Jessicka
That little box keeps popping up in the lower right corner on all browsers I have installed, and on the Second Life client for some reason. I ran Malewarebytes, eset, MSE and it's not showing up in any of those, but it's the one everyone is describing and I can't seem to get rid of it. Can anyone help?
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by [redacted] at 5:51:22 on 2012-05-24
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.12279.7122 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Program Files (x86)\Silicon Image\SiI31xx HBA Wakeup Utility\SiHbaWakeupService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Alienware\Alienware TactX Mouse CI\AWMouseCI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Alienware\Command Center\DoorController.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\ThermalController.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Windows\system32\notepad.exe
C:\Program Files\SUPERAntiSpyware\4652d6ef-30b8-42b3-b681-ef4fe8a64a3d.com
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\notepad.exe
C:\Windows\notepad.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [DriverMax_RESTART]
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
mRun: [Razer Naga Driver] C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [<NO NAME>]
mRun: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
dRun: [CtxfiReg] CTXFIREG.exe /FAIL1
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AWMOUS~1.LNK - C:\Program Files (x86)\Alienware\Alienware TactX Mouse CI\AWMouseCI.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/ ... emLite.CAB
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwar ... /CTPID.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{E43AB5AF-E531-4A4B-981B-9223A8A2D4E1} : DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun-x64: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
mRun-x64: [Razer Naga Driver] C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [(Default)]
mRun-x64: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Hosts: 69.10.57.36 http://www.google-analytics.com.
Hosts: 69.10.57.36 ad-emea.doubleclick.net.
Hosts: 69.10.57.36 http://www.statcounter.com.
Hosts: 108.163.215.51 http://www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Lightning\AppData\Roaming\Mozilla\Firefox\Profiles\fb08nrxg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxps://www.google.com/
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Lightning\AppData\Roaming\Mozilla\Firefox\Profiles\fb08nrxg.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.searchya_i.hmpg - true
FF - user.js: extensions.searchya_i.hmpgUrl - hxxp://searchya.com/?chnl=ft-100&s=0&cr ... tBtDtBtCyD
FF - user.js: extensions.searchya_i.dfltSrch - true
FF - user.js: extensions.searchya_i.srchPrvdr - SearchYa!
FF - user.js: extensions.searchya_i.dnsErr - true
FF - user.js: extensions.searchya_i.newTab - true
FF - user.js: extensions.searchya_i.newTabUrl - hxxp://searchya.com/?chnl=ft-100&s=2&cr ... tBtDtBtCyD
FF - user.js: extensions.searchya_i.tlbrSrchUrl - hxxp://searchya.com/?chnl=ft-100&s=3&cr ... DtBtCyD&q=
FF - user.js: extensions.searchya_i.id - bacb074a000000000000a4badbfd71ba
FF - user.js: extensions.searchya_i.instlDay - 15385
FF - user.js: extensions.searchya_i.vrsn - 1.5.13.0
FF - user.js: extensions.searchya_i.vrsni - 1.5.13.0
FF - user.js: extensions.searchya_i.vrsnTs - 1.5.13.014:39:16
FF - user.js: extensions.searchya_i.prtnrId - ironsrc
FF - user.js: extensions.searchya_i.prdct - searchya
FF - user.js: extensions.searchya_i.aflt - foxtab
FF - user.js: extensions.searchya_i.smplGrp - none
FF - user.js: extensions.searchya_i.tlbrId - base
FF - user.js: extensions.searchya_i.instlRef - ft-100
FF - user.js: extensions.searchya_i.dfltLng -
FF - user.js: extensions.searchya_i.excTlbr - false
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2010-11-5 15296]
R2 BrcmMgmtAgent;Broadcom Management Agent;C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2011-1-14 163328]
R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-12-7 13336]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-4-21 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-5-21 1262400]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
R2 SiHbaWakeupService;SiI31xx HBA Wakeup Utility;C:\Program Files (x86)\Silicon Image\SiI31xx HBA Wakeup Utility\SiHbaWakeupService.exe [2009-7-27 62464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-5-15 382272]
R3 AWOPFilterDriver;AWOPFilterDriver;\??\C:\Windows\system32\drivers\AWOPFilterDriver.sys --> C:\Windows\system32\drivers\AWOPFilterDriver.sys [?]
R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
R3 danewFltr;NewDeathAdder Mouse;C:\Windows\system32\drivers\danew.sys --> C:\Windows\system32\drivers\danew.sys [?]
R3 ha20x22k;Creative 20X2 HAL Driver;C:\Windows\system32\drivers\ha20x22k.sys --> C:\Windows\system32\drivers\ha20x22k.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 mio;Master IO Filter Driver;C:\Windows\system32\DRIVERS\mio.sys --> C:\Windows\system32\DRIVERS\mio.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 rzudd;Razer Mouse Driver;C:\Windows\system32\DRIVERS\rzudd.sys --> C:\Windows\system32\DRIVERS\rzudd.sys [?]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2010/12/07 15:29:09;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-4-26 232944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-22 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-1 257696]
S3 btwampfl;btwampfl Bluetooth filter driver;\??\C:\Windows\system32\drivers\btwampfl.sys --> C:\Windows\system32\drivers\btwampfl.sys [?]
S3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\system32\DRIVERS\btwdpan.sys --> C:\Windows\system32\DRIVERS\btwdpan.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-1-6 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-12-7 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-1-6 79360]
S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
S3 DAdderFltr;DeathAdder Mouse;C:\Windows\system32\drivers\dadder.sys --> C:\Windows\system32\drivers\dadder.sys [?]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2012-1-26 135584]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-22 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-25 129976]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RzSynapse;Razer Driver;C:\Windows\system32\DRIVERS\RzSynapse.sys --> C:\Windows\system32\DRIVERS\RzSynapse.sys [?]
S3 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-10-14 994360]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;C:\Windows\system32\DRIVERS\gtkdrv.sys --> C:\Windows\system32\DRIVERS\gtkdrv.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2012-2-1 214896]
S4 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2010-12-7 1692480]
.
=============== Created Last 30 ================
.
