ramping
2013-11-03, 14:00
1. Link back to initial thread: http://forums.spybot.info/showthread.php?69602-Unwanted-
Ads&p=446524#post446524
2. I ran Spybot, again, but this time, as administrator.
After 34:41 minutes, Spybot reported finding 24 "results".
So, I clicked on "Fix Selected".
3. DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16720
Run by Wheelsup Club at 11:34:46 on 2013-11-02
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5872.1861 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe
c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\windows\SysWOW64\java.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\rundll32.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\SaltarSmart\updateSaltarSmart.exe
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files (x86)\SaltarSmart\bin\utilSaltarSmart.exe
C:\Program Files (x86)\UltraVNC Addons\uvnc_service.exe
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Speech\Common\sapisvr.exe
C:\windows\System32\WUDFHost.exe
C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe
C:\Program Files\desksware\Desktop iCalendar Lite\Desktop iCalendar Lite.exe
C:\Program Files (x86)\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\VstaScan\VsAccess.exe
C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\Program Files (x86)\IBM\Lotus\Symphony\framework\rcp\eclipse\plugins
\com.ibm.rcp.base_6.2.3.20110915-1350\win32\x86\symphony.exe
C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\dad9.exe
C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Napster\napster.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\IBM\Lotus\Symphony\framework\shared\eclipse\plugins
\com.ibm.symphony.brand.win32_3.0.1.20120110-2000\program\soffice.bin
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
C:\windows\system32\notepad.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uWindow Title = Internet Explorer, optimized for Bing and MSN
uSearch Bar = res://C:\Program Files (x86)\Copernic Agent
\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
uURLSearchHooks: <No Name>: {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\Program Files (x86)\Copernic
Agent\CopernicAgentExt.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program
Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
uURLSearchHooks: <No Name>: {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
uURLSearchHooks: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
uURLSearchHooks: FCToolbarURLSearchHook Class: {cc376ed9-9e09-4b39-bad5-083d151eaa86} - C:\Program
Files (x86)\Pazera Toolbar\Helper.dll
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uURLSearchHooks: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
uURLSearchHooks: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
mURLSearchHooks: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
mURLSearchHooks: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
mURLSearchHooks: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
mWinlogon: Userinit = userinit.exe
BHO: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security
Scan\3.8.130\McAfeeMSS_IE.dll
BHO: SuperLyrics-16: {11111111-1111-1111-1111-110411411162} - C:\Program Files (x86)\SuperLyrics-
16\SuperLyrics-16-bho.dll
BHO: Pazera Toolbar BHO: {1B169632-4FA6-4BE0-B980-460B5BF7FD08} - C:\Program Files (x86)\Pazera
Toolbar\Toolbar.dll
BHO: Trellian BHO Impl: {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files (x86)\Trellian
\Toolbar\toolbar.dll
BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
BHO: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
BHO: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin
\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files
(x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google
\Google Toolbar\GoogleToolbar_32.dll
BHO: Freecorder extension: {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files
(x86)\Freecorder extension\ScriptHost.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee
\SiteAdvisor\McIEPlg.dll
BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
BHO: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - <orphaned>
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
BHO: SaltarSmart: {d99a4ec9-00bd-4fe4-85a5-4db018351265} - C:\Program Files (x86)\SaltarSmart
\SaltarSmartbho.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files
(x86)\Java\jre6\bin\jp2ssv.dll
BHO: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google
Toolbar\GoogleToolbar_32.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
TB: Trellian &Toolbar: {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files (x86)\Trellian
\Toolbar\toolbar.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files
(x86)\McAfee\SiteAdvisor\McIEPlg.dll
TB: FireShot: {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} -
TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
TB: Pazera Toolbar: {093B3D46-0F87-44CF-B44B-79537F1597E5} - C:\Program Files (x86)\Pazera Toolbar
\Toolbar.dll
TB: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
TB: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google
Toolbar\GoogleToolbar_32.dll
EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet
Explorer\iedvtool.dll
EB: Copernic Agent Results: {6F480F82-C3A6-4D35-96F7-B297AD49FBE8} - C:\Program Files (x86)\Copernic
Agent\CopernicAgentExt.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Speech Recognition] "C:\windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [Update Service] "C:\Program Files (x86)\Common Files\Teknum Systems\update.exe" /startup
uRun: [BIBLauncher] C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe
uRun: [VerControl] C:\Users\WHEELS~1\AppData\Local\TempImg\VerControl.exe
uRun: [SymphonyPreLoad] "C:\Program Files (x86)\IBM\Lotus\Symphony\framework\shared\eclipse\plugins
\com.ibm.symphony.standard.launcher.win32.x86_3.0.1.20120110-2000\IBM Lotus Symphony" -nogui -
nosplash
uRun: [Desktop iCalendar Lite.exe] "C:\Program Files\desksware\Desktop iCalendar Lite\Desktop
iCalendar Lite.exe"
uRunOnce: [Uninstall C:\Users\Wheelsup Club\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64]
C:\windows\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Wheelsup Club\AppData\Local\Microsoft
\SkyDrive\16.4.6013.0910\amd64"
uRunOnce: [Uninstall C:\Users\Wheelsup Club\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] C:
\windows\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Wheelsup Club\AppData\Local\Microsoft
\SkyDrive\16.4.6013.0910"
mRun: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
mRun: [OOTag] C:\Program Files (x86)\Gateway\OOBEOffer\OOTag.exe
mRun: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [NapsterShell] C:\Program Files (x86)\Napster\napster.exe /systray
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support
\APSDaemon.exe"
mRun: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:
\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper
Compact\ASHelper.exe
mRun: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe"
/m=2 /w /h
mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
mRun: "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
dRun: [SearchProtect] \SearchProtect\bin\cltmng.exe
StartupFolder: C:\Users\WHEELS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup
\CORELC~1.LNK - C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\alarm.exe
StartupFolder: C:\Users\WHEELS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup
\DESKTO~1.LNK - C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\dad9.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\CORELR~1.LNK - C:\Program
Files (x86)\Corel\WordPerfect Office 2000\Register\Remind32.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program
Files\McAfee Security Scan\3.8.130\SSScheduler.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SERVIC~1.LNK - C:\Program
Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\VISTAA~1.LNK - C:\VstaScan
\VsAccess.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Download current page with FreshWebSuction - C:\Program Files (x86)\FreshWebmaster
\FreshWebSuction\obiectx_all.htm
IE: Download using FreshWebSuction - C:\Program Files (x86)\FreshWebmaster\FreshWebSuction
\obiectx.htm
IE: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins
\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins
\freeytmp3downloader.htm
IE: Search Using Copernic Agent - C:\Program Files (x86)\Copernic Agent
\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
IE: {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~2\COPERN~1\COPERN~1.EXE
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program
Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~2\COPERN~1\COPERN~1.EXE
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
LSP: %SystemRoot%\system32\vsocklib.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10
-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-
windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-
windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-
windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-
windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: NameServer = 64.71.255.204 64.71.255.198
TCP: Interfaces\{16C6E4AB-95AE-44B4-B300-BF7F85B75A16} : DHCPNameServer = 64.71.255.204
64.71.255.198
TCP: Interfaces\{7A83BCC7-06FE-4C29-BFF1-A71A0A9D6DB9} : DHCPNameServer = 64.71.255.204
64.71.255.198
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - C:\Program Files (x86)\Copernic
Agent\CopernicAgentExt.dll
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - C:\Program Files
(x86)\Copernic Agent\CopernicAgentExt.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\McIEPlg.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure
Networks Shared\Platform\puresp4.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo
Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= c:\progra~3\browse~1\25986~1.67\{c16c1~1\browse~1.dll
SSODL: WebCheck - <orphaned>
x64-BHO: SuperLyrics-16: {11111111-1111-1111-1111-110411411162} - C:\Program Files
(x86)\SuperLyrics-16\SuperLyrics-16-bho64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files
\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files
\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files
(x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Freecorder extension x64: {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files
\Freecorder extension x64\ScriptHost.dll
x64-BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files
(x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - <orphaned>
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files
\Java\jre7\bin\jp2ssv.dll
x64-BHO: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
x64-TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files
(x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-TB: FireShot: {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} -
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google
\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [OOTag] C:\Program Files (x86)\Gateway\OOBEOffer\ootag.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - <orphaned>
x64-IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - <orphaned>
x64-Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - <orphaned>
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files
\Pure Networks Shared\Platform\amd64\puresp4.dll
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Wheelsup Club\AppData\Roaming\Mozilla\Firefox\Profiles
\51iipmx9.default-1368301715119\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?
