tokebuddude
New member
DDS (Ver_10-03-17.01) - NTFSX64
Run by John at 2:20:16.64 on Thu 09/30/2010
Internet Explorer: 9.0.7930.16406
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6135.3722 [GMT -4:00]
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\John\AppData\Local\TVersity\Media Server\MediaServer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.MSSMLBIZ\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Users\John\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\John\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Trillian\trillian.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Razer\Naga\NagaTray.exe
C:\Program Files (x86)\Razer\Lycosa\razerhid.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Razer\Lycosa\razertra.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Windows\SysWOW64\CtHelper.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\SysWOW64\drivers\safesurf.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\John\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~2\spybot~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\mif5ba~1\office14\URLREDIR.DLL
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [uTorrent] "c:\program files (x86)\utorrent\uTorrent.exe"
uRun: [PeerBlock] c:\program files\peerblock\peerblock.exe
uRun: [DAEMON Tools Lite] "c:\program files (x86)\daemon tools lite\DTLite.exe" -autorun
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
uRun: [Google Update] "c:\users\john\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [LightScribe Control Panel] c:\program files (x86)\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [SpybotSD TeaTimer] c:\program files (x86)\spybot - search & destroy\TeaTimer.exe
mRun: [RemoteControl10] "c:\program files (x86)\cyberlink\powerdvd10\PDVD10Serv.exe"
mRun: [BDRegion] c:\program files (x86)\cyberlink\shared files\brs.exe
mRun: [Razer Naga Driver] c:\program files (x86)\razer\naga\NagaTray.exe
mRun: [Lycosa] "c:\program files (x86)\razer\lycosa\razerhid.exe"
mRun: [TrueImageMonitor.exe] c:\program files (x86)\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [IME14 CHT Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHT /Log
mRun: [IME14 JPN Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /JPN /Log
mRun: [IME14 KOR Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /KOR /Log
mRun: [IME14 CHS Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHS /Log
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files (x86)\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [TkBellExe] "c:\program files (x86)\common files\real\update_ob\realsched.exe" -osboot
mRun: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
mRun: [CTHelper] CTHELPER.EXE
mRun: [Windows LSASS Service] c:\program files (x86)\dao\svchost.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [NBAgent] "c:\program files (x86)\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mRun: [jsafesurf] c:\windows\syswow64\drivers\safesurf.exe
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\john\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files (x86)\erunt\AUTOBACK.EXE
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office14\GROOVE.EXE
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\trillian.lnk - c:\program files (x86)\trillian\trillian.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~2\spybot~1\SDHelper.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files (x86)\common files\lightscribe\LSRunOnce.exe"
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe -s
mRun-x64: [Acronis Scheduler2 Service] "c:\program files (x86)\common files\acronis\schedule2\schedhlp.exe"
mRun-x64: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun-x64: [IME14 CHT Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHT /Log
mRun-x64: [IME14 JPN Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /JPN /Log
mRun-x64: [IME14 KOR Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /KOR /Log
mRun-x64: [IME14 CHS Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHS /Log
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-9-29 69152]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [2010-8-31 1477728]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 173984]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/08/29 18:05:37];c:\program files (x86)\cyberlink\powerdvd10\navfilter\000.fcl [2010-4-2 146928]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\common files\acronis\cdp\afcdpsrv.exe [2010-8-31 2480048]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\common files\microsoft shared\ime14\shared\IMEDICTUPDATE.EXE [2010-1-21 83312]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\lavasoft\ad-aware\AAWService.exe [2010-8-12 1356952]
R2 NAUpdate;Nero Update;c:\program files (x86)\nero\update\NASvc.exe [2010-3-25 490280]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-7-9 248936]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2010-8-31 252512]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 158808]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 706648]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 681048]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\lavasoft\ad-aware\kernexplorer64.sys [2010-8-12 16928]
R3 Lycosa;Lycosa Keyboard;c:\windows\system32\drivers\Lycosa.sys [2010-8-29 20352]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 40832]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-12-19 314400]
R3 RzSynapse;Razer Naga Driver;c:\windows\system32\drivers\RzSynapse.sys [2010-4-21 73216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-9-30 1153368]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 158808]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\common files\creative labs shared\service\AL6Licensing.exe [2010-9-17 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-9-17 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 706648]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 141912]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 141912]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 681048]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;e:\games\dragon age\bin_ship\daupdatersvc.service.exe [2010-9-28 25832]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 51456888]