2012-05-24 03:08:58 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E7CE8D9A-235C-49A7-A1A9-827D127FAFF9}\offreg.dll
2012-05-23 23:30:57 -------- d-----w- C:\Users\Lightning\AppData\Local\{7BAB18E2-0345-477B-A322-78BA2930A22D}
2012-05-23 23:30:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{BB80044A-27DD-4568-A6B8-90F3BCC15D2A}
2012-05-23 23:30:03 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E7CE8D9A-235C-49A7-A1A9-827D127FAFF9}\mpengine.dll
2012-05-22 20:46:36 -------- d-----w- C:\Users\Lightning\AppData\Local\{08496945-B200-4845-8F5D-625317B58129}
2012-05-22 20:46:25 -------- d-----w- C:\Users\Lightning\AppData\Local\{5555DA86-B1D2-4B27-8DC3-4DB836AB5FF0}
2012-05-22 08:35:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{B402261C-0006-43FD-ACBD-14EE7985C9D9}
2012-05-22 08:34:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{F46CE1F7-7274-4FA1-B889-7282B50E1D2B}
2012-05-22 08:34:42 -------- d-----w- C:\Users\Lightning\AppData\Local\{5490BD05-34BF-4615-867C-B579544822E6}
2012-05-22 08:34:31 -------- d-----w- C:\Users\Lightning\AppData\Local\{15173883-3AE6-4676-8C34-49A93C5E183E}
2012-05-22 08:34:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{9CB6E20C-16A8-4AF4-9BC2-C4A777A319E2}
2012-05-22 08:32:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{BB76A48C-91C5-4792-8B44-2BA1A7393043}
2012-05-22 08:09:59 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-22 00:14:21 978944 ----a-w- C:\Windows\System32\msvcp71.dll
2012-05-22 00:14:21 520192 ----a-w- C:\Windows\System32\msvcr71.dll
2012-05-22 00:14:21 381952 ----a-w- C:\Windows\System32\nvexpBar.dll
2012-05-22 00:14:21 372736 ----a-w- C:\Windows\System32\NVUNINST.EXE
2012-05-22 00:14:21 2065920 ----a-w- C:\Windows\System32\nvcplUI.exe
2012-05-22 00:14:21 1524736 ----a-w- C:\Windows\System32\MFC71.dll
2012-05-22 00:14:21 1064448 ----a-w- C:\Windows\System32\nvcplUIR.dll
2012-05-22 00:14:12 -------- d-----w- C:\Users\Lightning\AppData\Local\NVIDIA Corporation
2012-05-22 00:13:29 -------- d-----w- C:\Program Files (x86)\NVIDIA nTune Performance Application
2012-05-21 20:23:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{695A79C2-D774-4B05-8836-CF4D4C6F8013}
2012-05-21 20:23:42 -------- d-----w- C:\Users\Lightning\AppData\Local\{7B355EC0-7E15-43C7-B562-AF4E8DD9D68D}
2012-05-20 23:00:47 -------- d-----w- C:\Users\Lightning\AppData\Local\{DB9EE5E3-BCB2-4489-8A4B-1F5D3D8417B7}
2012-05-20 23:00:37 -------- d-----w- C:\Users\Lightning\AppData\Local\{480D3817-F403-4BA6-81BF-D6B56BF03F56}
2012-05-20 10:09:51 -------- d-----w- C:\Users\Lightning\AppData\Local\{3E5F4D3D-494A-46DB-B2A6-517E5865FAF3}
2012-05-20 10:09:29 -------- d-----w- C:\Users\Lightning\AppData\Local\{FC2098F1-6104-4186-931E-9342F7F66486}
2012-05-19 22:09:04 -------- d-----w- C:\Users\Lightning\AppData\Local\{0286F34E-FF9A-4042-80E3-1C9D8987EEEB}
2012-05-19 22:08:53 -------- d-----w- C:\Users\Lightning\AppData\Local\{23DDD0B7-A008-460B-BF1D-88EF14C2FAFA}
2012-05-19 09:49:40 -------- d-----w- C:\Users\Lightning\AppData\Local\{B17B0578-8C27-45BA-839E-4977E02BECEF}
2012-05-19 09:49:18 -------- d-----w- C:\Users\Lightning\AppData\Local\{1805F74D-429B-455A-B089-47BE66E13C23}
2012-05-19 01:26:18 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-05-19 01:26:18 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
2012-05-19 01:26:18 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-05-19 01:25:56 -------- d-----w- C:\Program Files\iPod
2012-05-19 01:25:55 -------- d-----w- C:\Program Files\iTunes
2012-05-19 01:25:55 -------- d-----w- C:\Program Files (x86)\iTunes
2012-05-19 01:25:16 -------- d-----w- C:\Program Files\Bonjour
2012-05-19 01:25:16 -------- d-----w- C:\Program Files (x86)\Bonjour
2012-05-18 21:48:53 -------- d-----w- C:\Users\Lightning\AppData\Local\{F189A3B2-94A4-497C-A7C9-A1D6B3AAC1A3}
2012-05-18 21:48:30 -------- d-----w- C:\Users\Lightning\AppData\Local\{36B14775-2FCD-4C74-AF86-0A2886F176CC}
2012-05-18 02:41:41 -------- d-----w- C:\Users\Lightning\AppData\Local\Razer
2012-05-18 00:37:25 -------- d-----w- C:\Users\Lightning\AppData\Local\{3855A4A5-21D6-4A8D-B5E8-AE1368D19F9C}
2012-05-18 00:37:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{0AF56C2D-CB34-42AD-BDE4-920F275B4B5D}
2012-05-17 08:58:28 -------- d-----w- C:\Users\Lightning\AppData\Local\{8CC8A56C-3836-4A5D-83F1-E0BD93665C70}
2012-05-17 08:58:17 -------- d-----w- C:\Users\Lightning\AppData\Local\{1BE0983F-6804-487C-AEC7-914FAAB4E254}
2012-05-16 20:58:04 -------- d-----w- C:\Users\Lightning\AppData\Local\{5BE81193-AD0F-46B8-ADFD-74990CDCB0D3}
2012-05-16 20:57:53 -------- d-----w- C:\Users\Lightning\AppData\Local\{0BA64573-696A-4E67-A94C-3AD7CDB089F5}
2012-05-16 01:16:43 -------- d-----w- C:\Users\Lightning\AppData\Local\{E75028C4-70DF-4107-9CBF-3EF596F12B9E}
2012-05-16 01:16:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{218AA661-9B58-44AB-BAC2-A81055215E03}
2012-05-15 07:21:50 423744 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2012-05-15 05:58:36 -------- d-----w- C:\Users\Lightning\AppData\Local\{7ACCF44C-0D4B-4C6F-8527-312333CA5215}
2012-05-15 05:57:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{D5300770-F350-44F0-9209-A15003EF8BDB}
2012-05-14 17:57:33 -------- d-----w- C:\Users\Lightning\AppData\Local\{92E86B17-5B88-4709-BB0F-1D4206397A32}
2012-05-14 17:57:11 -------- d-----w- C:\Users\Lightning\AppData\Local\{9F4A09C6-B8B6-450C-95C5-B7B810267CBE}
2012-05-14 00:28:44 -------- d-----w- C:\Users\Lightning\AppData\Local\{78E4DA42-CCF5-4838-BA8E-C0779EED6898}