ctid=CT3298580&CUI=UN41812124047612243&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?
ctid=CT3298580&SearchSource=2&CUI=UN41812124047612243&UM=2&q=
FF - prefs.js: network.proxy.ftp - 202.147.204.125
FF - prefs.js: network.proxy.ftp_port - 8888
FF - prefs.js: network.proxy.gopher - 202.147.204.125
FF - prefs.js: network.proxy.gopher_port - 8888
FF - prefs.js: network.proxy.http - 202.147.204.125
FF - prefs.js: network.proxy.http_port - 8888
FF - prefs.js: network.proxy.socks - 202.147.204.125
FF - prefs.js: network.proxy.socks_port - 8888
FF - prefs.js: network.proxy.ssl - 202.147.204.125
FF - prefs.js: network.proxy.ssl_port - 8888
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Virtual Earth 3D\npVE3D.dll
FF - plugin: C:\Program Files (x86)\Winamp Detect\npwachk.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMSS.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: 2013-09-16 14:56; {90a1b331-c2b4-4933-9f63-ba7b84d60d58}; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\{90a1b331-c2b4-
4933-9f63-ba7b84d60d58}
FF - ExtSQL: 2013-10-03 15:24; jid0-KMOFrRnd6cHkSQEU5WJxd4Vz7SA@jetpack; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\jid0-
KMOFrRnd6cHkSQEU5WJxd4Vz7SA@jetpack.xpi
FF - ExtSQL: 2013-10-03 15:24; arpit3@techraga.in; C:\Users\Wheelsup Club\AppData\Roaming\Mozilla
\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\arpit3@techraga.in.xpi
FF - ExtSQL: 2013-10-03 15:25; proxytool@proxylist.co; C:\Users\Wheelsup Club\AppData\Roaming
\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\proxytool@proxylist.co.xpi
FF - ExtSQL: 2013-10-03 16:59; firefox@saltarsmart.biz; C:\Users\Wheelsup Club\AppData\Roaming
\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\firefox@saltarsmart.biz.xpi
FF - ExtSQL: 2013-10-15 09:40; jid0-XXocAsQYPfKHSY8ebTi0VcX8eNQ@jetpack; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\jid0-
XXocAsQYPfKHSY8ebTi0VcX8eNQ@jetpack.xpi
FF - ExtSQL: 2013-10-23 14:10; {e8f509f0-b677-11de-8a39-0800200c9a66}; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\{e8f509f0-b677-
11de-8a39-0800200c9a66}.xpi
FF - ExtSQL: 2013-10-23 14:10; save-as-pdf-ff@pdfcrowd.com; C:\Users\Wheelsup Club\AppData\Roaming
\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\save-as-pdf-ff@pdfcrowd.com.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 ahcix64s;ahcix64s;C:\windows\System32\drivers\ahcix64s.sys [2010-5-31 235312]
R0 MpFilter;Microsoft Malware Protection Driver;C:\windows\System32\drivers\MpFilter.sys [2013-6-18
247216]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/12/15 09:45:12];C:\Program Files
(x86)\CyberLink\PowerDVD9\000.fcl [2010-2-8 146928]
R2 AMD External Events Utility;AMD External Events Utility;C:\windows\System32\atiesrxx.exe [2012-7
-4 238080]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
[2012-7-4 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys
[2012-3-5 53888]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared
\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 Greg_Service;GRegService;C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe [2009-8-28
1150496]
R2 LinksysUpdater;Linksys Updater;C:\Program Files (x86)\Linksys\Linksys Updater\bin
\LinksysUpdater.exe [2008-11-13 204800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
[2013-10-3 121616]
R2 NisDrv;Microsoft Network Inspection System;C:\windows\System32\drivers\NisDrvWFP.sys [2011-4-27
139616]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy
2\SDFSSvc.exe [2013-10-30 3921880]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy
2\SDUpdSvc.exe [2013-10-30 1042272]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search &
Destroy 2\SDWSCSvc.exe [2013-10-30 171416]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application
Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 SrvUpdater;Software Updater;C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe [2013-2-18
31744]
R2 Update SaltarSmart;Update SaltarSmart;C:\Program Files (x86)\SaltarSmart\updateSaltarSmart.exe
[2013-10-3 65312]
R2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
[2010-5-31 243232]
R2 Util SaltarSmart;Util SaltarSmart;C:\Program Files (x86)\SaltarSmart\bin\utilSaltarSmart.exe
[2013-10-30 65312]
R2 Uvnc_service;Uvnc_service;C:\Program Files (x86)\UltraVNC Addons\uvnc_service.exe [2013-3-22
63296]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin
\4zbarsvc.exe [2013-3-18 42504]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB
\vmware-usbarbitrator64.exe [2011-8-29 846448]
R3 amdiox64;AMD IO Driver;C:\windows\System32\drivers\amdiox64.sys [2012-7-12 46136]
R3 anvsnddrv;AnvSoft Virtual Sound Device;C:\windows\System32\drivers\anvsnddrv.sys [2013-3-19
33872]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\windows\System32\drivers
\AtihdW76.sys [2012-2-23 95760]