S3 ose64;Office 64 Source Engine;c:\program files\common files\microsoft shared\source engine\OSE.EXE [2010-1-9 174440]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-8-29 19544]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-8-29 31800]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2010-4-19 50688]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-30 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\microsoft sql server\100\shared\sqladhlp.exe [2009-3-31 47128]
S4 SQLAgent$MSSMLBIZ;SQL Server Agent (MSSMLBIZ);c:\program files (x86)\microsoft sql server\mssql10.mssmlbiz\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
=============== Created Last 30 ================
2010-09-30 06:13:33 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-30 06:13:33 0 d-----w- c:\program files (x86)\Spybot - Search & Destroy
2010-09-29 15:54:34 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-09-29 15:39:04 69152 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-09-29 15:17:22 0 d-----w- c:\programdata\Lavasoft
2010-09-29 15:17:22 0 d-----w- c:\program files (x86)\Lavasoft
2010-09-29 15:08:41 0 dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-29 14:52:19 0 d-----w- c:\program files (x86)\Trend Micro
2010-09-29 14:03:52 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 13:40:35 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-09-29 13:40:35 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-29 04:34:05 0 d-----w- c:\program files (x86)\Microsoft Synchronization Services
2010-09-29 04:31:05 0 d-----w- c:\program files (x86)\Microsoft Visual Studio 10.0
2010-09-29 04:31:05 0 d-----w- c:\program files (x86)\common files\Merge Modules
2010-09-29 04:29:54 0 d-----w- c:\program files\Microsoft Visual Studio 10.0
2010-09-29 04:29:52 0 d-----w- c:\program files\Microsoft Help Viewer
2010-09-28 22:34:08 0 d-----w- c:\users\john\appdata\roaming\Crayon Physics Deluxe
2010-09-28 22:33:05 0 d-----w- c:\windows\syswow64\system32
2010-09-26 23:15:38 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-09-26 23:15:38 206848 ----a-w- c:\windows\system32\mfps.dll
2010-09-26 23:15:38 196608 ----a-w- c:\windows\syswow64\mfreadwrite.dll
2010-09-26 23:15:38 1619456 ----a-w- c:\windows\syswow64\WMVDECOD.DLL
2010-09-26 23:15:37 4068864 ----a-w- c:\windows\system32\mf.dll
2010-09-26 23:15:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-09-26 23:15:36 3181568 ----a-w- c:\windows\syswow64\mf.dll
2010-09-26 23:13:27 1863680 ----a-w- c:\windows\system32\ExplorerFrame.dll
2010-09-26 23:13:26 1495040 ----a-w- c:\windows\syswow64\ExplorerFrame.dll
2010-09-26 23:12:49 0 d-----w- c:\program files (x86)\Feedback Tool
2010-09-26 22:57:04 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-09-26 14:28:04 0 d-----w- c:\program files\iPod
2010-09-26 14:28:00 0 d-----w- c:\program files\iTunes
2010-09-26 14:28:00 0 d-----w- c:\program files (x86)\iTunes
2010-09-26 14:26:27 0 d-----w- c:\program files\Bonjour
2010-09-26 14:26:27 0 d-----w- c:\program files (x86)\Bonjour
2010-09-25 06:31:44 0 d-----w- c:\program files (x86)\Sid Meier's Civilization V
2010-09-24 13:32:22 0 d-----w- c:\program files (x86)\1C Company
2010-09-24 13:26:55 0 d-----w- c:\users\john\appdata\roaming\Ubisoft
2010-09-24 09:03:28 1080 ----a-w- c:\windows\system32\settingsbkup.sfm
2010-09-24 09:03:28 1080 ----a-w- c:\windows\system32\settings.sfm
2010-09-23 04:13:59 0 d-----w- c:\program files (x86)\PopCap Games
2010-09-23 03:44:58 0 d-----w- c:\programdata\PopCap Games
2010-09-22 03:57:27 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-09-21 00:04:36 390 ----a-w- c:\windows\syswow64\tversity.cookies
2010-09-20 14:13:03 0 d-----w- c:\programdata\LightScribe
2010-09-20 14:05:11 0 d-----w- c:\programdata\Nero
2010-09-20 14:04:22 0 d-----w- c:\program files (x86)\Nero
2010-09-19 14:12:22 0 d-----w- c:\programdata\BioWare
2010-09-19 05:37:46 0 d-----w- c:\windows\syswow64\URTTEMP
2010-09-19 05:36:48 103736 ----a-w- c:\windows\syswow64\PnkBstrB.exe
2010-09-19 05:36:47 66872 ----a-w- c:\windows\syswow64\PnkBstrA.exe
2010-09-19 05:36:45 669184 ----a-w- c:\windows\syswow64\pbsvc.exe
2010-09-18 18:35:31 0 d-----w- c:\users\john\appdata\roaming\SquareLogic
2010-09-17 21:44:43 53248 ------w- c:\windows\Ctregrun.exe
2010-09-17 21:43:53 0 d-----w- c:\programdata\Creative Labs
2010-09-17 21:37:37 0 d-----w- c:\program files\Creative
2010-09-17 21:37:09 0 d-----w- c:\program files (x86)\common files\Creative
2010-09-17 21:37:05 0 d--h--w- c:\program files (x86)\Creative Installation Information
2010-09-17 21:18:05 36016 ----a-w- c:\windows\system32\BMXState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:18:05 32088 ----a-w- c:\windows\system32\BMXCtrlState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:18:05 32088 ----a-w- c:\windows\system32\BMXBkpCtrlState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:18:05 11564 ----a-w- c:\windows\system32\DVCState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:17:47 4931577 ----a-w- c:\windows\{00000009-00000000-00000001-00001102-00000004-20021102}.BAK
2010-09-17 21:16:35 4931577 ----a-w- c:\windows\{00000009-00000000-00000001-00001102-00000004-20021102}.CDF
2010-09-17 21:16:07 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2010-09-17 21:15:00 89088 ----a-w- c:\windows\system32\CmdRtr64.DLL
2010-09-17 21:15:00 73728 ----a-w- c:\windows\syswow64\CmdRtr.DLL
2010-09-17 21:15:00 190976 ----a-w- c:\windows\system32\APOMgr64.DLL
2010-09-17 21:15:00 159 ---ha-r- c:\windows\ctfile.rfc
2010-09-17 21:15:00 148480 ----a-w- c:\windows\syswow64\APOMngr.DLL
2010-09-17 21:12:43 10240 ----a-w- c:\windows\system32\CTDCRES.DLL
2010-09-17 20:41:17 0 d-----w- c:\programdata\Creative