2012-05-14 00:28:33 -------- d-----w- C:\Users\Lightning\AppData\Local\{E065DB90-86C0-47FA-8D3A-520976B10133}
2012-05-13 00:55:11 -------- d-----w- C:\Users\Lightning\AppData\Local\{25B3C571-C789-4DEF-9816-99A4AAC3F68D}
2012-05-13 00:55:00 -------- d-----w- C:\Users\Lightning\AppData\Local\{06640C94-44C7-4D6A-8813-E7A1A7DD76A5}
2012-05-12 07:38:44 -------- d-----w- C:\Users\Lightning\AppData\Local\{ADCA69E0-44C4-449E-AE87-8402FC71DE8D}
2012-05-12 07:38:23 -------- d-----w- C:\Users\Lightning\AppData\Local\{8644B141-1767-4AF7-8B90-A0BAAAE6A91D}
2012-05-11 19:37:57 -------- d-----w- C:\Users\Lightning\AppData\Local\{5CF25E04-73C8-41A5-A001-6CE49E693D0D}
2012-05-11 19:37:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{E53F95B3-4557-4C13-AC7D-F9D65EE88FE6}
2012-05-11 07:31:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{F91E865A-A19C-47C7-9907-23D748E461D9}
2012-05-11 07:31:13 -------- d-----w- C:\Users\Lightning\AppData\Local\{05E27C7F-DB0C-4D65-AB15-57837B9AA8CC}
2012-05-10 19:31:00 -------- d-----w- C:\Users\Lightning\AppData\Local\{E5D174FB-3645-405F-B53A-28BA1B4BDC4F}
2012-05-10 19:30:39 -------- d-----w- C:\Users\Lightning\AppData\Local\{63529318-2197-4596-AB4D-9E9EAE390788}
2012-05-10 07:30:13 -------- d-----w- C:\Users\Lightning\AppData\Local\{6A69C422-5C5C-4D84-8820-4926B9F4B3B2}
2012-05-10 07:29:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{0438930B-287B-4833-8987-6240411B0B6F}
2012-05-09 19:29:39 -------- d-----w- C:\Users\Lightning\AppData\Local\{0267D066-EF50-4C49-AFDB-374A41B5C182}
2012-05-09 19:29:28 -------- d-----w- C:\Users\Lightning\AppData\Local\{898F34E2-7B21-4A73-90AB-B819C3C01FEB}
2012-05-09 08:01:35 -------- d-----w- C:\e6e8d012520a8e56c76bc7665b9488
2012-05-08 20:01:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{8FAFC6F2-BF55-49DE-9587-FDA13F2CB5BD}
2012-05-08 20:00:41 -------- d-----w- C:\Users\Lightning\AppData\Local\{E12635CD-754C-43D5-821A-2322F8619B2A}
2012-05-08 08:00:17 -------- d-----w- C:\Users\Lightning\AppData\Local\{BEC338E6-BC3B-4CAE-9A47-644AB45A6262}
2012-05-08 07:59:55 -------- d-----w- C:\Users\Lightning\AppData\Local\{2C087274-22D2-4A0E-947B-2A72656076D7}
2012-05-07 19:59:42 -------- d-----w- C:\Users\Lightning\AppData\Local\{1D94EA2E-2D67-46A9-8171-DC756D842203}
2012-05-07 19:59:20 -------- d-----w- C:\Users\Lightning\AppData\Local\{6FC8C58A-A257-4650-8808-3AE9DEE31400}
2012-05-07 07:58:56 -------- d-----w- C:\Users\Lightning\AppData\Local\{56F87393-BA28-479B-9F16-D23406A85934}
2012-05-07 07:58:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{C9CFBF69-030C-4995-A8A4-AEB2F836A6AD}
2012-05-06 19:58:21 -------- d-----w- C:\Users\Lightning\AppData\Local\{D9098F0C-F754-44ED-9C5A-EE73C06E4754}
2012-05-06 19:57:59 -------- d-----w- C:\Users\Lightning\AppData\Local\{B22849BF-F535-4B15-85D9-A488B2555F00}
2012-05-06 07:57:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{04E72FB9-2CBA-4AE7-8016-E37A24387E94}
2012-05-06 07:57:13 -------- d-----w- C:\Users\Lightning\AppData\Local\{EAF4D99A-0FFE-472A-8C5B-90B55B9219AE}
2012-05-05 19:57:00 -------- d-----w- C:\Users\Lightning\AppData\Local\{D720956D-6D99-437D-8C44-9952C1B5D36C}
2012-05-05 19:56:49 -------- d-----w- C:\Users\Lightning\AppData\Local\{036A2801-81C5-46B8-882D-3E86A970688E}
2012-05-05 07:54:02 -------- d-----w- C:\Users\Lightning\AppData\Local\{BFAEEF38-DC67-4B4A-B8F3-C31AEB70D95A}
2012-05-05 07:53:40 -------- d-----w- C:\Users\Lightning\AppData\Local\{BB4330C9-4CCE-42A0-A967-7D6B4CEB1045}
2012-05-04 19:53:24 -------- d-----w- C:\Users\Lightning\AppData\Local\{5C8AEAD7-AE7C-40B4-8594-B85F5967E9D4}
2012-05-04 19:53:02 -------- d-----w- C:\Users\Lightning\AppData\Local\{9F4A72B9-38EE-45C5-95DB-FC69F619DB20}
2012-05-04 07:49:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{538529CE-4138-4632-B24F-5231549469BB}
2012-05-04 07:49:24 -------- d-----w- C:\Users\Lightning\AppData\Local\{F2E6B971-2A3F-41B9-A3E6-0918C5672364}
2012-05-03 19:49:11 -------- d-----w- C:\Users\Lightning\AppData\Local\{73E86C5C-215F-479A-B36A-637A7DF38DF5}
2012-05-03 19:48:50 -------- d-----w- C:\Users\Lightning\AppData\Local\{0950AE19-799E-4194-9DE0-498EDCD1C910}
2012-05-03 19:32:32 -------- d-----w- C:\Users\Lightning\AppData\Local\Innovative Solutions
2012-05-03 19:32:30 -------- d-----w- C:\Program Files (x86)\Innovative Solutions
2012-05-03 19:30:50 -------- d--h--w- C:\ProgramData\Common Files
2012-05-03 07:48:25 -------- d-----w- C:\Users\Lightning\AppData\Local\{301DEB12-2569-4E72-B223-34BE50A156DD}
2012-05-03 07:48:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{95BF36DE-189E-4188-A4F2-50EC68FDF560}
2012-05-02 19:47:49 -------- d-----w- C:\Users\Lightning\AppData\Local\{A97C69AB-4FE3-4A15-AD53-94305EB49E8A}
2012-05-02 19:47:38 -------- d-----w- C:\Users\Lightning\AppData\Local\{0799BCB6-5EB1-46FB-8944-72D0A33DA132}
2012-05-01 21:34:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{F99D9B7F-A6DA-4323-A171-D6004303022C}
2012-05-01 21:34:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{4CE64A14-166F-4DDA-918E-6CE3BB4ED233}
2012-05-01 09:33:45 -------- d-----w- C:\Users\Lightning\AppData\Local\{15071BF1-7FEE-406A-AB07-68272DF842A0}
2012-05-01 09:33:23 -------- d-----w- C:\Users\Lightning\AppData\Local\{8F859861-7DBD-40A0-B0D1-6C0C486E4714}
2012-05-01 08:00:53 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-04-30 21:33:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{79775016-1C83-400A-9019-6E7A2C7A56BA}