R3 AVer7231_x64;AVerMedia 7231 capture service;C:\windows\System32\drivers\AVer7231_x64.sys [2010-7
-26 1799808]
R3 bbcap;bb_capture_driver;C:\windows\System32\drivers\bbcap.sys [2013-3-22 4608]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-3-14 245760]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-
8-12 366600]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2010-5-31 346144]
R3 rtl819xpn64;Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;C:\windows
\System32\drivers\rtl819xp.sys [2010-2-1 622624]
R3 Sftfs;Sftfs;C:\windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application
Virtualization Client\sftvsa.exe [2013-6-26 207528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows
\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows
\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin
\CltMngSvc.exe --> C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [?]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-4-1
183560]
S3 debutfilter;Debut Filter Driver v6.20.00;C:\windows\System32\drivers\debutfilterx64.sys [2013-3-
23 33488]
S3 fssfltr;fssfltr;C:\windows\System32\drivers\fssfltr.sys [2013-8-14 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety
\fsssvc.exe [2013-2-5 1512448]
S3 GSService;GSService;C:\Windows\SysWOW64\GSService.exe [2013-3-17 448736]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee
Security Scan\3.8.130\McCHSvc.exe [2013-9-6 288776]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers
\rdpvideominiport.sys [2013-3-19 19456]
S3 SndTAudio;SndTAudio;C:\windows\System32\drivers\SndTAudio.sys [2013-3-17 34528]
S3 SWDUMon;SWDUMon;C:\windows\System32\drivers\SWDUMon.sys [2012-3-30 15672]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2013-3-19 57856]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe
[2011-10-27 1255736]
S3 WsAudio_Device(1);WsAudio_Device(1);C:\windows\System32\drivers\VirtualAudio1.sys [2013-3-17
31080]
S3 WsAudio_Device(2);WsAudio_Device(2);C:\windows\System32\drivers\VirtualAudio2.sys [2013-3-17
31080]
S3 WsAudio_Device(3);WsAudio_Device(3);C:\windows\System32\drivers\VirtualAudio3.sys [2013-3-17
31080]
S3 WsAudio_Device(4);WsAudio_Device(4);C:\windows\System32\drivers\VirtualAudio4.sys [2013-3-17
31080]
S3 WsAudio_Device(5);WsAudio_Device(5);C:\windows\System32\drivers\VirtualAudio5.sys [2013-3-17
31080]
.
=============== Created Last 30 ================
.
2013-11-01 20:11:08 10280728 ----a-w- C:\ProgramData\Microsoft\Microsoft
Antimalware\Definition Updates\{01E01A6A-BC83-4FE0-A01C-372922FD9866}\mpengine.dll
2013-11-01 16:05:53 10280728 ------w- C:\ProgramData\Microsoft\Microsoft
Antimalware\Definition Updates\Backup\mpengine.dll
2013-10-31 13:22:17 71048 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-31 13:22:17 692616 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-10-30 13:51:03 21040 ----a-w- C:\windows\System32\sdnclean64.exe
2013-10-30 13:50:45 -------- d-----w- C:\Program Files (x86)\Spybot - Search &
Destroy 2
2013-10-29 18:41:37 -------- d-----w- C:\Program Files\Uninstaller
2013-10-29 18:39:47 -------- d-----w- C:\Program Files (x86)\SaltarSmart
2013-10-29 18:37:13 -------- d-----w- C:\Program Files (x86)\SuperLyrics-16
2013-10-27 12:54:40 -------- d-----w- C:\Program Files\iPod
2013-10-27 12:54:39 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-
52C6199EBF69
2013-10-27 12:54:39 -------- d-----w- C:\Program Files\iTunes
2013-10-27 12:54:39 -------- d-----w- C:\Program Files (x86)\iTunes
2013-10-24 20:31:13 -------- d-----w- C:\Users\Wheelsup Club\AppData\Local
\FreeFileViewer
2013-10-19 14:18:58 965000 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware
\Definition Updates\{09992E5C-E36E-42A4-BEC1-C9B59B97F77E}\gapaengine.dll
2013-10-17 15:44:01 -------- d-----w- C:\Program Files\McAfee Security Scan
2013-10-16 12:57:03 17813896 ----a-w- C:\windows\SysWow64\FlashPlayerInstaller.exe
2013-10-15 20:28:53 -------- d-----w- C:\Program Files (x86)\Flash Movie Player
2013-10-15 14:26:46 163504 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest
\Sqm10145.bin
2013-10-09 17:41:57 -------- d-----w- C:\Users\Wheelsup Club\AppData\Roaming
\DonationCoder
2013-10-09 17:41:44 -------- d-----w- C:\ProgramData\DonationCoder
2013-10-09 17:41:44 -------- d-----w- C:\Program Files (x86)\ScreenshotCaptor
2013-10-09 15:34:28 -------- d-----w- C:\FFOutput
2013-10-09 15:33:33 -------- d-----w- C:\Program Files (x86)\FreeTime
2013-10-09 15:14:36 -------- d-----w- C:\Program Files (x86)\Free All to Image
Jpg-Jpeg Bmp Tiff Png Converter
2013-10-09 14:14:32 -------- d-----w- C:\Users\Wheelsup Club\AppData\Roaming
\Free-backup.info
2013-10-06 02:54:17 -------- d-----w- C:\Program Files (x86)\K-Lite Codec Pack
2013-10-04 20:51:52 -------- d-----w- C:\Program Files (x86)\MPC-HC
.
==================== Find3M ====================
.
