____D () C:\Windows\ERUNT
2014-02-22 12:15 - 2014-02-22 12:15 - 01037734 _____ (Thisisu) C:\Users\james\Desktop\JRT.exe
2014-02-22 12:07 - 2014-02-22 12:07 - 00009564 _____ () C:\Users\james\Desktop\AdwCleaner[S0].txt
2014-02-22 11:51 - 2014-02-22 12:01 - 00000000 ____D () C:\AdwCleaner
2014-02-22 11:49 - 2014-02-22 11:49 - 01037734 _____ (Thisisu) C:\Users\james\Downloads\JRT.exe
2014-02-22 11:47 - 2014-02-22 11:47 - 01241834 _____ () C:\Users\james\Desktop\AdwCleaner.exe
2014-02-21 03:24 - 2014-02-21 03:24 - 00602112 _____ (OldTimer Tools) C:\Users\james\Downloads\OTL (1).exe
2014-02-13 03:03 - 2014-02-05 03:58 - 12345344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-13 03:03 - 2014-02-05 03:56 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-13 03:03 - 2014-02-05 03:53 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-13 03:03 - 2014-02-05 03:51 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-13 03:03 - 2014-02-05 03:50 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-13 03:03 - 2014-02-05 03:49 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-13 03:03 - 2014-02-05 03:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-13 03:03 - 2014-02-05 03:48 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-13 03:03 - 2014-02-05 03:48 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-13 03:03 - 2014-02-05 03:48 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-13 03:03 - 2014-02-05 03:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-13 03:03 - 2014-02-05 03:48 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-13 03:03 - 2014-02-05 03:47 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-13 03:03 - 2014-02-05 03:47 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-13 03:03 - 2014-02-05 03:47 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-13 03:03 - 2014-02-05 03:46 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-13 02:57 - 2014-02-13 02:57 - 00793600 _____ () C:\Users\james\Documents\PUBH-8002-2 ClarkK FinalProject.ppt
2014-02-12 22:15 - 2013-12-04 21:12 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 22:00 - 2014-02-12 22:00 - 00001781 _____ () C:\Users\james\Desktop\Verizon Cloud.lnk
2014-02-12 21:59 - 2014-02-12 22:00 - 00000000 ____D () C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Verizon Cloud
2014-02-12 21:55 - 2014-02-12 21:55 - 44163440 _____ (Installation Program) C:\Users\james\Downloads\3.5.108-update.exe
2014-02-05 07:10 - 2014-02-05 07:10 - 00602112 _____ () C:\Windows\system32\xvid.dll
==================== One Month Modified Files and Folders =======
2014-03-03 23:46 - 2014-03-03 23:46 - 00000000 ____D () C:\FRST
2014-03-03 23:45 - 2009-07-31 00:50 - 01997632 _____ () C:\Windows\WindowsUpdate.log
2014-03-03 23:27 - 2010-02-13 12:49 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-03 23:22 - 2010-02-13 12:49 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-03 23:10 - 2012-03-31 20:14 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-03 23:10 - 2006-11-02 07:45 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-03 23:10 - 2006-11-02 07:45 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-26 04:03 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\tracing
2014-02-26 02:12 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-26 02:03 - 2006-11-02 05:33 - 00778902 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-26 01:47 - 2011-02-25 02:32 - 00000000 ____D () C:\ProgramData\T-Mobile
2014-02-26 01:46 - 2010-07-10 07:03 - 00000000 ____D () C:\Program Files\Common Files\PctelEapPeer Authentication
2014-02-26 01:45 - 2009-10-12 01:12 - 00000000 ____D () C:\Users\james\AppData\Roaming\Shareaza
2014-02-26 01:45 - 2009-10-12 01:12 - 00000000 ____D () C:\Program Files\Shareaza
2014-02-26 01:39 - 2013-07-09 01:44 - 00000000 ____D () C:\Users\james\AppData\Local\Backup Assistant Plus
2014-02-26 01:38 - 2013-07-07 21:12 - 00000000 ____D () C:\Users\james\AppData\Local\HTC MediaHub
2014-02-26 01:37 - 2010-01-21 21:07 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-02-26 01:37 - 2008-01-20 22:02 - 00157202 _____ () C:\Windows\PFRO.log
2014-02-26 01:37 - 2006-11-02 07:58 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-26 01:36 - 2009-08-24 17:56 - 00000012 _____ () C:\Windows\bthservsdp.dat
2014-02-26 01:36 - 2006-11-02 07:58 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-26 01:31 - 2014-02-26 01:31 - 00016386 _____ () C:\ComboFix.txt
2014-02-26 01:31 - 2014-02-26 01:14 - 00000000 ____D () C:\Qoobox
2014-02-26 01:31 - 2006-11-02 06:18 - 00000000 ___RD () C:\Users\Public
2014-02-26 01:29 - 2014-02-26 01:14 - 00000000 ____D () C:\Windows\erdnt
2014-02-26 01:28 - 2006-11-02 05:23 - 00000215 _____ () C:\Windows\system.ini
2014-02-26 00:59 - 2014-02-26 00:59 - 00000000 ____D () C:\Program Files\QuickTime
2014-02-26 00:55 - 2014-02-26 00:55 - 05185084 ____R (Swearware) C:\Users\james\Desktop\ComboFix.exe