2012-04-30 21:32:49 -------- d-----w- C:\Users\Lightning\AppData\Local\{AF0C0804-AC4D-47DE-8742-C5137D76E5BC}
2012-04-30 09:32:23 -------- d-----w- C:\Users\Lightning\AppData\Local\{007421F4-B7A9-4A7F-9FDC-F39CE8B9E252}
2012-04-30 09:32:02 -------- d-----w- C:\Users\Lightning\AppData\Local\{E7C6821C-F57E-4B7D-97FA-091C8C4BE880}
2012-04-29 21:31:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{1358A382-AB1E-4928-8B00-1748C215A250}
2012-04-29 21:31:24 -------- d-----w- C:\Users\Lightning\AppData\Local\{FC5B258E-EA63-4770-AA99-9F518A903DF4}
2012-04-29 11:33:15 -------- d-----w- C:\Users\Lightning\AppData\Local\{40F7C910-B02E-4C0C-A106-A53A8A18DA96}
2012-04-28 08:11:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{68375E77-8201-4288-83F8-1FB58BC1AB16}
2012-04-28 08:11:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{3C47B299-3EB5-4555-BF9D-70394E50959D}
2012-04-27 20:10:57 -------- d-----w- C:\Users\Lightning\AppData\Local\{988034D2-DF2F-43FD-917A-C08C587DD6D3}
2012-04-27 20:10:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{BE77D127-68BA-458B-9222-75B3E079C8B9}
2012-04-27 07:49:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{65762524-24B2-4D84-8158-E049581A1416}
2012-04-27 07:49:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{B0F5A489-60E3-4D32-B394-26491296C063}
2012-04-26 23:29:49 -------- d-----w- C:\_OTL
2012-04-26 01:34:44 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2012-04-26 01:34:42 157352 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-26 01:34:42 129976 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
.
==================== Find3M ====================
.
2012-05-15 09:29:47 889664 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-05-15 09:29:46 63296 ----a-w- C:\Windows\System32\nvshext.dll
2012-05-15 09:29:46 118080 ----a-w- C:\Windows\System32\nvmctray.dll
2012-05-15 09:29:45 2621723 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-05-15 09:29:25 3149632 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-05-15 09:28:42 6151488 ----a-w- C:\Windows\System32\nvcpl.dll
2012-05-05 00:09:16 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 00:09:15 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 00:09:06 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-04-21 18:20:15 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2012-04-20 20:13:40 269712 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2012-04-18 17:08:08 31040 ----a-w- C:\Windows\System32\nvhdap64.dll
2012-04-18 17:08:03 188736 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2012-04-18 17:08:02 1451840 ----a-w- C:\Windows\System32\nvhdagenco6420103.dll
2012-04-17 08:07:01 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-04-04 20:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-04-03 23:15:45 269712 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-03-31 06:05:57 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-03-21 01:44:12 98688 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-21 01:44:12 203888 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-03-08 23:37:20 302448 ----a-w- C:\Windows\WLXPGSS.SCR
2012-03-08 05:46:50 138752 ----a-w- C:\Windows\SysWow64\rztouchdll.dll
2012-03-05 08:49:56 19536 ----a-w- C:\Windows\System32\drivers\AWOPFilterDriver.sys
2012-03-03 06:35:38 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2012-03-03 05:31:19 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-03-01 08:32:06 284672 ----a-w- C:\Windows\SysWow64\rzdevicedll.dll
2012-03-01 06:46:16 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-03-01 06:38:27 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-03-01 06:33:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-03-01 06:28:47 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-03-01 05:37:41 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-03-01 05:33:23 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-03-01 05:29:16 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-02-28 06:39:37 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-02-28 05:38:52 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 04:31:38 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 03:52:27 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-02-24 15:36:50 230952 ----a-w- C:\Windows\System32\drivers\PCTSD64.sys
.
============= FINISH: 5:51:47.74 ===============
http://www.malwarebytes.org
Database version: v2012.05.22.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Lightning :: LIGHTNING-PC [administrator]
5/24/2012 1:54:05 AM
mbam-log-2012-05-24 (01-54-05).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 724507
Time elapsed: 2 hour(s), 9 minute(s), 3 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
It said not to post the attach file but there was this in there:
==== Hosts File Hijack ======================
.
Hosts: 69.10.57.36 www.google-analytics.com.
Hosts: 69.10.57.36 ad-emea.doubleclick.net.
Hosts: 69.10.57.36 http://www.statcounter.com.
Hosts: 108.163.215.51 www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
Hosts: 108.163.215.51 http://www.statcounter.com.
when i go to the hosts file it looks correct. none of those entires. somehow second life has it's own built in browser or something too and as I said all my browsers (firefox, chrome, ie) are infected. This little box in everything I mentioned including second life appears in the lower right. It's legit places but I don't want that there.