2013-09-22 23:28:06 1767936 ----a-w- C:\windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- C:\windows\SysWow64\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- C:\windows\SysWow64\iesysprep.dll
2013-09-22 22:55:10 2241024 ----a-w- C:\windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 ----a-w- C:\windows\System32\jscript9.dll
2013-09-22 22:54:50 67072 ----a-w- C:\windows\System32\iesetup.dll
2013-09-22 22:54:50 136704 ----a-w- C:\windows\System32\iesysprep.dll
2013-09-21 03:38:39 2706432 ----a-w- C:\windows\System32\mshtml.tlb
2013-09-21 03:30:24 2706432 ----a-w- C:\windows\SysWow64\mshtml.tlb
2013-09-21 02:48:36 89600 ----a-w- C:\windows\System32\RegisterIEPKEYs.exe
2013-09-21 02:39:47 71680 ----a-w- C:\windows\SysWow64\RegisterIEPKEYs.exe
2013-09-14 01:10:19 497152 ----a-w- C:\windows\System32\drivers\afd.sys
2013-09-08 02:30:37 1903552 ----a-w- C:\windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14 327168 ----a-w- C:\windows\System32\mswsock.dll
2013-09-08 02:03:58 231424 ----a-w- C:\windows\SysWow64\mswsock.dll
2013-09-04 12:12:11 343040 ----a-w- C:\windows\System32\drivers\usbhub.sys
2013-09-04 12:11:51 325120 ----a-w- C:\windows\System32\drivers\usbport.sys
2013-09-04 12:11:49 99840 ----a-w- C:\windows\System32\drivers\usbccgp.sys
2013-09-04 12:11:43 52736 ----a-w- C:\windows\System32\drivers\usbehci.sys
2013-09-04 12:11:43 30720 ----a-w- C:\windows\System32\drivers\usbuhci.sys
2013-09-04 12:11:42 25600 ----a-w- C:\windows\System32\drivers\usbohci.sys
2013-09-04 12:11:40 7808 ----a-w- C:\windows\System32\drivers\usbd.sys
2013-08-29 02:17:48 5549504 ----a-w- C:\windows\System32\ntoskrnl.exe
2013-08-29 02:16:35 1732032 ----a-w- C:\windows\System32\ntdll.dll
2013-08-29 02:16:28 243712 ----a-w- C:\windows\System32\wow64.dll
2013-08-29 02:16:14 859648 ----a-w- C:\windows\System32\tdh.dll
2013-08-29 02:13:28 878080 ----a-w- C:\windows\System32\advapi32.dll
2013-08-29 01:51:45 3969472 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2013-08-29 01:51:45 3914176 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2013-08-29 01:50:31 5120 ----a-w- C:\windows\SysWow64\wow32.dll
2013-08-29 01:50:30 1292192 ----a-w- C:\windows\SysWow64\ntdll.dll
2013-08-29 01:50:16 619520 ----a-w- C:\windows\SysWow64\tdh.dll
2013-08-29 01:48:17 640512 ----a-w- C:\windows\SysWow64\advapi32.dll
2013-08-29 01:48:15 44032 ----a-w- C:\windows\apppatch\acwow64.dll
2013-08-29 00:49:53 25600 ----a-w- C:\windows\SysWow64\setup16.exe
2013-08-29 00:49:52 7680 ----a-w- C:\windows\SysWow64\instnm.exe
2013-08-29 00:49:52 14336 ----a-w- C:\windows\SysWow64\ntvdm64.dll
2013-08-29 00:49:49 2048 ----a-w- C:\windows\SysWow64\user.exe
2013-08-28 01:21:06 3155968 ----a-w- C:\windows\System32\win32k.sys
2013-08-28 01:12:33 461312 ----a-w- C:\windows\System32\scavengeui.dll
2013-08-21 01:12:32 4812567 ----a-w- C:\Users\Wheelsup Club\FileZilla_3.7.3_win32-
setup.exe
2013-08-18 03:08:39 106496 ----a-w- C:\windows\SysWow64\ATL71.DLL
2013-08-14 01:39:44 1169609 ----a-w- C:\windows\unins001.exe
2013-08-13 17:51:58 4817275 ----a-w- C:\Users\Wheelsup Club\FileZilla_3.7.2_win32-
setup.exe
2013-08-05 02:25:45 155584 ----a-w- C:\windows\System32\drivers\ataport.sys
.
============= FINISH: 11:36:34.80 ===============
4. When I launched Firefox to get back to this post, one of the bothersome ads popped up, in a new
tab, again.
5. aswMBR Log:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-11-02 11:46:31
-----------------------------
11:46:31.670 OS Version: Windows x64 6.1.7601 Service Pack 1
11:46:31.670 Number of processors: 4 586 0x402
11:46:31.680 ComputerName: WHEELSUPCLUB-PC UserName: Wheelsup Club
11:46:36.503 Initialize success
11:49:32.473 AVAST engine defs: 13110200
11:52:53.826 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000074
11:52:53.826 Disk 0 Vendor: WDC_____ 01.0 Size: 953805MB BusType: 8
11:52:53.976 Disk 0 MBR read successfully
11:52:53.976 Disk 0 MBR scan
11:52:54.056 Disk 0 unknown MBR code
11:52:54.066 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 16000 MB offset 2048
11:52:54.116 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 32770048
11:52:54.156 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 937703 MB offset 32974848
11:52:54.236 Disk 0 scanning C:\windows\system32\drivers
11:53:12.308 Service scanning
11:53:52.652 Modules scanning
11:53:52.652 Disk 0 trace - called modules:
11:53:52.672 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix64s.sys
11:53:52.682 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80067c8060]
11:53:52.682 3 CLASSPNP.SYS[fffff880018a443f] -> nt!IofCallDriver -> \Device\00000074
[0xfffffa8005e389c0]
11:53:55.783 AVAST engine scan C:\windows
11:54:05.724 AVAST engine scan C:\windows\system32
11:59:10.902 AVAST engine scan C:\windows\system32\drivers
11:59:40.715 AVAST engine scan C:\Users\Wheelsup Club
01:47:13.742 AVAST engine scan C:\ProgramData
01:10:57.966 Scan finished successfully
06:43:12.596 Disk 0 MBR has been saved successfully to "C:\Users\Wheelsup Club\Desktop\MBR.dat"
06:43:12.636 The log file has been saved successfully to "C:\Users\Wheelsup Club\Desktop
\aswMBR.txt"
6. I think I successfully uploaded the [I]"attached.zip" file, in the "Managed Attachments" facility.
Kindly let me know, though, if I did something wrong and need to try uploading the file, again.
- r
Ads&p=446524#post446524
2. I ran Spybot, again, but this time, as administrator.
After 34:41 minutes, Spybot reported finding 24 "results".
So, I clicked on "Fix Selected".
3. DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16720
Run by Wheelsup Club at 11:34:46 on 2013-11-02
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5872.1861 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe
c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\windows\SysWOW64\java.exe
C:\windows\system32\rundll32.exe
C:\windows\system32\rundll32.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\SaltarSmart\updateSaltarSmart.exe
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files (x86)\SaltarSmart\bin\utilSaltarSmart.exe
C:\Program Files (x86)\UltraVNC Addons\uvnc_service.exe
C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\windows\SysWOW64\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
C:\windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Speech\Common\sapisvr.exe
C:\windows\System32\WUDFHost.exe
C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe
C:\Program Files\desksware\Desktop iCalendar Lite\Desktop iCalendar Lite.exe
C:\Program Files (x86)\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\VstaScan\VsAccess.exe
C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\Program Files (x86)\IBM\Lotus\Symphony\framework\rcp\eclipse\plugins
\com.ibm.rcp.base_6.2.3.20110915-1350\win32\x86\symphony.exe
C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\dad9.exe
C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\Napster\napster.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\IBM\Lotus\Symphony\framework\shared\eclipse\plugins
\com.ibm.symphony.brand.win32_3.0.1.20120110-2000\program\soffice.bin
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
C:\windows\system32\notepad.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uWindow Title = Internet Explorer, optimized for Bing and MSN
uSearch Bar = res://C:\Program Files (x86)\Copernic Agent
\CopernicAgentExt.dll/INTEGRATION_BAND_SEARCHBAR_HTML
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
uURLSearchHooks: <No Name>: {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\Program Files (x86)\Copernic
Agent\CopernicAgentExt.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program
Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll
uURLSearchHooks: <No Name>: {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
uURLSearchHooks: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
uURLSearchHooks: FCToolbarURLSearchHook Class: {cc376ed9-9e09-4b39-bad5-083d151eaa86} - C:\Program
Files (x86)\Pazera Toolbar\Helper.dll
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uURLSearchHooks: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
uURLSearchHooks: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
mURLSearchHooks: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
mURLSearchHooks: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
mURLSearchHooks: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
mWinlogon: Userinit = userinit.exe
BHO: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
BHO: MSS+ Identifier: {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security
Scan\3.8.130\McAfeeMSS_IE.dll
BHO: SuperLyrics-16: {11111111-1111-1111-1111-110411411162} - C:\Program Files (x86)\SuperLyrics-
16\SuperLyrics-16-bho.dll
BHO: Pazera Toolbar BHO: {1B169632-4FA6-4BE0-B980-460B5BF7FD08} - C:\Program Files (x86)\Pazera
Toolbar\Toolbar.dll
BHO: Trellian BHO Impl: {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files (x86)\Trellian
\Toolbar\toolbar.dll
BHO: Toolbar BHO: {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
BHO: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
BHO: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin
\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files
(x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google
\Google Toolbar\GoogleToolbar_32.dll
BHO: Freecorder extension: {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files
(x86)\Freecorder extension\ScriptHost.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee
\SiteAdvisor\McIEPlg.dll
BHO: Search Assistant BHO: {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
BHO: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - <orphaned>
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -
BHO: SaltarSmart: {d99a4ec9-00bd-4fe4-85a5-4db018351265} - C:\Program Files (x86)\SaltarSmart
\SaltarSmartbho.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files
(x86)\Java\jre6\bin\jp2ssv.dll
BHO: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google
Toolbar\GoogleToolbar_32.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
TB: Trellian &Toolbar: {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files (x86)\Trellian
\Toolbar\toolbar.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files
(x86)\McAfee\SiteAdvisor\McIEPlg.dll
TB: FireShot: {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} -
TB: VideoDownloadConverter: {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files
(x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll
TB: freevideomaster Toolbar: {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files
(x86)\freevideomaster\tbfree.dll
TB: Pazera Toolbar: {093B3D46-0F87-44CF-B44B-79537F1597E5} - C:\Program Files (x86)\Pazera Toolbar
\Toolbar.dll
TB: ytbyclick B1 Toolbar: {49c53dce-afa0-49a1-a08b-2eb8e8444128} - C:\Program Files
(x86)\ytbyclick_B1\prxtbytby.dll
TB: MixiDJ V44 Toolbar: {90a1b331-c2b4-4933-9f63-ba7b84d60d58} - C:\Program Files
(x86)\MixiDJ_V44\prxtbMixi.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google
Toolbar\GoogleToolbar_32.dll
EB: Developer Tools: {1A6FE369-F28C-4AD9-A3E6-2BCB50807CF1} - C:\Program Files (x86)\Internet
Explorer\iedvtool.dll
EB: Copernic Agent Results: {6F480F82-C3A6-4D35-96F7-B297AD49FBE8} - C:\Program Files (x86)\Copernic
Agent\CopernicAgentExt.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Speech Recognition] "C:\windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [Update Service] "C:\Program Files (x86)\Common Files\Teknum Systems\update.exe" /startup
uRun: [BIBLauncher] C:\Program Files (x86)\Business-in-a-Box\BIBLauncher.exe
uRun: [VerControl] C:\Users\WHEELS~1\AppData\Local\TempImg\VerControl.exe
uRun: [SymphonyPreLoad] "C:\Program Files (x86)\IBM\Lotus\Symphony\framework\shared\eclipse\plugins
\com.ibm.symphony.standard.launcher.win32.x86_3.0.1.20120110-2000\IBM Lotus Symphony" -nogui -
nosplash
uRun: [Desktop iCalendar Lite.exe] "C:\Program Files\desksware\Desktop iCalendar Lite\Desktop
iCalendar Lite.exe"
uRunOnce: [Uninstall C:\Users\Wheelsup Club\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64]
C:\windows\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Wheelsup Club\AppData\Local\Microsoft
\SkyDrive\16.4.6013.0910\amd64"
uRunOnce: [Uninstall C:\Users\Wheelsup Club\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] C:
\windows\System32\cmd.exe /q /c rmdir /s /q "C:\Users\Wheelsup Club\AppData\Local\Microsoft
\SkyDrive\16.4.6013.0910"
mRun: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
mRun: [OOTag] C:\Program Files (x86)\Gateway\OOBEOffer\OOTag.exe
mRun: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [NapsterShell] C:\Program Files (x86)\Napster\napster.exe /systray
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support
\APSDaemon.exe"
mRun: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:
\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper
Compact\ASHelper.exe