2010-09-17 20:39:35 36016 ----a-w- c:\windows\system32\BMXStateBkp-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 20:38:56 4174814 ------w- c:\windows\syswow64\CT4MGM.SF2
2010-09-17 20:38:56 4174814 ------w- c:\windows\system32\CT4MGM.SF2
2010-09-17 20:38:54 0 d-----w- c:\windows\syswow64\Defaults
2010-09-17 20:37:47 7062 ----a-w- c:\windows\syswow64\audiopid.vxd
2010-09-17 20:36:32 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2010-09-17 20:36:32 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2010-09-17 20:36:31 445016 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-09-17 20:36:31 109144 ----a-w- c:\windows\syswow64\OpenAL32.dll
2010-09-17 20:36:31 0 d-----w- c:\program files (x86)\OpenAL
2010-09-17 20:34:54 12288 ----a-w- c:\windows\system32\INRES.DLL
2010-09-17 20:34:54 0 d-----w- c:\windows\syswow64\Data
2010-09-17 20:34:54 0 d-----w- c:\windows\system32\Data
2010-09-17 20:34:52 0 d-----w- c:\program files (x86)\Creative
2010-09-17 02:54:10 0 d-----w- c:\windows\Google Earth Pro 4.2
2010-09-17 02:54:10 0 d-----w- c:\program files (x86)\Google Earth Pro 4.2
2010-09-16 13:16:35 203776 ----a-w- c:\windows\syswow64\clrviddc.dll
2010-09-16 13:15:10 0 d-----w- c:\program files (x86)\common files\xing shared
2010-09-16 13:12:52 185920 ----a-w- c:\windows\syswow64\rmoc3260.dll
2010-09-16 13:12:45 6656 ----a-w- c:\windows\syswow64\pndx5016.dll
2010-09-16 13:12:45 5632 ----a-w- c:\windows\syswow64\pndx5032.dll
2010-09-16 13:12:31 278528 ----a-w- c:\windows\syswow64\pncrt.dll
2010-09-16 12:06:07 0 d-----w- c:\users\john\appdata\roaming\OnLive App
2010-09-16 12:04:51 0 d-----w- c:\program files (x86)\OnLive
2010-09-15 19:01:28 0 d-----w- c:\program files (x86)\CCleaner
2010-09-15 18:45:52 71168 ----a-w- c:\windows\syswow64\ijl11pro.DLL
2010-09-15 18:45:52 609584 ----a-w- c:\windows\syswow64\COMCTL32.OCX
2010-09-15 18:45:52 29696 ----a-w- c:\windows\syswow64\VB5STKIT.DLL
2010-09-15 18:45:52 111376 ----a-w- c:\windows\syswow64\MSINET.OCX
2010-09-15 13:04:08 0 d-----w- c:\programdata\Game Room
2010-09-15 13:03:25 0 d-----w- c:\program files (x86)\Microsoft Games
2010-09-15 12:53:41 0 d-----w- c:\program files (x86)\Microsoft Corporation
2010-09-15 07:23:26 558592 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-14 23:43:49 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-09-14 23:43:49 467984 ----a-w- c:\windows\syswow64\d3dx10_39.dll
2010-09-14 23:43:49 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-09-14 23:43:49 1493528 ----a-w- c:\windows\syswow64\D3DCompiler_39.dll
2010-09-14 23:43:48 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-09-14 23:43:48 3851784 ----a-w- c:\windows\syswow64\D3DX9_39.dll
2010-09-12 23:35:06 0 d-----w- c:\programdata\Real
2010-09-12 23:35:06 0 d-----w- c:\program files (x86)\common files\Real
2010-09-12 19:40:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-09-11 23:38:32 0 d-----w- c:\windows\DD1865F0AD7340FBB23E1822E02396FF.TMP
2010-09-11 23:38:31 0 d-----w- c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
2010-09-11 21:28:46 85504 ----a-w- c:\windows\syswow64\ff_vfw.dll
2010-09-11 21:28:46 50688 ----a-w- c:\windows\syswow64\ff_acm.acm
2010-09-11 21:28:45 0 d-----w- c:\program files (x86)\ffdshow
2010-09-11 21:25:47 0 d-----w- c:\program files (x86)\TVersity Codec Pack
2010-09-10 00:40:23 0 d-----w- c:\users\john\appdata\roaming\Dropbox
2010-09-08 15:17:46 94208 ----a-w- c:\windows\syswow64\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- c:\windows\syswow64\QuickTime.qts
2010-09-07 03:50:14 0 d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2010-09-07 00:55:20 0 d-----w- c:\windows\syswow64\xlive
2010-09-07 00:55:20 0 d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2010-09-07 00:54:52 519000 ----a-w- c:\windows\system32\d3dx10_40.dll
2010-09-07 00:54:52 452440 ----a-w- c:\windows\syswow64\d3dx10_40.dll
2010-09-07 00:54:52 2605920 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2010-09-07 00:54:52 2036576 ----a-w- c:\windows\syswow64\D3DCompiler_40.dll
2010-09-07 00:54:51 5631312 ----a-w- c:\windows\system32\D3DX9_40.dll
2010-09-07 00:54:51 4379984 ----a-w- c:\windows\syswow64\D3DX9_40.dll
2010-09-07 00:01:35 0 d-----w- c:\users\john\appdata\roaming\EVEMon
2010-09-07 00:01:30 0 d-----w- c:\program files (x86)\EVEMon
2010-09-06 15:56:15 45 ----a-w- c:\windows\syswow64\initdebug.nfo
2010-09-06 15:56:15 0 d-----w- c:\program files (x86)\SpeedFan
2010-09-05 21:17:36 0 d-----w- c:\users\john\appdata\roaming\cYo
2010-09-02 12:54:29 422 ----a-w- c:\windows\system32\mapisvc.inf
2010-09-02 12:54:16 0 d-----w- c:\program files\Microsoft Small Business
2010-09-02 12:53:58 0 d-----w- c:\program files (x86)\Microsoft Chart Controls
2010-09-02 12:51:50 50200 ----a-w- c:\windows\syswow64\perf-SQLAgent$MSSMLBIZ-sqlagtctr10.1.2531.0.dll
2010-09-02 12:51:36 79896 ----a-w- c:\windows\syswow64\perf-MSSQL$MSSMLBIZ-sqlctr10.1.2531.0.dll
2010-09-02 12:48:52 0 d-----w- c:\windows\syswow64\1033
2010-09-02 12:48:52 0 d-----w- c:\windows\system32\1033
2010-09-02 12:48:52 0 d-----w- c:\program files\Microsoft SQL Server
2010-09-01 13:48:55 39 ----a-w- c:\windows\vbaddin.ini
2010-09-01 13:43:01 0 d-----w- c:\program files (x86)\MSECache
2010-09-01 13:17:54 0 d-----w- c:\program files\common files\DESIGNER
2010-09-01 13:17:08 0 d-----w- c:\program files\Microsoft Synchronization Services
2010-09-01 13:16:28 0 d-----w- c:\program files\Microsoft Sync Framework
2010-09-01 13:16:28 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-09-01 13:13:56 0 d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2010-09-01 13:11:50 0 d-----w- c:\program files\Microsoft Analysis Services
2010-09-01 13:11:49 0 d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-09-01 13:03:18 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-01 06:45:47 65536 --sha-w- c:\users\john\ntuser.dat{661675d4-b593-11df-a802-001fbc00e313}.TM.blf
2010-09-01 06:45:47 524288 --sha-w- c:\users\john\ntuser.dat{661675d4-b593-11df-a802-001fbc00e313}.TMContainer00000000000000000002.regtrans-ms
2010-09-01 06:45:47 524288 --sha-w- c:\users\john\ntuser.dat{661675d4-b593-11df-a802-001fbc00e313}.TMContainer00000000000000000001.regtrans-ms