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by [redacted] at 5:51:22 on 2012-05-24
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.12279.7122 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Program Files (x86)\Silicon Image\SiI31xx HBA Wakeup Utility\SiHbaWakeupService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Alienware\Alienware TactX Mouse CI\AWMouseCI.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Alienware\Command Center\DoorController.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\ThermalController.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Alienware\Command Center\AlienFusionController.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Windows\system32\notepad.exe
C:\Program Files\SUPERAntiSpyware\4652d6ef-30b8-42b3-b681-ef4fe8a64a3d.com
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\notepad.exe
C:\Windows\notepad.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [DriverMax_RESTART]
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
mRun: [Razer Naga Driver] C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [<NO NAME>]
mRun: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
dRun: [CtxfiReg] CTXFIREG.exe /FAIL1
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AWMOUS~1.LNK - C:\Program Files (x86)\Alienware\Alienware TactX Mouse CI\AWMouseCI.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/ ... emLite.CAB
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwar ... TSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwar ... /CTPID.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{E43AB5AF-E531-4A4B-981B-9223A8A2D4E1} : DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
LSA: Notification Packages = scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun-x64: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
mRun-x64: [Razer Naga Driver] C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [(Default)]
mRun-x64: [Razer Synapse] "C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Hosts: 69.10.57.36 http://www.google-analytics.com.
Hosts: 69.10.57.36 ad-emea.doubleclick.net.
Hosts: 69.10.57.36 http://www.statcounter.com.
Hosts: 108.163.215.51 http://www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Lightning\AppData\Roaming\Mozilla\Firefox\Profiles\fb08nrxg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxps://www.google.com/
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Lightning\AppData\Roaming\Mozilla\Firefox\Profiles\fb08nrxg.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.searchya_i.hmpg - true
FF - user.js: extensions.searchya_i.hmpgUrl - hxxp://searchya.com/?chnl=ft-100&s=0&cr ... tBtDtBtCyD
FF - user.js: extensions.searchya_i.dfltSrch - true
FF - user.js: extensions.searchya_i.srchPrvdr - SearchYa!
FF - user.js: extensions.searchya_i.dnsErr - true
FF - user.js: extensions.searchya_i.newTab - true
FF - user.js: extensions.searchya_i.newTabUrl - hxxp://searchya.com/?chnl=ft-100&s=2&cr ... tBtDtBtCyD
FF - user.js: extensions.searchya_i.tlbrSrchUrl - hxxp://searchya.com/?chnl=ft-100&s=3&cr ... DtBtCyD&q=
FF - user.js: extensions.searchya_i.id - bacb074a000000000000a4badbfd71ba
FF - user.js: extensions.searchya_i.instlDay - 15385
FF - user.js: extensions.searchya_i.vrsn - 1.5.13.0
FF - user.js: extensions.searchya_i.vrsni - 1.5.13.0
FF - user.js: extensions.searchya_i.vrsnTs - 1.5.13.014:39:16
FF - user.js: extensions.searchya_i.prtnrId - ironsrc
FF - user.js: extensions.searchya_i.prdct - searchya
FF - user.js: extensions.searchya_i.aflt - foxtab
FF - user.js: extensions.searchya_i.smplGrp - none
FF - user.js: extensions.searchya_i.tlbrId - base
FF - user.js: extensions.searchya_i.instlRef - ft-100
FF - user.js: extensions.searchya_i.dfltLng -
FF - user.js: extensions.searchya_i.excTlbr - false
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2010-11-5 15296]
R2 BrcmMgmtAgent;Broadcom Management Agent;C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [2011-1-14 163328]
R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-12-7 13336]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-4-21 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-5-21 1262400]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
R2 SiHbaWakeupService;SiI31xx HBA Wakeup Utility;C:\Program Files (x86)\Silicon Image\SiI31xx HBA Wakeup Utility\SiHbaWakeupService.exe [2009-7-27 62464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-5-15 382272]
R3 AWOPFilterDriver;AWOPFilterDriver;\??\C:\Windows\system32\drivers\AWOPFilterDriver.sys --> C:\Windows\system32\drivers\AWOPFilterDriver.sys [?]
R3 CT20XUT.SYS;CT20XUT.SYS;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
R3 CTHWIUT.SYS;CTHWIUT.SYS;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
R3 danewFltr;NewDeathAdder Mouse;C:\Windows\system32\drivers\danew.sys --> C:\Windows\system32\drivers\danew.sys [?]
R3 ha20x22k;Creative 20X2 HAL Driver;C:\Windows\system32\drivers\ha20x22k.sys --> C:\Windows\system32\drivers\ha20x22k.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 mio;Master IO Filter Driver;C:\Windows\system32\DRIVERS\mio.sys --> C:\Windows\system32\DRIVERS\mio.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 rzudd;Razer Mouse Driver;C:\Windows\system32\DRIVERS\rzudd.sys --> C:\Windows\system32\DRIVERS\rzudd.sys [?]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2010/12/07 15:29:09;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-4-26 232944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-22 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-1 257696]
S3 btwampfl;btwampfl Bluetooth filter driver;\??\C:\Windows\system32\drivers\btwampfl.sys --> C:\Windows\system32\drivers\btwampfl.sys [?]
S3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\system32\DRIVERS\btwdpan.sys --> C:\Windows\system32\DRIVERS\btwdpan.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-1-6 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-12-7 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-1-6 79360]
S3 CT20XUT;CT20XUT;C:\Windows\system32\drivers\CT20XUT.SYS --> C:\Windows\system32\drivers\CT20XUT.SYS [?]
S3 CTEXFIFX;CTEXFIFX;C:\Windows\system32\drivers\CTEXFIFX.SYS --> C:\Windows\system32\drivers\CTEXFIFX.SYS [?]
S3 CTHWIUT;CTHWIUT;C:\Windows\system32\drivers\CTHWIUT.SYS --> C:\Windows\system32\drivers\CTHWIUT.SYS [?]
S3 DAdderFltr;DeathAdder Mouse;C:\Windows\system32\drivers\dadder.sys --> C:\Windows\system32\drivers\dadder.sys [?]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2012-1-26 135584]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-22 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-25 129976]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RzSynapse;Razer Driver;C:\Windows\system32\DRIVERS\RzSynapse.sys --> C:\Windows\system32\DRIVERS\RzSynapse.sys [?]
S3 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-10-14 994360]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;C:\Windows\system32\DRIVERS\gtkdrv.sys --> C:\Windows\system32\DRIVERS\gtkdrv.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2012-2-1 214896]
S4 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2010-12-7 1692480]
.
=============== Created Last 30 ================
.