mRun: [VideoDownloadConverter Search Scope Monitor] "C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe"
/m=2 /w /h
mRun: [VideoDownloadConverter_4z Browser Plugin Loader] C:\PROGRA~2\VIDEOD~2\bar\1.bin\4zbrmon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
mRun: "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
dRun: [SearchProtect] \SearchProtect\bin\cltmng.exe
StartupFolder: C:\Users\WHEELS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup
\CORELC~1.LNK - C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\alarm.exe
StartupFolder: C:\Users\WHEELS~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup
\DESKTO~1.LNK - C:\Program Files (x86)\Corel\WordPerfect Office 2000\programs\dad9.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\CORELR~1.LNK - C:\Program
Files (x86)\Corel\WordPerfect Office 2000\Register\Remind32.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program
Files\McAfee Security Scan\3.8.130\SSScheduler.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SERVIC~1.LNK - C:\Program
Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\VISTAA~1.LNK - C:\VstaScan
\VsAccess.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Download current page with FreshWebSuction - C:\Program Files (x86)\FreshWebmaster
\FreshWebSuction\obiectx_all.htm
IE: Download using FreshWebSuction - C:\Program Files (x86)\FreshWebmaster\FreshWebSuction
\obiectx.htm
IE: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins
\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins
\freeytmp3downloader.htm
IE: Search Using Copernic Agent - C:\Program Files (x86)\Copernic Agent
\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
IE: {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~2\COPERN~1\COPERN~1.EXE
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program
Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~2\COPERN~1\COPERN~1.EXE
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
LSP: %SystemRoot%\system32\vsocklib.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10
-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-
windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-
windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-
windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-
windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: NameServer = 64.71.255.204 64.71.255.198
TCP: Interfaces\{16C6E4AB-95AE-44B4-B300-BF7F85B75A16} : DHCPNameServer = 64.71.255.204
64.71.255.198
TCP: Interfaces\{7A83BCC7-06FE-4C29-BFF1-A71A0A9D6DB9} : DHCPNameServer = 64.71.255.204
64.71.255.198
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - C:\Program Files (x86)\Copernic
Agent\CopernicAgentExt.dll
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - C:\Program Files
(x86)\Copernic Agent\CopernicAgentExt.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\McIEPlg.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure
Networks Shared\Platform\puresp4.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo
Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= c:\progra~3\browse~1\25986~1.67\{c16c1~1\browse~1.dll
SSODL: WebCheck - <orphaned>
x64-BHO: SuperLyrics-16: {11111111-1111-1111-1111-110411411162} - C:\Program Files
(x86)\SuperLyrics-16\SuperLyrics-16-bho64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files
\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files
\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files
(x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Freecorder extension x64: {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files
\Freecorder extension x64\ScriptHost.dll
x64-BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files
(x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-BHO: {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - <orphaned>
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files
\Java\jre7\bin\jp2ssv.dll
x64-BHO: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
x64-TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files
(x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll
x64-TB: FireShot: {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} -
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google
\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [OOTag] C:\Program Files (x86)\Gateway\OOBEOffer\ootag.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - <orphaned>
x64-IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - <orphaned>
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - <orphaned>
x64-Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - <orphaned>
x64-Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files
\Pure Networks Shared\Platform\amd64\puresp4.dll
x64-Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee
\SiteAdvisor\x64\McIEPlg.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Wheelsup Club\AppData\Roaming\Mozilla\Firefox\Profiles
\51iipmx9.default-1368301715119\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?
ctid=CT3298580&CUI=UN41812124047612243&UM=2&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?
ctid=CT3298580&SearchSource=2&CUI=UN41812124047612243&UM=2&q=
FF - prefs.js: network.proxy.ftp - 202.147.204.125
FF - prefs.js: network.proxy.ftp_port - 8888
FF - prefs.js: network.proxy.gopher - 202.147.204.125
FF - prefs.js: network.proxy.gopher_port - 8888
FF - prefs.js: network.proxy.http - 202.147.204.125
FF - prefs.js: network.proxy.http_port - 8888
FF - prefs.js: network.proxy.socks - 202.147.204.125
FF - prefs.js: network.proxy.socks_port - 8888
FF - prefs.js: network.proxy.ssl - 202.147.204.125
FF - prefs.js: network.proxy.ssl_port - 8888
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Virtual Earth 3D\npVE3D.dll
FF - plugin: C:\Program Files (x86)\Winamp Detect\npwachk.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMSS.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: 2013-09-16 14:56; {90a1b331-c2b4-4933-9f63-ba7b84d60d58}; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\{90a1b331-c2b4-
4933-9f63-ba7b84d60d58}
FF - ExtSQL: 2013-10-03 15:24; jid0-KMOFrRnd6cHkSQEU5WJxd4Vz7SA@jetpack; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\jid0-
KMOFrRnd6cHkSQEU5WJxd4Vz7SA@jetpack.xpi
FF - ExtSQL: 2013-10-03 15:24; arpit3@techraga.in; C:\Users\Wheelsup Club\AppData\Roaming\Mozilla
\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\arpit3@techraga.in.xpi
FF - ExtSQL: 2013-10-03 15:25; proxytool@proxylist.co; C:\Users\Wheelsup Club\AppData\Roaming
\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\proxytool@proxylist.co.xpi
FF - ExtSQL: 2013-10-03 16:59; firefox@saltarsmart.biz; C:\Users\Wheelsup Club\AppData\Roaming
\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\firefox@saltarsmart.biz.xpi
FF - ExtSQL: 2013-10-15 09:40; jid0-XXocAsQYPfKHSY8ebTi0VcX8eNQ@jetpack; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\jid0-
XXocAsQYPfKHSY8ebTi0VcX8eNQ@jetpack.xpi
FF - ExtSQL: 2013-10-23 14:10; {e8f509f0-b677-11de-8a39-0800200c9a66}; C:\Users\Wheelsup Club
\AppData\Roaming\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\{e8f509f0-b677-
11de-8a39-0800200c9a66}.xpi
FF - ExtSQL: 2013-10-23 14:10; save-as-pdf-ff@pdfcrowd.com; C:\Users\Wheelsup Club\AppData\Roaming
\Mozilla\Firefox\Profiles\51iipmx9.default-1368301715119\extensions\save-as-pdf-ff@pdfcrowd.com.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 ahcix64s;ahcix64s;C:\windows\System32\drivers\ahcix64s.sys [2010-5-31 235312]