2014-02-22 13:47 - 2014-02-22 13:47 - 00056688 ____N () C:\Users\james\Desktop\hotelcoupons.com-hotels-ohio-dayton-hawthorn-suites-dayt.tif
2014-02-22 12:20 - 2014-02-22 12:20 - 00002259 _____ () C:\Users\james\Desktop\JRT.txt
2014-02-22 12:16 - 2014-02-22 12:16 - 00000000 ____D () C:\Windows\ERUNT
2014-02-22 12:15 - 2014-02-22 12:15 - 01037734 _____ (Thisisu) C:\Users\james\Desktop\JRT.exe
2014-02-22 12:07 - 2014-02-22 12:07 - 00009564 _____ () C:\Users\james\Desktop\AdwCleaner[S0].txt
2014-02-22 12:01 - 2014-02-22 11:51 - 00000000 ____D () C:\AdwCleaner
2014-02-22 11:51 - 2010-07-13 00:27 - 00001898 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-22 11:49 - 2014-02-22 11:49 - 01037734 _____ (Thisisu) C:\Users\james\Downloads\JRT.exe
2014-02-22 11:47 - 2014-02-22 11:47 - 01241834 _____ () C:\Users\james\Desktop\AdwCleaner.exe
2014-02-21 03:36 - 2012-10-06 16:59 - 00110568 _____ () C:\Users\james\Downloads\OTL.Txt
2014-02-21 03:24 - 2014-02-21 03:24 - 00602112 _____ (OldTimer Tools) C:\Users\james\Downloads\OTL (1).exe
2014-02-21 02:49 - 2013-12-12 21:48 - 00000000 ____D () C:\Users\james\Documents\PhD Homework
2014-02-20 23:42 - 2012-03-31 20:14 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-02-20 23:42 - 2011-06-05 00:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-02-13 03:45 - 2009-07-23 04:17 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-13 03:29 - 2013-09-07 02:21 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-13 03:20 - 2006-11-02 05:24 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-02-13 03:10 - 2006-11-02 05:23 - 00000275 _____ () C:\Windows\win.ini
2014-02-13 02:57 - 2014-02-13 02:57 - 00793600 _____ () C:\Users\james\Documents\PUBH-8002-2 ClarkK FinalProject.ppt
2014-02-12 22:00 - 2014-02-12 22:00 - 00001781 _____ () C:\Users\james\Desktop\Verizon Cloud.lnk
2014-02-12 22:00 - 2014-02-12 21:59 - 00000000 ____D () C:\Users\james\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Verizon Cloud
2014-02-12 21:59 - 2013-10-18 02:18 - 00000000 ____D () C:\Program Files\Verizon Cloud
2014-02-12 21:59 - 2013-07-09 01:42 - 00000000 ____D () C:\Program Files\ffdshow
2014-02-12 21:55 - 2014-02-12 21:55 - 44163440 _____ (Installation Program) C:\Users\james\Downloads\3.5.108-update.exe
2014-02-12 21:55 - 2014-01-23 21:20 - 00000309 _____ () C:\Users\james\Downloads\3.5.108-update.xml
2014-02-07 00:56 - 2013-10-11 01:49 - 00001800 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-02-07 00:55 - 2013-10-11 01:49 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-07 00:55 - 2013-10-11 01:49 - 00410784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-02-07 00:55 - 2013-10-11 01:49 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-07 00:55 - 2013-10-11 01:49 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-02-07 00:55 - 2013-10-11 01:49 - 00054832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2014-02-07 00:55 - 2013-10-11 01:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-07 00:55 - 2012-10-09 01:22 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-05 07:10 - 2014-02-05 07:10 - 00602112 _____ () C:\Windows\system32\xvid.dll
2014-02-05 03:58 - 2014-02-13 03:03 - 12345344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-05 03:56 - 2014-02-13 03:03 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-05 03:53 - 2014-02-13 03:03 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-05 03:51 - 2014-02-13 03:03 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-05 03:50 - 2014-02-13 03:03 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-05 03:49 - 2014-02-13 03:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-05 03:49 - 2014-02-13 03:03 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-05 03:48 - 2014-02-13 03:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-05 03:48 - 2014-02-13 03:03 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-05 03:48 - 2014-02-13 03:03 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-05 03:48 - 2014-02-13 03:03 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-05 03:48 - 2014-02-13 03:03 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-05 03:47 - 2014-02-13 03:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-05 03:47 - 2014-02-13 03:03 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-05 03:47 - 2014-02-13 03:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-05 03:46 - 2014-02-13 03:03 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-01 23:52 - 2013-12-15 19:08 - 00001879 _____ () C:\Users\Public\Desktop\HTC Sync Manager.lnk
2014-02-01 23:51 - 2013-07-07 20:31 - 00000000 ____D () C:\Users\james\AppData\Local\Downloaded Installations
2014-02-01 23:38 - 2006-11-02 07:49 - 00168201 _____ () C:\Windows\setupact.log
Files to move or delete:
====================
C:\Users\james\AppData\Roaming\desktop.ini
Some content of TEMP:
====================
C:\Users\james\AppData\Local\Temp\catchme.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-26 01:44
==================== End Of Log ============================