2012-05-24 03:08:58 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E7CE8D9A-235C-49A7-A1A9-827D127FAFF9}\offreg.dll
2012-05-23 23:30:57 -------- d-----w- C:\Users\Lightning\AppData\Local\{7BAB18E2-0345-477B-A322-78BA2930A22D}
2012-05-23 23:30:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{BB80044A-27DD-4568-A6B8-90F3BCC15D2A}
2012-05-23 23:30:03 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E7CE8D9A-235C-49A7-A1A9-827D127FAFF9}\mpengine.dll
2012-05-22 20:46:36 -------- d-----w- C:\Users\Lightning\AppData\Local\{08496945-B200-4845-8F5D-625317B58129}
2012-05-22 20:46:25 -------- d-----w- C:\Users\Lightning\AppData\Local\{5555DA86-B1D2-4B27-8DC3-4DB836AB5FF0}
2012-05-22 08:35:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{B402261C-0006-43FD-ACBD-14EE7985C9D9}
2012-05-22 08:34:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{F46CE1F7-7274-4FA1-B889-7282B50E1D2B}
2012-05-22 08:34:42 -------- d-----w- C:\Users\Lightning\AppData\Local\{5490BD05-34BF-4615-867C-B579544822E6}
2012-05-22 08:34:31 -------- d-----w- C:\Users\Lightning\AppData\Local\{15173883-3AE6-4676-8C34-49A93C5E183E}
2012-05-22 08:34:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{9CB6E20C-16A8-4AF4-9BC2-C4A777A319E2}
2012-05-22 08:32:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{BB76A48C-91C5-4792-8B44-2BA1A7393043}
2012-05-22 08:09:59 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-22 00:14:21 978944 ----a-w- C:\Windows\System32\msvcp71.dll
2012-05-22 00:14:21 520192 ----a-w- C:\Windows\System32\msvcr71.dll
2012-05-22 00:14:21 381952 ----a-w- C:\Windows\System32\nvexpBar.dll
2012-05-22 00:14:21 372736 ----a-w- C:\Windows\System32\NVUNINST.EXE
2012-05-22 00:14:21 2065920 ----a-w- C:\Windows\System32\nvcplUI.exe
2012-05-22 00:14:21 1524736 ----a-w- C:\Windows\System32\MFC71.dll
2012-05-22 00:14:21 1064448 ----a-w- C:\Windows\System32\nvcplUIR.dll
2012-05-22 00:14:12 -------- d-----w- C:\Users\Lightning\AppData\Local\NVIDIA Corporation
2012-05-22 00:13:29 -------- d-----w- C:\Program Files (x86)\NVIDIA nTune Performance Application
2012-05-21 20:23:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{695A79C2-D774-4B05-8836-CF4D4C6F8013}
2012-05-21 20:23:42 -------- d-----w- C:\Users\Lightning\AppData\Local\{7B355EC0-7E15-43C7-B562-AF4E8DD9D68D}
2012-05-20 23:00:47 -------- d-----w- C:\Users\Lightning\AppData\Local\{DB9EE5E3-BCB2-4489-8A4B-1F5D3D8417B7}
2012-05-20 23:00:37 -------- d-----w- C:\Users\Lightning\AppData\Local\{480D3817-F403-4BA6-81BF-D6B56BF03F56}
2012-05-20 10:09:51 -------- d-----w- C:\Users\Lightning\AppData\Local\{3E5F4D3D-494A-46DB-B2A6-517E5865FAF3}
2012-05-20 10:09:29 -------- d-----w- C:\Users\Lightning\AppData\Local\{FC2098F1-6104-4186-931E-9342F7F66486}
2012-05-19 22:09:04 -------- d-----w- C:\Users\Lightning\AppData\Local\{0286F34E-FF9A-4042-80E3-1C9D8987EEEB}
2012-05-19 22:08:53 -------- d-----w- C:\Users\Lightning\AppData\Local\{23DDD0B7-A008-460B-BF1D-88EF14C2FAFA}
2012-05-19 09:49:40 -------- d-----w- C:\Users\Lightning\AppData\Local\{B17B0578-8C27-45BA-839E-4977E02BECEF}
2012-05-19 09:49:18 -------- d-----w- C:\Users\Lightning\AppData\Local\{1805F74D-429B-455A-B089-47BE66E13C23}
2012-05-19 01:26:18 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-05-19 01:26:18 126312 ----a-w- C:\Windows\System32\GEARAspi64.dll
2012-05-19 01:26:18 107368 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-05-19 01:25:56 -------- d-----w- C:\Program Files\iPod
2012-05-19 01:25:55 -------- d-----w- C:\Program Files\iTunes
2012-05-19 01:25:55 -------- d-----w- C:\Program Files (x86)\iTunes
2012-05-19 01:25:16 -------- d-----w- C:\Program Files\Bonjour
2012-05-19 01:25:16 -------- d-----w- C:\Program Files (x86)\Bonjour
2012-05-18 21:48:53 -------- d-----w- C:\Users\Lightning\AppData\Local\{F189A3B2-94A4-497C-A7C9-A1D6B3AAC1A3}
2012-05-18 21:48:30 -------- d-----w- C:\Users\Lightning\AppData\Local\{36B14775-2FCD-4C74-AF86-0A2886F176CC}
2012-05-18 02:41:41 -------- d-----w- C:\Users\Lightning\AppData\Local\Razer
2012-05-18 00:37:25 -------- d-----w- C:\Users\Lightning\AppData\Local\{3855A4A5-21D6-4A8D-B5E8-AE1368D19F9C}
2012-05-18 00:37:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{0AF56C2D-CB34-42AD-BDE4-920F275B4B5D}
2012-05-17 08:58:28 -------- d-----w- C:\Users\Lightning\AppData\Local\{8CC8A56C-3836-4A5D-83F1-E0BD93665C70}
2012-05-17 08:58:17 -------- d-----w- C:\Users\Lightning\AppData\Local\{1BE0983F-6804-487C-AEC7-914FAAB4E254}
2012-05-16 20:58:04 -------- d-----w- C:\Users\Lightning\AppData\Local\{5BE81193-AD0F-46B8-ADFD-74990CDCB0D3}
2012-05-16 20:57:53 -------- d-----w- C:\Users\Lightning\AppData\Local\{0BA64573-696A-4E67-A94C-3AD7CDB089F5}
2012-05-16 01:16:43 -------- d-----w- C:\Users\Lightning\AppData\Local\{E75028C4-70DF-4107-9CBF-3EF596F12B9E}
2012-05-16 01:16:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{218AA661-9B58-44AB-BAC2-A81055215E03}
2012-05-15 07:21:50 423744 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2012-05-15 05:58:36 -------- d-----w- C:\Users\Lightning\AppData\Local\{7ACCF44C-0D4B-4C6F-8527-312333CA5215}
2012-05-15 05:57:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{D5300770-F350-44F0-9209-A15003EF8BDB}
2012-05-14 17:57:33 -------- d-----w- C:\Users\Lightning\AppData\Local\{92E86B17-5B88-4709-BB0F-1D4206397A32}
2012-05-14 17:57:11 -------- d-----w- C:\Users\Lightning\AppData\Local\{9F4A09C6-B8B6-450C-95C5-B7B810267CBE}
2012-05-14 00:28:44 -------- d-----w- C:\Users\Lightning\AppData\Local\{78E4DA42-CCF5-4838-BA8E-C0779EED6898}