2010-09-01 06:08:22 0 d-----w- c:\program files (x86)\Microsoft SQL Server
2010-09-01 05:37:04 0 d-----w- c:\program files\Microsoft Office
2010-09-01 05:37:03 0 d-----w- c:\programdata\Microsoft Help
2010-09-01 05:18:57 0 d-----w- c:\program files (x86)\DAEMON Tools Lite
2010-09-01 05:18:30 0 d-----w- c:\users\john\appdata\roaming\DAEMON Tools Lite
2010-09-01 05:18:28 0 d-----w- c:\programdata\DAEMON Tools Lite
2010-09-01 05:17:21 0 d-----w- c:\users\john\appdata\roaming\DAEMON Tools Net
2010-09-01 01:54:45 252512 ----a-w- c:\windows\system32\drivers\afcdp.sys
2010-09-01 01:54:37 1477728 ----a-w- c:\windows\system32\drivers\tdrpm258.sys
2010-09-01 01:54:34 943712 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-09-01 01:27:01 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
==================== Find3M ====================
2010-09-12 23:35:08 499712 ----a-w- c:\windows\syswow64\msvcp71.dll
2010-09-01 04:55:48 460088 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-09-01 04:47:30 10199040 ----a-w- c:\windows\syswow64\mshtml.dll
2010-09-01 04:46:36 1355264 ----a-w- c:\windows\syswow64\jscript9.dll
2010-09-01 04:45:42 12348928 ----a-w- c:\windows\syswow64\ieframe.dll
2010-09-01 04:44:24 1122304 ----a-w- c:\windows\syswow64\wininet.dll
2010-09-01 04:44:22 441856 ----a-w- c:\windows\syswow64\ieapfltr.dll
2010-09-01 04:44:16 1097728 ----a-w- c:\windows\syswow64\urlmon.dll
2010-09-01 04:44:06 424960 ----a-w- c:\windows\syswow64\vbscript.dll
2010-09-01 04:43:34 208384 ----a-w- c:\windows\syswow64\webcheck.dll
2010-09-01 04:43:26 128000 ----a-w- c:\windows\syswow64\occache.dll
2010-09-01 04:43:24 166400 ----a-w- c:\windows\syswow64\msrating.dll
2010-09-01 04:43:22 23552 ----a-w- c:\windows\syswow64\licmgr10.dll
2010-09-01 04:43:22 109568 ----a-w- c:\windows\syswow64\url.dll
2010-09-01 04:43:18 65024 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-09-01 04:43:12 142848 ----a-w- c:\windows\syswow64\ieUnatt.exe
2010-09-01 04:43:12 114176 ----a-w- c:\windows\syswow64\iesysprep.dll
2010-09-01 04:43:10 76800 ----a-w- c:\windows\syswow64\SetIEInstalledDate.exe
2010-09-01 04:43:10 74752 ----a-w- c:\windows\syswow64\RegisterIEPKEYs.exe
2010-09-01 04:43:04 227840 ----a-w- c:\windows\syswow64\ieaksie.dll
2010-09-01 04:43:00 130560 ----a-w- c:\windows\syswow64\ieakeng.dll
2010-09-01 04:41:56 601088 ----a-w- c:\windows\system32\vbscript.dll
2010-09-01 04:40:40 215552 ----a-w- c:\windows\system32\msls31.dll
2010-09-01 01:54:23 271456 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-08-29 22:41:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_RzSynapse_01007.Wdf
2010-08-29 22:03:19 353576 ----a-w- c:\windows\syswow64\msvcr71.dll
2010-08-29 22:03:19 29480 ----a-w- c:\windows\syswow64\msxml3a.dll
2010-08-16 06:50:45 1137664 ----a-w- c:\windows\system32\FntCache.dll
2010-08-16 06:50:43 1543168 ----a-w- c:\windows\system32\DWrite.dll
2010-08-16 06:50:42 899072 ----a-w- c:\windows\system32\d2d1.dll
2010-08-16 06:50:42 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2010-08-16 06:50:42 1844224 ----a-w- c:\windows\system32\d3d10warp.dll
2010-08-16 06:14:36 1076224 ----a-w- c:\windows\syswow64\DWrite.dll
2010-08-16 06:14:24 737280 ----a-w- c:\windows\syswow64\d2d1.dll
2010-08-16 06:14:24 218624 ----a-w- c:\windows\syswow64\d3d10_1core.dll
2010-08-16 06:14:24 1172480 ----a-w- c:\windows\syswow64\d3d10warp.dll
2010-08-02 18:50:00 3695400 ----a-w- c:\windows\syswow64\ieapfltr.dat
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-28 22:26:12 332392 ----a-w- c:\windows\system32\RtlCPAPI64.dll
2010-07-28 22:26:12 2032232 ----a-w- c:\windows\system32\RtPgEx64.dll
2010-07-28 22:26:00 149608 ----a-w- c:\windows\system32\RtkCfg64.dll
2010-07-28 22:25:48 476264 ----a-w- c:\windows\system32\RtkApi64.dll
2010-07-28 22:25:48 2618984 ----a-w- c:\windows\system32\RtkAPO64.dll
2010-07-28 22:25:48 1213544 ----a-w- c:\windows\system32\RTCOM64.dll
2010-07-28 22:25:38 76904 ----a-w- c:\windows\system32\RCoInst64.dll
2010-07-28 22:25:38 372328 ----a-w- c:\windows\system32\RCoRes64.dat
2010-07-27 22:55:50 95520 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 22:55:50 69408 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-27 22:55:50 237856 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 22:55:50 119584 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-27 22:44:10 91424 ----a-w- c:\windows\syswow64\dnssd.dll
2010-07-27 22:44:10 75040 ----a-w- c:\windows\syswow64\jdns_sd.dll
2010-07-27 22:44:10 197920 ----a-w- c:\windows\syswow64\dnssdX.dll
2010-07-27 22:44:10 107808 ----a-w- c:\windows\syswow64\dns-sd.exe
2010-07-27 17:54:00 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-07-22 20:48:58 220496 ----a-w- c:\windows\system32\SFNHK64.dll
2010-07-22 20:48:50 78160 ----a-w- c:\windows\system32\SFAPO64.dll
2010-07-22 20:48:44 81232 ----a-w- c:\windows\system32\SFCOM64.dll
2010-07-22 20:48:26 74064 ----a-w- c:\windows\syswow64\SFCOM.dll
2010-07-22 20:37:14 200800 ----a-w- c:\windows\system32\AERTAC64.dll
2010-07-09 20:27:02 61032 ----a-w- c:\windows\system32\nvshext.dll
2010-07-09 20:27:02 159336 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 20:27:02 1585256 ----a-w- c:\windows\system32\nvsvc64.dll
2010-07-09 20:27:02 15314024 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 20:27:02 116328 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-06 15:48:02 1756160 ----a-w- c:\windows\system32\MaxxAudioRealtek.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 2:20:32.95 ===============
This is my DDS log as per request. I know that I have safesurf and surfguard here, that I don't know how to get rid of. I don't know of anything else that I'm infected with. Any help would be greatly appreciated
Run by John at 2:20:16.64 on Thu 09/30/2010
Internet Explorer: 9.0.7930.16406
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.6135.3722 [GMT -4:00]