R0 MpFilter;Microsoft Malware Protection Driver;C:\windows\System32\drivers\MpFilter.sys [2013-6-18
247216]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/12/15 09:45:12];C:\Program Files
(x86)\CyberLink\PowerDVD9\000.fcl [2010-2-8 146928]
R2 AMD External Events Utility;AMD External Events Utility;C:\windows\System32\atiesrxx.exe [2012-7
-4 238080]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
[2012-7-4 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys
[2012-3-5 53888]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared
\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 Greg_Service;GRegService;C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe [2009-8-28
1150496]
R2 LinksysUpdater;Linksys Updater;C:\Program Files (x86)\Linksys\Linksys Updater\bin
\LinksysUpdater.exe [2008-11-13 204800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
[2013-10-3 121616]
R2 NisDrv;Microsoft Network Inspection System;C:\windows\System32\drivers\NisDrvWFP.sys [2011-4-27
139616]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy
2\SDFSSvc.exe [2013-10-30 3921880]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy
2\SDUpdSvc.exe [2013-10-30 1042272]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search &
Destroy 2\SDWSCSvc.exe [2013-10-30 171416]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application
Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 SrvUpdater;Software Updater;C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe [2013-2-18
31744]
R2 Update SaltarSmart;Update SaltarSmart;C:\Program Files (x86)\SaltarSmart\updateSaltarSmart.exe
[2013-10-3 65312]
R2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
[2010-5-31 243232]
R2 Util SaltarSmart;Util SaltarSmart;C:\Program Files (x86)\SaltarSmart\bin\utilSaltarSmart.exe
[2013-10-30 65312]
R2 Uvnc_service;Uvnc_service;C:\Program Files (x86)\UltraVNC Addons\uvnc_service.exe [2013-3-22
63296]
R2 VideoDownloadConverter_4zService;VideoDownloadConverterService;C:\PROGRA~2\VIDEOD~2\bar\1.bin
\4zbarsvc.exe [2013-3-18 42504]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB
\vmware-usbarbitrator64.exe [2011-8-29 846448]
R3 amdiox64;AMD IO Driver;C:\windows\System32\drivers\amdiox64.sys [2012-7-12 46136]
R3 anvsnddrv;AnvSoft Virtual Sound Device;C:\windows\System32\drivers\anvsnddrv.sys [2013-3-19
33872]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\windows\System32\drivers
\AtihdW76.sys [2012-2-23 95760]
R3 AVer7231_x64;AVerMedia 7231 capture service;C:\windows\System32\drivers\AVer7231_x64.sys [2010-7
-26 1799808]
R3 bbcap;bb_capture_driver;C:\windows\System32\drivers\bbcap.sys [2013-3-22 4608]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-3-14 245760]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-
8-12 366600]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\System32\drivers\Rt64win7.sys [2010-5-31 346144]
R3 rtl819xpn64;Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;C:\windows
\System32\drivers\rtl819xp.sys [2010-2-1 622624]
R3 Sftfs;Sftfs;C:\windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application
Virtualization Client\sftvsa.exe [2013-6-26 207528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows
\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows
\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 CltMngSvc;Search Protect by Conduit Updater;C:\Program Files (x86)\SearchProtect\bin
\CltMngSvc.exe --> C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [?]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-4-1
183560]
S3 debutfilter;Debut Filter Driver v6.20.00;C:\windows\System32\drivers\debutfilterx64.sys [2013-3-
23 33488]
S3 fssfltr;fssfltr;C:\windows\System32\drivers\fssfltr.sys [2013-8-14 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety
\fsssvc.exe [2013-2-5 1512448]
S3 GSService;GSService;C:\Windows\SysWOW64\GSService.exe [2013-3-17 448736]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee
Security Scan\3.8.130\McCHSvc.exe [2013-9-6 288776]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\windows\System32\drivers
\rdpvideominiport.sys [2013-3-19 19456]
S3 SndTAudio;SndTAudio;C:\windows\System32\drivers\SndTAudio.sys [2013-3-17 34528]
S3 SWDUMon;SWDUMon;C:\windows\System32\drivers\SWDUMon.sys [2012-3-30 15672]
S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2013-3-19 57856]
S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe
[2011-10-27 1255736]
S3 WsAudio_Device(1);WsAudio_Device(1);C:\windows\System32\drivers\VirtualAudio1.sys [2013-3-17
31080]
S3 WsAudio_Device(2);WsAudio_Device(2);C:\windows\System32\drivers\VirtualAudio2.sys [2013-3-17
31080]
S3 WsAudio_Device(3);WsAudio_Device(3);C:\windows\System32\drivers\VirtualAudio3.sys [2013-3-17
31080]
S3 WsAudio_Device(4);WsAudio_Device(4);C:\windows\System32\drivers\VirtualAudio4.sys [2013-3-17
31080]
S3 WsAudio_Device(5);WsAudio_Device(5);C:\windows\System32\drivers\VirtualAudio5.sys [2013-3-17
31080]
.
=============== Created Last 30 ================
.
2013-11-01 20:11:08 10280728 ----a-w- C:\ProgramData\Microsoft\Microsoft
Antimalware\Definition Updates\{01E01A6A-BC83-4FE0-A01C-372922FD9866}\mpengine.dll
2013-11-01 16:05:53 10280728 ------w- C:\ProgramData\Microsoft\Microsoft
Antimalware\Definition Updates\Backup\mpengine.dll
2013-10-31 13:22:17 71048 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-31 13:22:17 692616 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe
2013-10-30 13:51:03 21040 ----a-w- C:\windows\System32\sdnclean64.exe
2013-10-30 13:50:45 -------- d-----w- C:\Program Files (x86)\Spybot - Search &
Destroy 2
2013-10-29 18:41:37 -------- d-----w- C:\Program Files\Uninstaller
2013-10-29 18:39:47 -------- d-----w- C:\Program Files (x86)\SaltarSmart
2013-10-29 18:37:13 -------- d-----w- C:\Program Files (x86)\SuperLyrics-16
2013-10-27 12:54:40 -------- d-----w- C:\Program Files\iPod
2013-10-27 12:54:39 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-
52C6199EBF69
2013-10-27 12:54:39 -------- d-----w- C:\Program Files\iTunes
2013-10-27 12:54:39 -------- d-----w- C:\Program Files (x86)\iTunes
2013-10-24 20:31:13 -------- d-----w- C:\Users\Wheelsup Club\AppData\Local
\FreeFileViewer
2013-10-19 14:18:58 965000 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware
\Definition Updates\{09992E5C-E36E-42A4-BEC1-C9B59B97F77E}\gapaengine.dll
2013-10-17 15:44:01 -------- d-----w- C:\Program Files\McAfee Security Scan
2013-10-16 12:57:03 17813896 ----a-w- C:\windows\SysWow64\FlashPlayerInstaller.exe
2013-10-15 20:28:53 -------- d-----w- C:\Program Files (x86)\Flash Movie Player
2013-10-15 14:26:46 163504 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest
\Sqm10145.bin
2013-10-09 17:41:57 -------- d-----w- C:\Users\Wheelsup Club\AppData\Roaming
\DonationCoder
2013-10-09 17:41:44 -------- d-----w- C:\ProgramData\DonationCoder
2013-10-09 17:41:44 -------- d-----w- C:\Program Files (x86)\ScreenshotCaptor
2013-10-09 15:34:28 -------- d-----w- C:\FFOutput
2013-10-09 15:33:33 -------- d-----w- C:\Program Files (x86)\FreeTime
2013-10-09 15:14:36 -------- d-----w- C:\Program Files (x86)\Free All to Image
Jpg-Jpeg Bmp Tiff Png Converter
2013-10-09 14:14:32 -------- d-----w- C:\Users\Wheelsup Club\AppData\Roaming
\Free-backup.info
2013-10-06 02:54:17 -------- d-----w- C:\Program Files (x86)\K-Lite Codec Pack
2013-10-04 20:51:52 -------- d-----w- C:\Program Files (x86)\MPC-HC
.
==================== Find3M ====================
.