2012-05-14 00:28:33 -------- d-----w- C:\Users\Lightning\AppData\Local\{E065DB90-86C0-47FA-8D3A-520976B10133}
2012-05-13 00:55:11 -------- d-----w- C:\Users\Lightning\AppData\Local\{25B3C571-C789-4DEF-9816-99A4AAC3F68D}
2012-05-13 00:55:00 -------- d-----w- C:\Users\Lightning\AppData\Local\{06640C94-44C7-4D6A-8813-E7A1A7DD76A5}
2012-05-12 07:38:44 -------- d-----w- C:\Users\Lightning\AppData\Local\{ADCA69E0-44C4-449E-AE87-8402FC71DE8D}
2012-05-12 07:38:23 -------- d-----w- C:\Users\Lightning\AppData\Local\{8644B141-1767-4AF7-8B90-A0BAAAE6A91D}
2012-05-11 19:37:57 -------- d-----w- C:\Users\Lightning\AppData\Local\{5CF25E04-73C8-41A5-A001-6CE49E693D0D}
2012-05-11 19:37:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{E53F95B3-4557-4C13-AC7D-F9D65EE88FE6}
2012-05-11 07:31:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{F91E865A-A19C-47C7-9907-23D748E461D9}
2012-05-11 07:31:13 -------- d-----w- C:\Users\Lightning\AppData\Local\{05E27C7F-DB0C-4D65-AB15-57837B9AA8CC}
2012-05-10 19:31:00 -------- d-----w- C:\Users\Lightning\AppData\Local\{E5D174FB-3645-405F-B53A-28BA1B4BDC4F}
2012-05-10 19:30:39 -------- d-----w- C:\Users\Lightning\AppData\Local\{63529318-2197-4596-AB4D-9E9EAE390788}
2012-05-10 07:30:13 -------- d-----w- C:\Users\Lightning\AppData\Local\{6A69C422-5C5C-4D84-8820-4926B9F4B3B2}
2012-05-10 07:29:52 -------- d-----w- C:\Users\Lightning\AppData\Local\{0438930B-287B-4833-8987-6240411B0B6F}
2012-05-09 19:29:39 -------- d-----w- C:\Users\Lightning\AppData\Local\{0267D066-EF50-4C49-AFDB-374A41B5C182}
2012-05-09 19:29:28 -------- d-----w- C:\Users\Lightning\AppData\Local\{898F34E2-7B21-4A73-90AB-B819C3C01FEB}
2012-05-09 08:01:35 -------- d-----w- C:\e6e8d012520a8e56c76bc7665b9488
2012-05-08 20:01:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{8FAFC6F2-BF55-49DE-9587-FDA13F2CB5BD}
2012-05-08 20:00:41 -------- d-----w- C:\Users\Lightning\AppData\Local\{E12635CD-754C-43D5-821A-2322F8619B2A}
2012-05-08 08:00:17 -------- d-----w- C:\Users\Lightning\AppData\Local\{BEC338E6-BC3B-4CAE-9A47-644AB45A6262}
2012-05-08 07:59:55 -------- d-----w- C:\Users\Lightning\AppData\Local\{2C087274-22D2-4A0E-947B-2A72656076D7}
2012-05-07 19:59:42 -------- d-----w- C:\Users\Lightning\AppData\Local\{1D94EA2E-2D67-46A9-8171-DC756D842203}
2012-05-07 19:59:20 -------- d-----w- C:\Users\Lightning\AppData\Local\{6FC8C58A-A257-4650-8808-3AE9DEE31400}
2012-05-07 07:58:56 -------- d-----w- C:\Users\Lightning\AppData\Local\{56F87393-BA28-479B-9F16-D23406A85934}
2012-05-07 07:58:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{C9CFBF69-030C-4995-A8A4-AEB2F836A6AD}
2012-05-06 19:58:21 -------- d-----w- C:\Users\Lightning\AppData\Local\{D9098F0C-F754-44ED-9C5A-EE73C06E4754}
2012-05-06 19:57:59 -------- d-----w- C:\Users\Lightning\AppData\Local\{B22849BF-F535-4B15-85D9-A488B2555F00}
2012-05-06 07:57:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{04E72FB9-2CBA-4AE7-8016-E37A24387E94}
2012-05-06 07:57:13 -------- d-----w- C:\Users\Lightning\AppData\Local\{EAF4D99A-0FFE-472A-8C5B-90B55B9219AE}
2012-05-05 19:57:00 -------- d-----w- C:\Users\Lightning\AppData\Local\{D720956D-6D99-437D-8C44-9952C1B5D36C}
2012-05-05 19:56:49 -------- d-----w- C:\Users\Lightning\AppData\Local\{036A2801-81C5-46B8-882D-3E86A970688E}
2012-05-05 07:54:02 -------- d-----w- C:\Users\Lightning\AppData\Local\{BFAEEF38-DC67-4B4A-B8F3-C31AEB70D95A}
2012-05-05 07:53:40 -------- d-----w- C:\Users\Lightning\AppData\Local\{BB4330C9-4CCE-42A0-A967-7D6B4CEB1045}
2012-05-04 19:53:24 -------- d-----w- C:\Users\Lightning\AppData\Local\{5C8AEAD7-AE7C-40B4-8594-B85F5967E9D4}
2012-05-04 19:53:02 -------- d-----w- C:\Users\Lightning\AppData\Local\{9F4A72B9-38EE-45C5-95DB-FC69F619DB20}
2012-05-04 07:49:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{538529CE-4138-4632-B24F-5231549469BB}
2012-05-04 07:49:24 -------- d-----w- C:\Users\Lightning\AppData\Local\{F2E6B971-2A3F-41B9-A3E6-0918C5672364}
2012-05-03 19:49:11 -------- d-----w- C:\Users\Lightning\AppData\Local\{73E86C5C-215F-479A-B36A-637A7DF38DF5}
2012-05-03 19:48:50 -------- d-----w- C:\Users\Lightning\AppData\Local\{0950AE19-799E-4194-9DE0-498EDCD1C910}
2012-05-03 19:32:32 -------- d-----w- C:\Users\Lightning\AppData\Local\Innovative Solutions
2012-05-03 19:32:30 -------- d-----w- C:\Program Files (x86)\Innovative Solutions
2012-05-03 19:30:50 -------- d--h--w- C:\ProgramData\Common Files
2012-05-03 07:48:25 -------- d-----w- C:\Users\Lightning\AppData\Local\{301DEB12-2569-4E72-B223-34BE50A156DD}
2012-05-03 07:48:03 -------- d-----w- C:\Users\Lightning\AppData\Local\{95BF36DE-189E-4188-A4F2-50EC68FDF560}
2012-05-02 19:47:49 -------- d-----w- C:\Users\Lightning\AppData\Local\{A97C69AB-4FE3-4A15-AD53-94305EB49E8A}
2012-05-02 19:47:38 -------- d-----w- C:\Users\Lightning\AppData\Local\{0799BCB6-5EB1-46FB-8944-72D0A33DA132}
2012-05-01 21:34:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{F99D9B7F-A6DA-4323-A171-D6004303022C}
2012-05-01 21:34:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{4CE64A14-166F-4DDA-918E-6CE3BB4ED233}
2012-05-01 09:33:45 -------- d-----w- C:\Users\Lightning\AppData\Local\{15071BF1-7FEE-406A-AB07-68272DF842A0}
2012-05-01 09:33:23 -------- d-----w- C:\Users\Lightning\AppData\Local\{8F859861-7DBD-40A0-B0D1-6C0C486E4714}
2012-05-01 08:00:53 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-04-30 21:33:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{79775016-1C83-400A-9019-6E7A2C7A56BA}