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\John\AppData\Local\TVersity\Media Server\MediaServer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.MSSMLBIZ\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Users\John\AppData\Local\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\John\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\Office14\GROOVE.EXE
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Trillian\trillian.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Razer\Naga\NagaTray.exe
C:\Program Files (x86)\Razer\Lycosa\razerhid.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Razer\Lycosa\razertra.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Windows\SysWOW64\CtHelper.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\SysWOW64\drivers\safesurf.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\John\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~2\spybot~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~2\mif5ba~1\office14\URLREDIR.DLL
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [uTorrent] "c:\program files (x86)\utorrent\uTorrent.exe"
uRun: [PeerBlock] c:\program files\peerblock\peerblock.exe
uRun: [DAEMON Tools Lite] "c:\program files (x86)\daemon tools lite\DTLite.exe" -autorun
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
uRun: [Google Update] "c:\users\john\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [LightScribe Control Panel] c:\program files (x86)\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [SpybotSD TeaTimer] c:\program files (x86)\spybot - search & destroy\TeaTimer.exe
mRun: [RemoteControl10] "c:\program files (x86)\cyberlink\powerdvd10\PDVD10Serv.exe"
mRun: [BDRegion] c:\program files (x86)\cyberlink\shared files\brs.exe
mRun: [Razer Naga Driver] c:\program files (x86)\razer\naga\NagaTray.exe
mRun: [Lycosa] "c:\program files (x86)\razer\lycosa\razerhid.exe"
mRun: [TrueImageMonitor.exe] c:\program files (x86)\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [IME14 CHT Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHT /Log
mRun: [IME14 JPN Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /JPN /Log
mRun: [IME14 KOR Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /KOR /Log
mRun: [IME14 CHS Setup] c:\progra~2\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHS /Log
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AppleSyncNotifier] c:\program files (x86)\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [TkBellExe] "c:\program files (x86)\common files\real\update_ob\realsched.exe" -osboot
mRun: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
mRun: [CTHelper] CTHELPER.EXE
mRun: [Windows LSASS Service] c:\program files (x86)\dao\svchost.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [NBAgent] "c:\program files (x86)\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mRun: [jsafesurf] c:\windows\syswow64\drivers\safesurf.exe
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\john\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files (x86)\erunt\AUTOBACK.EXE
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office14\GROOVE.EXE
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\trillian.lnk - c:\program files (x86)\trillian\trillian.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files (x86)\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files (x86)\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~2\spybot~1\SDHelper.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15112/CTPID.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~2\mif5ba~1\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files (x86)\common files\lightscribe\LSRunOnce.exe"
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe -s
mRun-x64: [Acronis Scheduler2 Service] "c:\program files (x86)\common files\acronis\schedule2\schedhlp.exe"
mRun-x64: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun-x64: [IME14 CHT Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHT /Log
mRun-x64: [IME14 JPN Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /JPN /Log
mRun-x64: [IME14 KOR Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /KOR /Log
mRun-x64: [IME14 CHS Setup] c:\progra~1\common~1\micros~1\ime14\shared\IMEKLMG.EXE /SetPreload /CHS /Log
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-9-29 69152]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [2010-8-31 1477728]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 173984]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/08/29 18:05:37];c:\program files (x86)\cyberlink\powerdvd10\navfilter\000.fcl [2010-4-2 146928]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files (x86)\common files\acronis\cdp\afcdpsrv.exe [2010-8-31 2480048]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\common files\microsoft shared\ime14\shared\IMEDICTUPDATE.EXE [2010-1-21 83312]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\lavasoft\ad-aware\AAWService.exe [2010-8-12 1356952]
R2 NAUpdate;Nero Update;c:\program files (x86)\nero\update\NASvc.exe [2010-3-25 490280]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-7-9 248936]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2010-8-31 252512]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 158808]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 706648]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 681048]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\lavasoft\ad-aware\kernexplorer64.sys [2010-8-12 16928]
R3 Lycosa;Lycosa Keyboard;c:\windows\system32\drivers\Lycosa.sys [2010-8-29 20352]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 40832]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-12-19 314400]
R3 RzSynapse;Razer Naga Driver;c:\windows\system32\drivers\RzSynapse.sys [2010-4-21 73216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-9-30 1153368]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 158808]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\common files\creative labs shared\service\AL6Licensing.exe [2010-9-17 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2010-9-17 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 706648]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 141912]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 141912]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 681048]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;e:\games\dragon age\bin_ship\daupdatersvc.service.exe [2010-9-28 25832]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 51456888]