2013-09-22 23:28:06 1767936 ----a-w- C:\windows\SysWow64\wininet.dll
2013-09-22 23:27:49 2876928 ----a-w- C:\windows\SysWow64\jscript9.dll
2013-09-22 23:27:48 61440 ----a-w- C:\windows\SysWow64\iesetup.dll
2013-09-22 23:27:48 109056 ----a-w- C:\windows\SysWow64\iesysprep.dll
2013-09-22 22:55:10 2241024 ----a-w- C:\windows\System32\wininet.dll
2013-09-22 22:54:51 3959296 ----a-w- C:\windows\System32\jscript9.dll
2013-09-22 22:54:50 67072 ----a-w- C:\windows\System32\iesetup.dll
2013-09-22 22:54:50 136704 ----a-w- C:\windows\System32\iesysprep.dll
2013-09-21 03:38:39 2706432 ----a-w- C:\windows\System32\mshtml.tlb
2013-09-21 03:30:24 2706432 ----a-w- C:\windows\SysWow64\mshtml.tlb
2013-09-21 02:48:36 89600 ----a-w- C:\windows\System32\RegisterIEPKEYs.exe
2013-09-21 02:39:47 71680 ----a-w- C:\windows\SysWow64\RegisterIEPKEYs.exe
2013-09-14 01:10:19 497152 ----a-w- C:\windows\System32\drivers\afd.sys
2013-09-08 02:30:37 1903552 ----a-w- C:\windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14 327168 ----a-w- C:\windows\System32\mswsock.dll
2013-09-08 02:03:58 231424 ----a-w- C:\windows\SysWow64\mswsock.dll
2013-09-04 12:12:11 343040 ----a-w- C:\windows\System32\drivers\usbhub.sys
2013-09-04 12:11:51 325120 ----a-w- C:\windows\System32\drivers\usbport.sys
2013-09-04 12:11:49 99840 ----a-w- C:\windows\System32\drivers\usbccgp.sys
2013-09-04 12:11:43 52736 ----a-w- C:\windows\System32\drivers\usbehci.sys
2013-09-04 12:11:43 30720 ----a-w- C:\windows\System32\drivers\usbuhci.sys
2013-09-04 12:11:42 25600 ----a-w- C:\windows\System32\drivers\usbohci.sys
2013-09-04 12:11:40 7808 ----a-w- C:\windows\System32\drivers\usbd.sys
2013-08-29 02:17:48 5549504 ----a-w- C:\windows\System32\ntoskrnl.exe
2013-08-29 02:16:35 1732032 ----a-w- C:\windows\System32\ntdll.dll
2013-08-29 02:16:28 243712 ----a-w- C:\windows\System32\wow64.dll
2013-08-29 02:16:14 859648 ----a-w- C:\windows\System32\tdh.dll
2013-08-29 02:13:28 878080 ----a-w- C:\windows\System32\advapi32.dll
2013-08-29 01:51:45 3969472 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2013-08-29 01:51:45 3914176 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2013-08-29 01:50:31 5120 ----a-w- C:\windows\SysWow64\wow32.dll
2013-08-29 01:50:30 1292192 ----a-w- C:\windows\SysWow64\ntdll.dll
2013-08-29 01:50:16 619520 ----a-w- C:\windows\SysWow64\tdh.dll
2013-08-29 01:48:17 640512 ----a-w- C:\windows\SysWow64\advapi32.dll
2013-08-29 01:48:15 44032 ----a-w- C:\windows\apppatch\acwow64.dll
2013-08-29 00:49:53 25600 ----a-w- C:\windows\SysWow64\setup16.exe
2013-08-29 00:49:52 7680 ----a-w- C:\windows\SysWow64\instnm.exe
2013-08-29 00:49:52 14336 ----a-w- C:\windows\SysWow64\ntvdm64.dll
2013-08-29 00:49:49 2048 ----a-w- C:\windows\SysWow64\user.exe
2013-08-28 01:21:06 3155968 ----a-w- C:\windows\System32\win32k.sys
2013-08-28 01:12:33 461312 ----a-w- C:\windows\System32\scavengeui.dll
2013-08-21 01:12:32 4812567 ----a-w- C:\Users\Wheelsup Club\FileZilla_3.7.3_win32-
setup.exe
2013-08-18 03:08:39 106496 ----a-w- C:\windows\SysWow64\ATL71.DLL
2013-08-14 01:39:44 1169609 ----a-w- C:\windows\unins001.exe
2013-08-13 17:51:58 4817275 ----a-w- C:\Users\Wheelsup Club\FileZilla_3.7.2_win32-
setup.exe
2013-08-05 02:25:45 155584 ----a-w- C:\windows\System32\drivers\ataport.sys
.
============= FINISH: 11:36:34.80 ===============
4. When I launched Firefox to get back to this post, one of the bothersome ads popped up, in a new
tab, again.
5. aswMBR Log:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-11-02 11:46:31
-----------------------------
11:46:31.670 OS Version: Windows x64 6.1.7601 Service Pack 1
11:46:31.670 Number of processors: 4 586 0x402
11:46:31.680 ComputerName: WHEELSUPCLUB-PC UserName: Wheelsup Club
11:46:36.503 Initialize success
11:49:32.473 AVAST engine defs: 13110200
11:52:53.826 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000074
11:52:53.826 Disk 0 Vendor: WDC_____ 01.0 Size: 953805MB BusType: 8
11:52:53.976 Disk 0 MBR read successfully
11:52:53.976 Disk 0 MBR scan
11:52:54.056 Disk 0 unknown MBR code
11:52:54.066 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 16000 MB offset 2048
11:52:54.116 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 32770048
11:52:54.156 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 937703 MB offset 32974848
11:52:54.236 Disk 0 scanning C:\windows\system32\drivers
11:53:12.308 Service scanning
11:53:52.652 Modules scanning
11:53:52.652 Disk 0 trace - called modules:
11:53:52.672 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll ahcix64s.sys
11:53:52.682 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80067c8060]
11:53:52.682 3 CLASSPNP.SYS[fffff880018a443f] -> nt!IofCallDriver -> \Device\00000074
[0xfffffa8005e389c0]
11:53:55.783 AVAST engine scan C:\windows
11:54:05.724 AVAST engine scan C:\windows\system32
11:59:10.902 AVAST engine scan C:\windows\system32\drivers
11:59:40.715 AVAST engine scan C:\Users\Wheelsup Club
01:47:13.742 AVAST engine scan C:\ProgramData
01:10:57.966 Scan finished successfully
06:43:12.596 Disk 0 MBR has been saved successfully to "C:\Users\Wheelsup Club\Desktop\MBR.dat"
06:43:12.636 The log file has been saved successfully to "C:\Users\Wheelsup Club\Desktop
\aswMBR.txt"
6. I think I successfully uploaded the [I]"attached.zip" file, in the "Managed Attachments" facility.
Kindly let me know, though, if I did something wrong and need to try uploading the file, again.
- r