2012-04-30 21:32:49 -------- d-----w- C:\Users\Lightning\AppData\Local\{AF0C0804-AC4D-47DE-8742-C5137D76E5BC}
2012-04-30 09:32:23 -------- d-----w- C:\Users\Lightning\AppData\Local\{007421F4-B7A9-4A7F-9FDC-F39CE8B9E252}
2012-04-30 09:32:02 -------- d-----w- C:\Users\Lightning\AppData\Local\{E7C6821C-F57E-4B7D-97FA-091C8C4BE880}
2012-04-29 21:31:35 -------- d-----w- C:\Users\Lightning\AppData\Local\{1358A382-AB1E-4928-8B00-1748C215A250}
2012-04-29 21:31:24 -------- d-----w- C:\Users\Lightning\AppData\Local\{FC5B258E-EA63-4770-AA99-9F518A903DF4}
2012-04-29 11:33:15 -------- d-----w- C:\Users\Lightning\AppData\Local\{40F7C910-B02E-4C0C-A106-A53A8A18DA96}
2012-04-28 08:11:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{68375E77-8201-4288-83F8-1FB58BC1AB16}
2012-04-28 08:11:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{3C47B299-3EB5-4555-BF9D-70394E50959D}
2012-04-27 20:10:57 -------- d-----w- C:\Users\Lightning\AppData\Local\{988034D2-DF2F-43FD-917A-C08C587DD6D3}
2012-04-27 20:10:46 -------- d-----w- C:\Users\Lightning\AppData\Local\{BE77D127-68BA-458B-9222-75B3E079C8B9}
2012-04-27 07:49:32 -------- d-----w- C:\Users\Lightning\AppData\Local\{65762524-24B2-4D84-8158-E049581A1416}
2012-04-27 07:49:10 -------- d-----w- C:\Users\Lightning\AppData\Local\{B0F5A489-60E3-4D32-B394-26491296C063}
2012-04-26 23:29:49 -------- d-----w- C:\_OTL
2012-04-26 01:34:44 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2012-04-26 01:34:42 157352 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-26 01:34:42 129976 ----a-w- C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe
.
==================== Find3M ====================
.
2012-05-15 09:29:47 889664 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-05-15 09:29:46 63296 ----a-w- C:\Windows\System32\nvshext.dll
2012-05-15 09:29:46 118080 ----a-w- C:\Windows\System32\nvmctray.dll
2012-05-15 09:29:45 2621723 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-05-15 09:29:25 3149632 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-05-15 09:28:42 6151488 ----a-w- C:\Windows\System32\nvcpl.dll
2012-05-05 00:09:16 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 00:09:15 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 00:09:06 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-04-21 18:20:15 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2012-04-20 20:13:40 269712 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2012-04-18 17:08:08 31040 ----a-w- C:\Windows\System32\nvhdap64.dll
2012-04-18 17:08:03 188736 ----a-w- C:\Windows\System32\drivers\nvhda64v.sys
2012-04-18 17:08:02 1451840 ----a-w- C:\Windows\System32\nvhdagenco6420103.dll
2012-04-17 08:07:01 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-04-04 20:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-04-03 23:15:45 269712 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-03-31 06:05:57 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-03-21 01:44:12 98688 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-21 01:44:12 203888 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-03-08 23:37:20 302448 ----a-w- C:\Windows\WLXPGSS.SCR
2012-03-08 05:46:50 138752 ----a-w- C:\Windows\SysWow64\rztouchdll.dll
2012-03-05 08:49:56 19536 ----a-w- C:\Windows\System32\drivers\AWOPFilterDriver.sys
2012-03-03 06:35:38 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2012-03-03 05:31:19 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-03-01 08:32:06 284672 ----a-w- C:\Windows\SysWow64\rzdevicedll.dll
2012-03-01 06:46:16 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-03-01 06:38:27 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-03-01 06:33:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-03-01 06:28:47 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-03-01 05:37:41 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-03-01 05:33:23 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-03-01 05:29:16 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-02-28 06:39:37 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-02-28 05:38:52 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 04:31:38 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 03:52:27 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-02-24 15:36:50 230952 ----a-w- C:\Windows\System32\drivers\PCTSD64.sys
.
============= FINISH: 5:51:47.74 ===============
http://www.malwarebytes.org
Database version: v2012.05.22.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Lightning :: LIGHTNING-PC [administrator]
5/24/2012 1:54:05 AM
mbam-log-2012-05-24 (01-54-05).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 724507
Time elapsed: 2 hour(s), 9 minute(s), 3 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
It said not to post the attach file but there was this in there:
==== Hosts File Hijack ======================
.
Hosts: 69.10.57.36 www.google-analytics.com.
Hosts: 69.10.57.36 ad-emea.doubleclick.net.
Hosts: 69.10.57.36 http://www.statcounter.com.
Hosts: 108.163.215.51 www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
Hosts: 108.163.215.51 http://www.statcounter.com.
when i go to the hosts file it looks correct. none of those entires. somehow second life has it's own built in browser or something too and as I said all my browsers (firefox, chrome, ie) are infected. This little box in everything I mentioned including second life appears in the lower right. It's legit places but I don't want that there.

... then save the file to your desktop as ESETScan.txt.