S3 ose64;Office 64 Source Engine;c:\program files\common files\microsoft shared\source engine\OSE.EXE [2010-1-9 174440]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-8-29 19544]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-8-29 31800]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2010-4-19 50688]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-8-30 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\microsoft sql server\100\shared\sqladhlp.exe [2009-3-31 47128]
S4 SQLAgent$MSSMLBIZ;SQL Server Agent (MSSMLBIZ);c:\program files (x86)\microsoft sql server\mssql10.mssmlbiz\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
=============== Created Last 30 ================
2010-09-30 06:13:33 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-30 06:13:33 0 d-----w- c:\program files (x86)\Spybot - Search & Destroy
2010-09-29 15:54:34 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-09-29 15:39:04 69152 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-09-29 15:17:22 0 d-----w- c:\programdata\Lavasoft
2010-09-29 15:17:22 0 d-----w- c:\program files (x86)\Lavasoft
2010-09-29 15:08:41 0 dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-29 14:52:19 0 d-----w- c:\program files (x86)\Trend Micro
2010-09-29 14:03:52 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 13:40:35 2048 ----a-w- c:\windows\syswow64\tzres.dll
2010-09-29 13:40:35 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-29 04:34:05 0 d-----w- c:\program files (x86)\Microsoft Synchronization Services
2010-09-29 04:31:05 0 d-----w- c:\program files (x86)\Microsoft Visual Studio 10.0
2010-09-29 04:31:05 0 d-----w- c:\program files (x86)\common files\Merge Modules
2010-09-29 04:29:54 0 d-----w- c:\program files\Microsoft Visual Studio 10.0
2010-09-29 04:29:52 0 d-----w- c:\program files\Microsoft Help Viewer
2010-09-28 22:34:08 0 d-----w- c:\users\john\appdata\roaming\Crayon Physics Deluxe
2010-09-28 22:33:05 0 d-----w- c:\windows\syswow64\system32
2010-09-26 23:15:38 257024 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-09-26 23:15:38 206848 ----a-w- c:\windows\system32\mfps.dll
2010-09-26 23:15:38 196608 ----a-w- c:\windows\syswow64\mfreadwrite.dll
2010-09-26 23:15:38 1619456 ----a-w- c:\windows\syswow64\WMVDECOD.DLL
2010-09-26 23:15:37 4068864 ----a-w- c:\windows\system32\mf.dll
2010-09-26 23:15:37 1888256 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-09-26 23:15:36 3181568 ----a-w- c:\windows\syswow64\mf.dll
2010-09-26 23:13:27 1863680 ----a-w- c:\windows\system32\ExplorerFrame.dll
2010-09-26 23:13:26 1495040 ----a-w- c:\windows\syswow64\ExplorerFrame.dll
2010-09-26 23:12:49 0 d-----w- c:\program files (x86)\Feedback Tool
2010-09-26 22:57:04 0 d-----w- c:\program files (x86)\SystemRequirementsLab
2010-09-26 14:28:04 0 d-----w- c:\program files\iPod
2010-09-26 14:28:00 0 d-----w- c:\program files\iTunes
2010-09-26 14:28:00 0 d-----w- c:\program files (x86)\iTunes
2010-09-26 14:26:27 0 d-----w- c:\program files\Bonjour
2010-09-26 14:26:27 0 d-----w- c:\program files (x86)\Bonjour
2010-09-25 06:31:44 0 d-----w- c:\program files (x86)\Sid Meier's Civilization V
2010-09-24 13:32:22 0 d-----w- c:\program files (x86)\1C Company
2010-09-24 13:26:55 0 d-----w- c:\users\john\appdata\roaming\Ubisoft
2010-09-24 09:03:28 1080 ----a-w- c:\windows\system32\settingsbkup.sfm
2010-09-24 09:03:28 1080 ----a-w- c:\windows\system32\settings.sfm
2010-09-23 04:13:59 0 d-----w- c:\program files (x86)\PopCap Games
2010-09-23 03:44:58 0 d-----w- c:\programdata\PopCap Games
2010-09-22 03:57:27 0 d-----w- c:\program files (x86)\MSXML 4.0
2010-09-21 00:04:36 390 ----a-w- c:\windows\syswow64\tversity.cookies
2010-09-20 14:13:03 0 d-----w- c:\programdata\LightScribe
2010-09-20 14:05:11 0 d-----w- c:\programdata\Nero
2010-09-20 14:04:22 0 d-----w- c:\program files (x86)\Nero
2010-09-19 14:12:22 0 d-----w- c:\programdata\BioWare
2010-09-19 05:37:46 0 d-----w- c:\windows\syswow64\URTTEMP
2010-09-19 05:36:48 103736 ----a-w- c:\windows\syswow64\PnkBstrB.exe
2010-09-19 05:36:47 66872 ----a-w- c:\windows\syswow64\PnkBstrA.exe
2010-09-19 05:36:45 669184 ----a-w- c:\windows\syswow64\pbsvc.exe
2010-09-18 18:35:31 0 d-----w- c:\users\john\appdata\roaming\SquareLogic
2010-09-17 21:44:43 53248 ------w- c:\windows\Ctregrun.exe
2010-09-17 21:43:53 0 d-----w- c:\programdata\Creative Labs
2010-09-17 21:37:37 0 d-----w- c:\program files\Creative
2010-09-17 21:37:09 0 d-----w- c:\program files (x86)\common files\Creative
2010-09-17 21:37:05 0 d--h--w- c:\program files (x86)\Creative Installation Information
2010-09-17 21:18:05 36016 ----a-w- c:\windows\system32\BMXState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:18:05 32088 ----a-w- c:\windows\system32\BMXCtrlState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:18:05 32088 ----a-w- c:\windows\system32\BMXBkpCtrlState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:18:05 11564 ----a-w- c:\windows\system32\DVCState-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 21:17:47 4931577 ----a-w- c:\windows\{00000009-00000000-00000001-00001102-00000004-20021102}.BAK
2010-09-17 21:16:35 4931577 ----a-w- c:\windows\{00000009-00000000-00000001-00001102-00000004-20021102}.CDF
2010-09-17 21:16:07 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2010-09-17 21:15:00 89088 ----a-w- c:\windows\system32\CmdRtr64.DLL
2010-09-17 21:15:00 73728 ----a-w- c:\windows\syswow64\CmdRtr.DLL
2010-09-17 21:15:00 190976 ----a-w- c:\windows\system32\APOMgr64.DLL
2010-09-17 21:15:00 159 ---ha-r- c:\windows\ctfile.rfc
2010-09-17 21:15:00 148480 ----a-w- c:\windows\syswow64\APOMngr.DLL
2010-09-17 21:12:43 10240 ----a-w- c:\windows\system32\CTDCRES.DLL
2010-09-17 20:41:17 0 d-----w- c:\programdata\Creative
2010-09-17 20:39:35 36016 ----a-w- c:\windows\system32\BMXStateBkp-{00000009-00000000-00000001-00001102-00000004-20021102}.rfx
2010-09-17 20:38:56 4174814 ------w- c:\windows\syswow64\CT4MGM.SF2
2010-09-17 20:38:56 4174814 ------w- c:\windows\system32\CT4MGM.SF2
2010-09-17 20:38:54 0 d-----w- c:\windows\syswow64\Defaults
2010-09-17 20:37:47 7062 ----a-w- c:\windows\syswow64\audiopid.vxd
2010-09-17 20:36:32 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2010-09-17 20:36:32 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2010-09-17 20:36:31 445016 ----a-w- c:\windows\syswow64\wrap_oal.dll
2010-09-17 20:36:31 109144 ----a-w- c:\windows\syswow64\OpenAL32.dll
2010-09-17 20:36:31 0 d-----w- c:\program files (x86)\OpenAL
2010-09-17 20:34:54 12288 ----a-w- c:\windows\system32\INRES.DLL
2010-09-17 20:34:54 0 d-----w- c:\windows\syswow64\Data
2010-09-17 20:34:54 0 d-----w- c:\windows\system32\Data
2010-09-17 20:34:52 0 d-----w- c:\program files (x86)\Creative
2010-09-17 02:54:10 0 d-----w- c:\windows\Google Earth Pro 4.2
2010-09-17 02:54:10 0 d-----w- c:\program files (x86)\Google Earth Pro 4.2
2010-09-16 13:16:35 203776 ----a-w- c:\windows\syswow64\clrviddc.dll
2010-09-16 13:15:10 0 d-----w- c:\program files (x86)\common files\xing shared
2010-09-16 13:12:52 185920 ----a-w- c:\windows\syswow64\rmoc3260.dll
2010-09-16 13:12:45 6656 ----a-w- c:\windows\syswow64\pndx5016.dll
2010-09-16 13:12:45 5632 ----a-w- c:\windows\syswow64\pndx5032.dll
2010-09-16 13:12:31 278528 ----a-w- c:\windows\syswow64\pncrt.dll
2010-09-16 12:06:07 0 d-----w- c:\users\john\appdata\roaming\OnLive App
2010-09-16 12:04:51 0 d-----w- c:\program files (x86)\OnLive
2010-09-15 19:01:28 0 d-----w- c:\program files (x86)\CCleaner
2010-09-15 18:45:52 71168 ----a-w- c:\windows\syswow64\ijl11pro.DLL
2010-09-15 18:45:52 609584 ----a-w- c:\windows\syswow64\COMCTL32.OCX
2010-09-15 18:45:52 29696 ----a-w- c:\windows\syswow64\VB5STKIT.DLL
2010-09-15 18:45:52 111376 ----a-w- c:\windows\syswow64\MSINET.OCX
2010-09-15 13:04:08 0 d-----w- c:\programdata\Game Room
2010-09-15 13:03:25 0 d-----w- c:\program files (x86)\Microsoft Games
2010-09-15 12:53:41 0 d-----w- c:\program files (x86)\Microsoft Corporation
2010-09-15 07:23:26 558592 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-14 23:43:49 540688 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-09-14 23:43:49 467984 ----a-w- c:\windows\syswow64\d3dx10_39.dll
2010-09-14 23:43:49 1942552 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-09-14 23:43:49 1493528 ----a-w- c:\windows\syswow64\D3DCompiler_39.dll
2010-09-14 23:43:48 4992520 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-09-14 23:43:48 3851784 ----a-w- c:\windows\syswow64\D3DX9_39.dll
2010-09-12 23:35:06 0 d-----w- c:\programdata\Real
2010-09-12 23:35:06 0 d-----w- c:\program files (x86)\common files\Real
2010-09-12 19:40:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-09-11 23:38:32 0 d-----w- c:\windows\DD1865F0AD7340FBB23E1822E02396FF.TMP
2010-09-11 23:38:31 0 d-----w- c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
2010-09-11 21:28:46 85504 ----a-w- c:\windows\syswow64\ff_vfw.dll
2010-09-11 21:28:46 50688 ----a-w- c:\windows\syswow64\ff_acm.acm
2010-09-11 21:28:45 0 d-----w- c:\program files (x86)\ffdshow
2010-09-11 21:25:47 0 d-----w- c:\program files (x86)\TVersity Codec Pack
2010-09-10 00:40:23 0 d-----w- c:\users\john\appdata\roaming\Dropbox
2010-09-08 15:17:46 94208 ----a-w- c:\windows\syswow64\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- c:\windows\syswow64\QuickTime.qts
2010-09-07 03:50:14 0 d-----w- c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
2010-09-07 00:55:20 0 d-----w- c:\windows\syswow64\xlive
2010-09-07 00:55:20 0 d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE
2010-09-07 00:54:52 519000 ----a-w- c:\windows\system32\d3dx10_40.dll
2010-09-07 00:54:52 452440 ----a-w- c:\windows\syswow64\d3dx10_40.dll
2010-09-07 00:54:52 2605920 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2010-09-07 00:54:52 2036576 ----a-w- c:\windows\syswow64\D3DCompiler_40.dll
2010-09-07 00:54:51 5631312 ----a-w- c:\windows\system32\D3DX9_40.dll
2010-09-07 00:54:51 4379984 ----a-w- c:\windows\syswow64\D3DX9_40.dll
2010-09-07 00:01:35 0 d-----w- c:\users\john\appdata\roaming\EVEMon
2010-09-07 00:01:30 0 d-----w- c:\program files (x86)\EVEMon
2010-09-06 15:56:15 45 ----a-w- c:\windows\syswow64\initdebug.nfo
2010-09-06 15:56:15 0 d-----w- c:\program files (x86)\SpeedFan
2010-09-05 21:17:36 0 d-----w- c:\users\john\appdata\roaming\cYo
2010-09-02 12:54:29 422 ----a-w- c:\windows\system32\mapisvc.inf
2010-09-02 12:54:16 0 d-----w- c:\program files\Microsoft Small Business
2010-09-02 12:53:58 0 d-----w- c:\program files (x86)\Microsoft Chart Controls
2010-09-02 12:51:50 50200 ----a-w- c:\windows\syswow64\perf-SQLAgent$MSSMLBIZ-sqlagtctr10.1.2531.0.dll
2010-09-02 12:51:36 79896 ----a-w- c:\windows\syswow64\perf-MSSQL$MSSMLBIZ-sqlctr10.1.2531.0.dll
2010-09-02 12:48:52 0 d-----w- c:\windows\syswow64\1033
2010-09-02 12:48:52 0 d-----w- c:\windows\system32\1033
2010-09-02 12:48:52 0 d-----w- c:\program files\Microsoft SQL Server
2010-09-01 13:48:55 39 ----a-w- c:\windows\vbaddin.ini
2010-09-01 13:43:01 0 d-----w- c:\program files (x86)\MSECache
2010-09-01 13:17:54 0 d-----w- c:\program files\common files\DESIGNER
2010-09-01 13:17:08 0 d-----w- c:\program files\Microsoft Synchronization Services
2010-09-01 13:16:28 0 d-----w- c:\program files\Microsoft Sync Framework
2010-09-01 13:16:28 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-09-01 13:13:56 0 d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2010-09-01 13:11:50 0 d-----w- c:\program files\Microsoft Analysis Services
2010-09-01 13:11:49 0 d-----w- c:\program files (x86)\Microsoft Analysis Services
2010-09-01 13:03:18 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-01 06:45:47 65536 --sha-w- c:\users\john\ntuser.dat{661675d4-b593-11df-a802-001fbc00e313}.TM.blf
2010-09-01 06:45:47 524288 --sha-w- c:\users\john\ntuser.dat{661675d4-b593-11df-a802-001fbc00e313}.TMContainer00000000000000000002.regtrans-ms
2010-09-01 06:45:47 524288 --sha-w- c:\users\john\ntuser.dat{661675d4-b593-11df-a802-001fbc00e313}.TMContainer00000000000000000001.regtrans-ms
2010-09-01 06:08:22 0 d-----w- c:\program files (x86)\Microsoft SQL Server
2010-09-01 05:37:04 0 d-----w- c:\program files\Microsoft Office
2010-09-01 05:37:03 0 d-----w- c:\programdata\Microsoft Help
2010-09-01 05:18:57 0 d-----w- c:\program files (x86)\DAEMON Tools Lite
2010-09-01 05:18:30 0 d-----w- c:\users\john\appdata\roaming\DAEMON Tools Lite
2010-09-01 05:18:28 0 d-----w- c:\programdata\DAEMON Tools Lite
2010-09-01 05:17:21 0 d-----w- c:\users\john\appdata\roaming\DAEMON Tools Net
2010-09-01 01:54:45 252512 ----a-w- c:\windows\system32\drivers\afcdp.sys
2010-09-01 01:54:37 1477728 ----a-w- c:\windows\system32\drivers\tdrpm258.sys
2010-09-01 01:54:34 943712 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-09-01 01:27:01 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
==================== Find3M ====================
2010-09-12 23:35:08 499712 ----a-w- c:\windows\syswow64\msvcp71.dll
2010-09-01 04:55:48 460088 ----a-w- c:\windows\syswow64\iedkcs32.dll
2010-09-01 04:47:30 10199040 ----a-w- c:\windows\syswow64\mshtml.dll
2010-09-01 04:46:36 1355264 ----a-w- c:\windows\syswow64\jscript9.dll
2010-09-01 04:45:42 12348928 ----a-w- c:\windows\syswow64\ieframe.dll
2010-09-01 04:44:24 1122304 ----a-w- c:\windows\syswow64\wininet.dll
2010-09-01 04:44:22 441856 ----a-w- c:\windows\syswow64\ieapfltr.dll
2010-09-01 04:44:16 1097728 ----a-w- c:\windows\syswow64\urlmon.dll
2010-09-01 04:44:06 424960 ----a-w- c:\windows\syswow64\vbscript.dll
2010-09-01 04:43:34 208384 ----a-w- c:\windows\syswow64\webcheck.dll
2010-09-01 04:43:26 128000 ----a-w- c:\windows\syswow64\occache.dll
2010-09-01 04:43:24 166400 ----a-w- c:\windows\syswow64\msrating.dll
2010-09-01 04:43:22 23552 ----a-w- c:\windows\syswow64\licmgr10.dll
2010-09-01 04:43:22 109568 ----a-w- c:\windows\syswow64\url.dll
2010-09-01 04:43:18 65024 ----a-w- c:\windows\syswow64\jsproxy.dll
2010-09-01 04:43:12 142848 ----a-w- c:\windows\syswow64\ieUnatt.exe
2010-09-01 04:43:12 114176 ----a-w- c:\windows\syswow64\iesysprep.dll
2010-09-01 04:43:10 76800 ----a-w- c:\windows\syswow64\SetIEInstalledDate.exe
2010-09-01 04:43:10 74752 ----a-w- c:\windows\syswow64\RegisterIEPKEYs.exe
2010-09-01 04:43:04 227840 ----a-w- c:\windows\syswow64\ieaksie.dll
2010-09-01 04:43:00 130560 ----a-w- c:\windows\syswow64\ieakeng.dll
2010-09-01 04:41:56 601088 ----a-w- c:\windows\system32\vbscript.dll
2010-09-01 04:40:40 215552 ----a-w- c:\windows\system32\msls31.dll
2010-09-01 01:54:23 271456 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-08-29 22:41:59 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_RzSynapse_01007.Wdf
2010-08-29 22:03:19 353576 ----a-w- c:\windows\syswow64\msvcr71.dll
2010-08-29 22:03:19 29480 ----a-w- c:\windows\syswow64\msxml3a.dll
2010-08-16 06:50:45 1137664 ----a-w- c:\windows\system32\FntCache.dll
2010-08-16 06:50:43 1543168 ----a-w- c:\windows\system32\DWrite.dll
2010-08-16 06:50:42 899072 ----a-w- c:\windows\system32\d2d1.dll
2010-08-16 06:50:42 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2010-08-16 06:50:42 1844224 ----a-w- c:\windows\system32\d3d10warp.dll
2010-08-16 06:14:36 1076224 ----a-w- c:\windows\syswow64\DWrite.dll
2010-08-16 06:14:24 737280 ----a-w- c:\windows\syswow64\d2d1.dll
2010-08-16 06:14:24 218624 ----a-w- c:\windows\syswow64\d3d10_1core.dll
2010-08-16 06:14:24 1172480 ----a-w- c:\windows\syswow64\d3d10warp.dll
2010-08-02 18:50:00 3695400 ----a-w- c:\windows\syswow64\ieapfltr.dat
2010-07-29 06:30:34 82944 ----a-w- c:\windows\syswow64\iccvid.dll
2010-07-28 22:26:12 332392 ----a-w- c:\windows\system32\RtlCPAPI64.dll
2010-07-28 22:26:12 2032232 ----a-w- c:\windows\system32\RtPgEx64.dll
2010-07-28 22:26:00 149608 ----a-w- c:\windows\system32\RtkCfg64.dll
2010-07-28 22:25:48 476264 ----a-w- c:\windows\system32\RtkApi64.dll
2010-07-28 22:25:48 2618984 ----a-w- c:\windows\system32\RtkAPO64.dll
2010-07-28 22:25:48 1213544 ----a-w- c:\windows\system32\RTCOM64.dll
2010-07-28 22:25:38 76904 ----a-w- c:\windows\system32\RCoInst64.dll
2010-07-28 22:25:38 372328 ----a-w- c:\windows\system32\RCoRes64.dat
2010-07-27 22:55:50 95520 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 22:55:50 69408 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-27 22:55:50 237856 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 22:55:50 119584 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-27 22:44:10 91424 ----a-w- c:\windows\syswow64\dnssd.dll
2010-07-27 22:44:10 75040 ----a-w- c:\windows\syswow64\jdns_sd.dll
2010-07-27 22:44:10 197920 ----a-w- c:\windows\syswow64\dnssdX.dll
2010-07-27 22:44:10 107808 ----a-w- c:\windows\syswow64\dns-sd.exe
2010-07-27 17:54:00 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-07-27 14:03:24 12867584 ----a-w- c:\windows\syswow64\shell32.dll
2010-07-22 20:48:58 220496 ----a-w- c:\windows\system32\SFNHK64.dll
2010-07-22 20:48:50 78160 ----a-w- c:\windows\system32\SFAPO64.dll
2010-07-22 20:48:44 81232 ----a-w- c:\windows\system32\SFCOM64.dll
2010-07-22 20:48:26 74064 ----a-w- c:\windows\syswow64\SFCOM.dll
2010-07-22 20:37:14 200800 ----a-w- c:\windows\system32\AERTAC64.dll
2010-07-09 20:27:02 61032 ----a-w- c:\windows\system32\nvshext.dll
2010-07-09 20:27:02 159336 ----a-w- c:\windows\system32\nvvsvc.exe
2010-07-09 20:27:02 1585256 ----a-w- c:\windows\system32\nvsvc64.dll
2010-07-09 20:27:02 15314024 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 20:27:02 116328 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-06 15:48:02 1756160 ----a-w- c:\windows\system32\MaxxAudioRealtek.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 2:20:32.95 ===============
This is my DDS log as per request. I know that I have safesurf and surfguard here, that I don't know how to get rid of. I don't know of anything else that I'm infected with. Any help would be greatly appreciated
Last edited by a moderator: