Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Suspected Malware Cause of Multiple DLL Errors.  (Read 43442 times)

0 Members and 1 Guest are viewing this topic.

Sirim

    Topic Starter


    Rookie

    Thanked: 2
    • Experience: Familiar
    • OS: Windows 7
    Suspected Malware Cause of Multiple DLL Errors.
    « on: September 16, 2012, 04:13:52 PM »
    Hi,

    I am not entirely sure whether this is the best sub-forum to post this thread under, so feel free to move the thread if needed.

    A few days ago, I started encountering a lot of DLL errors from DLLs mostly (but not exclusively) contained within the C:\Windows\System32 directory. I do not recall installing or uninstalling anything around the time the errors started. In no particular order, these were:

    'C:\Windows\system32\dxva2.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.' - on trying to play any flash video. The file description is 'DirectX Video Acceleration 2.0 DLL'.

    'C:\Program Files (x86)\OpenOffice.org 3\URE\bin\uwinapi.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.' - on attempting to launch any applications within the OpenOffice.org suite. The file description field is blank.

    'C:\Windows\System32\pnrpnsp.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.' - always on attempting to launch multiplayer mode within Halo: Combat Evolved and sometimes when within the multiplayer mode of Battlefield 2. The file description is PNRP name space provider.

    The first suggested fix I found was entering sfc/scannow at the command line. After it had completed, the DLLs still failed to work. I have included the relevant part of the log at the bottom of the post.

    I then queued a chkdsk and restarted my computer, in case it was a hard drive corruption to blame. No errors were found.

    As multiple DLL errors were occurring in a variety of a different applications when none had been occurring before, I considered that malware may be the cause of the issues. I performed a full scan with AVG anti-virus software in which it found one infection: "C:\Program Files (x86)\OpenOffice.org 3\program\svxmi.dll";"Virus found Win32/Heur";"Moved to Virus Vault" . I understand that this means that it was the heuristics scanning which found the suspected malware rather than a match being made to any of the malware AVG is aware of. So, although it is highly probable that the file in question was infected, it may not be the only one (how likely is it that a dll of one application can in itself cause multiple windows dlls to cease to function?). Alternatively, it is possible (though highly unlikely) that (perhaps there was no malware present on my system at the start) the .dll issues are caused by something else entirely, meaning this thread would then be in the wrong section of the forum.

    I then attempted to run Malwarebytes Anti-Malware, but received the error message:

    'Run-time error '50003':

    Unexpected error'

    On looking this error up, I discovered that it was caused by missing windows DLLs.

    I then attempted to launch msconfig (to disable any suspicious start-up items, in case the malware was still present) and Event Viewer (to see if any useful information about the program could be gathered from there). Neither was able to launch, both twice displaying the error:

    'C:\Windows\system32\odbcint.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.'
    The file description field is blank.

    I then launched the system restore application, but the only restore point listed was earlier today (with show more restore points checked). I realized this would be pointless, so exited the application.

    I would have considered inserting the windows installation disk and repairing/reinstalling windows, but unfortunately my laptop was not supplied with one and I foolishly failed to create one. I understand that it is possible to legally download windows 7 in an ISO format (for example as described in http://www.pcworld.com/article/248995/how_to_install_windows_7_without_the_disc.html), however, for obvious reasons, this is far from ideal, not least because I would presumably have a lot of driver-finding to do.

    I then came to this forum and followed the instructions in the 'IMPORTANT: Read this before requesting malware removal help' thread. I thus now confirm that my laptop is for personal use.

    I have read the 'Missing Microsoft Windows .dll files' page on this website (http://www.computerhope.com/issues/ch000749.htm). The two suggestions it made were to follow the troubleshooting steps described in Basic computer troubleshooting (none of which seemed relevant to my situation) and then, should errors persist, to reinstall windows (I do not have the installation disk).

    I ran CCleaner with no issue.

    I then ran adwcleaner, receiving the error message 'C:\Windows\system32\asycfilt.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.'  It still started, however, and did not find any malware. The log is included at the bottom of the post.

    As stated above, I had previously attempted to launch Malwarebytes Anti-Malware with no success.

    I ran DDS with no errors. Both logs are included at the bottom of this post.

    I attempted to run HijackThis, but without success. I received the same error as when I had tried to run Malwarebytes Anti-Malware:

    'Run-time error '50003':

    Unexpected error'


    I then ran SUPERAntiSpyware with no errors. It found the computer to be clean. The log is included at the bottom of the post.

    Advice much appreciated.

    Edit: it appears the post character limit allowed by the forum is insufficient for the logs to be posted in the manner requested. I have found each one of them again and instead attached them as files, over this and following posts. A simple notification that I'd exceeded the character count would have saved me much time.

    Edit 2: a response was received before I had the time to find all the log files. I am thus postponing this until later, should it be required.

    [year+ old attachment deleted by admin]
    « Last Edit: September 16, 2012, 04:57:46 PM by Sirim »

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Suspected Malware Cause of Multiple DLL Errors.
    « Reply #1 on: September 16, 2012, 04:52:53 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************
    First, let's try download vbrun60sp6.exe and see what happens. Can you boot in Safe Mode? If so, please try running MBAM from Safe mode.
    Windows 8 and Windows 10 dual boot with two SSD's

    Sirim

      Topic Starter


      Rookie

      Thanked: 2
      • Experience: Familiar
      • OS: Windows 7
      Re: Suspected Malware Cause of Multiple DLL Errors.
      « Reply #2 on: September 16, 2012, 05:10:19 PM »
      Thank-you for your extremely swift response. I have downloaded the linked exe and have extracted and run it. DLL errors still occur. I will now reboot and enter safe mode and try to run Malwarebytes Anti-Malware, though if the DLLs it requires are damaged, I doubt this will resolve the issue.

      Sirim

        Topic Starter


        Rookie

        Thanked: 2
        • Experience: Familiar
        • OS: Windows 7
        Re: Suspected Malware Cause of Multiple DLL Errors.
        « Reply #3 on: September 16, 2012, 05:42:18 PM »
        Apologies for the double post.

        I was unable to boot into safe mode. After loading the driver C:\Windows\system32\Drivers\AtiPcie.sys, nothing visibly occurred for the next 15 minutes or so and I was obliged to force an improper shutdown via the power button. I tried to boot into safe mode twice more, but on each occasion it stopped at the same stage. I am not sure if this driver is relevant, if the driver to be loaded after it (if one exists) is important or if it was the last of the drivers to be loaded and the issue occurred after the drivers had been loaded.

        Sirim

          Topic Starter


          Rookie

          Thanked: 2
          • Experience: Familiar
          • OS: Windows 7
          Re: Suspected Malware Cause of Multiple DLL Errors.
          « Reply #4 on: September 16, 2012, 05:56:47 PM »
          Apologies for the tripple-post. The logs missing from the first post on account of the character and attachment limits are now posted here.

          .
          DDS (Ver_2011-08-26.01) - NTFSAMD64
          Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_34
          Run by Removed at 0:48:43 on 2012-09-17
          Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.4092.2683 [GMT 1:00]
          .
          AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
          SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
          SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          .
          ============== Running Processes ===============
          .
          C:\PROGRA~2\AVG\AVG10\avgchsva.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe -k DcomLaunch
          C:\Windows\system32\svchost.exe -k RPCSS
          C:\Windows\system32\atiesrxx.exe
          C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
          C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
          C:\Windows\system32\svchost.exe -k netsvcs
          C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe
          C:\Windows\system32\svchost.exe -k LocalService
          C:\Windows\system32\svchost.exe -k NetworkService
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
          C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
          C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
          C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
          C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
          C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
          C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
          C:\Windows\SysWOW64\svchost.exe -k netsvcs
          C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe
          C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
          c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
          C:\Windows\SysWOW64\PnkBstrA.exe
          C:\Program Files\Macrium\Reflect\ReflectService.exe
          C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
          C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
          c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
          C:\Windows\system32\svchost.exe -k imgsvc
          C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
          C:\Program Files (x86)\VirtualDub-1.9.11 with DShowInputDriver\plugins\Activation\pg.exe
          C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
          C:\Windows\system32\taskhost.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
          C:\Program Files (x86)\AVG\AVG10\avgemca.exe
          C:\Windows\system32\conhost.exe
          C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
          C:\Program Files (x86)\AVG Secure Search\vprot.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files (x86)\Windows Media Player\wmplayer.exe
          C:\Windows\system32\svchost.exe -k bthsvcs
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
          C:\Windows\System32\svchost.exe -k LocalServicePeerNet
          C:\Windows\system32\taskeng.exe
          c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
          C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
          C:\Program Files (x86)\Opera\opera.exe
          C:\Windows\system32\wuauclt.exe
          C:\PROGRA~2\AVG\AVG10\avgrsa.exe
          C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
          C:\Windows\SysWOW64\cmd.exe
          C:\Windows\system32\conhost.exe
          C:\Windows\SysWOW64\cscript.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          .
          ============== Pseudo HJT Report ===============
          .
          uStart Page = hxxp://www.google.co.uk/
          mURLSearchHooks: H - No File
          BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
          BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
          BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
          BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
          BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
          BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
          BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
          BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
          TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
          TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
          TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
          TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
          {e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
          uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
          mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
          mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe"  /DoAction
          mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
          mRun: [ROC_ROC_JULY_P1] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1
          mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
          mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
          mPolicies-system: EnableLUA = 0 (0x0)
          mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
          mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
          mPolicies-system: HideFastUserSwitching = 0 (0x0)
          IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
          IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
          IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
          IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
          IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
          IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
          DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
          DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab
          DPF: {CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab
          DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_34-windows-i586.cab
          TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
          TCP: Interfaces\{26FFC4B7-D354-4D4D-A6AE-13B6669ABBD9} : DhcpNameServer = 194.168.4.100 194.168.8.100
          TCP: Interfaces\{26FFC4B7-D354-4D4D-A6AE-13B6669ABBD9}\2456C6B696E6F574F505C65737F5D494D4F4F5441413431364 : DhcpNameServer = 192.168.2.1
          TCP: Interfaces\{26FFC4B7-D354-4D4D-A6AE-13B6669ABBD9}\35B4957383235373 : DhcpNameServer = 192.168.0.1
          TCP: Interfaces\{887AB1F5-0825-4168-8858-A58B165D5035} : DhcpNameServer = 192.168.0.1
          Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
          Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
          Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
          Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
          mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
          BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          BHO-X64:     AcroIEHelperStub - No File
          BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
          BHO-X64:     Increase performance and video formats for your HTML5 <video> - No File
          BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
          BHO-X64:     WormRadar.com IESiteBlocker.NavFilter - No File
          BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
          BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
          BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
          BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
          BHO-X64:     SkypeIEPluginBHO - No File
          BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
          BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
          TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
          TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
          TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
          TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
          mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
          mRun-x64: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe"  /DoAction
          mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
          mRun-x64: [ROC_ROC_JULY_P1] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1
          IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
          .
          ================= FIREFOX ===================
          .
          FF - ProfilePath - C:\Users\Removed\AppData\Roaming\Mozilla\Firefox\Profiles\rda0e265.default\
          FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
          FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
          FF - prefs.js: keyword.URL - hxxp://www.google.co.uk/#hl=en&output=search&sclient=psy-ab&q=
          FF - plugin: C:\Program Files (x86)\Autograph 3.3\WebPlayer\npagraph.dll
          FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\npsitesafety.dll
          FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
          FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
          FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
          FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
          FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
          FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
          FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
          FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
          FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
          FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
          FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
          .
          ============= SERVICES / DRIVERS ===============
          .
          R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
          R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
          R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
          R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
          R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
          R1 avgtp;avgtp;\??\C:\Windows\system32\drivers\avgtpx64.sys --> C:\Windows\system32\drivers\avgtpx64.sys [?]
          R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
          R1 FreeOTFE;FreeOTFE;\??\C:\Windows\System32\FreeOTFE.sys --> C:\Windows\System32\FreeOTFE.sys [?]
          R1 FreeOTFECypherAES_ltc;FreeOTFECypherAES_ltc;\??\C:\Windows\System32\FreeOTFECypherAES_ltc.sys --> C:\Windows\System32\FreeOTFECypherAES_ltc.sys [?]
          R1 FreeOTFEHashSHA;FreeOTFEHashSHA;\??\C:\Windows\System32\FreeOTFEHashSHA.sys --> C:\Windows\System32\FreeOTFEHashSHA.sys [?]
          R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
          R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
          R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
          R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
          R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
          R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2012-1-31 7391072]
          R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
          R2 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
          R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
          R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-14 20992]
          R2 InternetEverywhere_Service;InternetEverywhere_Service;C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe [2011-6-9 329168]
          R2 Neurotechnology;Neurotechnology;C:\Program Files (x86)\VirtualDub-1.9.11 with DShowInputDriver\plugins\Activation\pg.exe [2012-3-20 230720]
          R2 ReflectService;Macrium Reflect Image Mounting Service;C:\Program Files\Macrium\Reflect\ReflectService.exe [2010-1-28 294880]
          R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-8-13 3064000]
          R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-9-4 722528]
          R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
          R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
          R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
          R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys --> C:\Windows\system32\DRIVERS\enecir.sys [?]
          R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
          R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?]
          S2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-3-2 89600]
          S2 ccosm;Contrl Center of Storm Media;\\JHV-PC-8GIGRAM\Downloads\StormII\stormliv.exe /asservice --> \\JHV-PC-8GIGRAM\Downloads\StormII\stormliv.exe  [?]
          S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
          S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
          S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-5 135664]
          S2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
          S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-3 160944]
          S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-6-11 167264]
          S3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-10-31 228408]
          S3 FreeOTFECypherBlowfish;FreeOTFECypherBlowfish;\??\C:\Windows\System32\FreeOTFECypherBlowfish.sys --> C:\Windows\System32\FreeOTFECypherBlowfish.sys [?]
          S3 FreeOTFECypherCAST5;FreeOTFECypherCAST5;\??\C:\Windows\System32\FreeOTFECypherCAST5.sys --> C:\Windows\System32\FreeOTFECypherCAST5.sys [?]
          S3 FreeOTFECypherCAST6_Gladman;FreeOTFECypherCAST6_Gladman;\??\C:\Windows\System32\FreeOTFECypherCAST6_Gladman.sys --> C:\Windows\System32\FreeOTFECypherCAST6_Gladman.sys [?]
          S3 FreeOTFECypherDES;FreeOTFECypherDES;\??\C:\Windows\System32\FreeOTFECypherDES.sys --> C:\Windows\System32\FreeOTFECypherDES.sys [?]
          S3 FreeOTFECypherMARS_Gladman;FreeOTFECypherMARS_Gladman;\??\C:\Windows\System32\FreeOTFECypherMARS_Gladman.sys --> C:\Windows\System32\FreeOTFECypherMARS_Gladman.sys [?]
          S3 FreeOTFECypherRC6_ltc;FreeOTFECypherRC6_ltc;\??\C:\Windows\System32\FreeOTFECypherRC6_ltc.sys --> C:\Windows\System32\FreeOTFECypherRC6_ltc.sys [?]
          S3 FreeOTFECypherSerpent_Gladman;FreeOTFECypherSerpent_Gladman;\??\C:\Windows\System32\FreeOTFECypherSerpent_Gladman.sys --> C:\Windows\System32\FreeOTFECypherSerpent_Gladman.sys [?]
          S3 FreeOTFECypherTwofish_ltc;FreeOTFECypherTwofish_ltc;\??\C:\Windows\System32\FreeOTFECypherTwofish_ltc.sys --> C:\Windows\System32\FreeOTFECypherTwofish_ltc.sys [?]
          S3 FreeOTFEHashMD;FreeOTFEHashMD;\??\C:\Windows\System32\FreeOTFEHashMD.sys --> C:\Windows\System32\FreeOTFEHashMD.sys [?]
          S3 FreeOTFEHashRIPEMD;FreeOTFEHashRIPEMD;\??\C:\Windows\System32\FreeOTFEHashRIPEMD.sys --> C:\Windows\System32\FreeOTFEHashRIPEMD.sys [?]
          S3 FreeOTFEHashTiger;FreeOTFEHashTiger;\??\C:\Windows\System32\FreeOTFEHashTiger.sys --> C:\Windows\System32\FreeOTFEHashTiger.sys [?]
          S3 FreeOTFEHashWhirlpool;FreeOTFEHashWhirlpool;\??\C:\Windows\System32\FreeOTFEHashWhirlpool.sys --> C:\Windows\System32\FreeOTFEHashWhirlpool.sys [?]
          S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
          S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-5 135664]
          S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
          S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-8-4 113120]
          S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
          S3 PSMounter;Macrium Reflect Image Explorer Service;\??\C:\Windows\system32\drivers\psmounter.sys --> C:\Windows\system32\drivers\psmounter.sys [?]
          S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
          S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
          S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
          S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
          S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
          S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
          S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009-7-22 61976]
          S4 PCPitstop Scheduling;PCPitstop Scheduling;C:\Program Files (x86)\PCPitstop\PCPitstopScheduleService.exe [2011-6-24 90352]
          S4 RsFx0105;RsFx0105 Driver;C:\Windows\system32\DRIVERS\RsFx0105.sys --> C:\Windows\system32\DRIVERS\RsFx0105.sys [?]
          S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-9-22 431464]
          .
          =============== Created Last 30 ================
          .
          2012-09-16 23:34:01   --------   d-sh--w-   C:\$RECYCLE.BIN
          2012-09-16 22:18:14   98816   ----a-w-   C:\Windows\sed.exe
          2012-09-16 22:18:14   518144   ----a-w-   C:\Windows\SWREG.exe
          2012-09-16 22:18:14   256000   ----a-w-   C:\Windows\PEV.exe
          2012-09-16 22:18:14   208896   ----a-w-   C:\Windows\MBR.exe
          2012-09-16 14:28:24   --------   d-----w-   C:\Users\Removed\AppData\Roaming\SUPERAntiSpyware.com
          2012-09-16 14:28:16   --------   d-----w-   C:\ProgramData\SUPERAntiSpyware.com
          2012-09-16 14:28:16   --------   d-----w-   C:\Program Files\SUPERAntiSpyware
          2012-09-16 14:22:00   --------   d-----w-   C:\Program Files (x86)\Trend Micro
          2012-09-16 11:16:52   --------   d-----w-   C:\Users\Removed\AppData\Roaming\Malwarebytes
          2012-09-16 11:16:40   --------   d-----w-   C:\ProgramData\Malwarebytes
          2012-09-16 11:16:39   25928   ----a-w-   C:\Windows\System32\drivers\mbam.sys
          2012-09-16 11:16:39   --------   d-----w-   C:\Program Files (x86)\Malwarebytes' Anti-Malware
          2012-09-14 21:30:15   --------   d-----w-   C:\Program Files (x86)\GameSpy Arcade
          2012-09-14 16:30:31   --------   d-----w-   C:\Program Files (x86)\WildTangent Games
          2012-09-09 18:12:47   --------   d-----w-   C:\Games
          2012-09-09 18:11:43   --------   d-----w-   C:\Program Files\red alert 2
          2012-09-04 11:49:39   31080   ----a-w-   C:\Windows\System32\drivers\avgtpx64.sys
          2012-09-01 20:27:18   --------   d-----w-   C:\ProgramData\Battle.net
          2012-08-27 12:24:38   552960   ----a-w-   C:\Windows\System32\drivers\bthport.sys
          .
          ==================== Find3M  ====================
          .
          2012-09-14 22:00:43   102400   ----a-w-   C:\Windows\System32\drivers\dfsc.sys
          2012-09-14 22:00:42   680448   ----a-w-   C:\Windows\System32\adtschema.dll
          2012-09-13 17:44:37   234536   ----a-w-   C:\Windows\SysWow64\PnkBstrB.xtr
          2012-09-13 17:44:37   234536   ----a-w-   C:\Windows\SysWow64\PnkBstrB.exe
          2012-08-15 17:32:03   477168   ----a-w-   C:\Windows\SysWow64\npdeployJava1.dll
          2012-08-15 17:32:03   473072   ----a-w-   C:\Windows\SysWow64\deployJava1.dll
          2012-08-09 23:11:16   30   ----a-w-   C:\Windows\System32\tkkc.bat
          2012-07-18 18:15:06   3148800   ----a-w-   C:\Windows\System32\win32k.sys
          2012-07-04 22:13:27   59392   ----a-w-   C:\Windows\System32\browcli.dll
          2012-07-04 22:13:27   136704   ----a-w-   C:\Windows\System32\browser.dll
          2012-07-04 21:14:34   41984   ----a-w-   C:\Windows\SysWow64\browcli.dll
          2012-06-29 03:56:34   2312704   ----a-w-   C:\Windows\System32\jscript9.dll
          2012-06-29 03:49:11   1392128   ----a-w-   C:\Windows\System32\wininet.dll
          2012-06-29 03:48:07   1494528   ----a-w-   C:\Windows\System32\inetcpl.cpl
          2012-06-29 03:43:49   173056   ----a-w-   C:\Windows\System32\ieUnatt.exe
          2012-06-29 03:39:48   2382848   ----a-w-   C:\Windows\System32\mshtml.tlb
          2012-06-29 00:16:58   1800704   ----a-w-   C:\Windows\SysWow64\jscript9.dll
          2012-06-29 00:09:01   1129472   ----a-w-   C:\Windows\SysWow64\wininet.dll
          2012-06-29 00:08:59   1427968   ----a-w-   C:\Windows\SysWow64\inetcpl.cpl
          2012-06-29 00:04:43   142848   ----a-w-   C:\Windows\SysWow64\ieUnatt.exe
          2012-06-29 00:00:45   2382848   ----a-w-   C:\Windows\SysWow64\mshtml.tlb
          .
          ============= FINISH:  0:49:30.36 ===============

          [year+ old attachment deleted by admin]

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Suspected Malware Cause of Multiple DLL Errors.
          « Reply #5 on: September 16, 2012, 07:30:42 PM »
          Remove the Adware:
          • Please close all open programs and internet browsers.
          • Double click on adwcleaner.exe to run the tool.
          • Click on Delete.
          • Confirm each time with OK
          • Your computer will be rebooted automatically. A text file will open after the restart.
          • Please post the content of that logfile in your reply.
          • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
          **********************************************
          Please read here for more information about WildTangent. Your choice if you want to remove it or not.

          If you choose to follow my advice, please follow these instructions.

          Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

          WildTangent Web Driveror anything related to WildTangent.
          *****************************************************
          When you ran SFC Scannow did you have your OS disk in the drive?
          If I forget, please remind me about updating Java later.
          Please don't attach your logs. Copy and paste them in your reply/ies.


          Please download aswMBR.exe ( 511KB ) to your desktop.

          Double click the aswMBR.exe to run it



          Click the "Scan" button to start scan

          Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives



          On completion of the scan click save log, save it to your desktop and post in your next reply
          **************************************************************
          • Download RogueKiller on the desktop
          • Close all the running programs
          • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
          • Otherwise just double-click on RogueKiller.exe
          • Pre-scan will start. Let it finish.
          • Click on SCAN button.
          • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
          • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
          Windows 8 and Windows 10 dual boot with two SSD's

          Sirim

            Topic Starter


            Rookie

            Thanked: 2
            • Experience: Familiar
            • OS: Windows 7
            Re: Suspected Malware Cause of Multiple DLL Errors.
            « Reply #6 on: September 17, 2012, 08:26:20 AM »
            Many thanks for your continued help.

            Remove the Adware:
            • Please close all open programs and internet browsers.
            • Double click on adwcleaner.exe to run the tool.
            • Click on Delete.
            • Confirm each time with OK
            • Your computer will be rebooted automatically. A text file will open after the restart.
            • Please post the content of that logfile in your reply.
            • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
            **********************************************

            I ran adwcleaner, this time with the delete option. The first time I attempted it it went non-responsive part-way through, but the second time it completed. Both logs included at the bottom of the post.

            Please read here for more information about WildTangent. Your choice if you want to remove it or not.

            If you choose to follow my advice, please follow these instructions.

            Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

            WildTangent Web Driveror anything related to WildTangent.
            *****************************************************

            I have removed the only application with WildTangent in the name.

            When you ran SFC Scannow did you have your OS disk in the drive?

            Perhaps I am misunderstanding you here, but if you were enquiring as to whether I had the OS (re)installation disc in the optical drive, the answer would be 'no', because the laptop was not supplied with one and I failed to create an equivalent (as previously stated).


            If I forget, please remind me about updating Java later.
            Please don't attach your logs. Copy and paste them in your reply/ies.



            As stated previously, the reason I resorted to attaching the logs was that they appeared to exceed the character limit when put into the post. I will now ensure I paste them into as many posts as they require instead.


            Please download aswMBR.exe ( 511KB ) to your desktop.

            Double click the aswMBR.exe to run it



            Click the "Scan" button to start scan

            Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives



            On completion of the scan click save log, save it to your desktop and post in your next reply
            **************************************************************

            I downloaded the program, accepted its offer to download the avast anti-virus database and ran a scan. The log is included below.

            • Download RogueKiller on the desktop
            • Close all the running programs
            • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
            • Otherwise just double-click on RogueKiller.exe
            • Pre-scan will start. Let it finish.
            • Click on SCAN button.
            • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
            • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

            I downloaded and ran Rogue Killer. Report included below.

            Edit 1: Typo correction.


            # AdwCleaner v2.002 - Logfile created 09/17/2012 at 13:38:51
            # Updated 16/09/2012 by Xplode
            # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
            # User : Removed - Removed
            # Boot Mode : Normal
            # Running from : C:\Users\Removed\Documents\adwcleaner.exe
            # Option [Delete]


            ***** [Services] *****


            ***** [Files / Folders] *****









            # AdwCleaner v2.002 - Logfile created 09/17/2012 at 14:00:36
            # Updated 16/09/2012 by Xplode
            # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
            # User : Removed - Removed
            # Boot Mode : Normal
            # Running from : C:\Users\Removed\Documents\adwcleaner.exe
            # Option [Delete]


            ***** [Services] *****


            ***** [Files / Folders] *****

            Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
            Deleted on reboot : C:\ProgramData\AVG Secure Search
            File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
            Folder Deleted : C:\Users\Removed\AppData\Local\AVG Secure Search
            Folder Deleted : C:\Users\Removed\AppData\LocalLow\AVG Secure Search
            Folder Deleted : C:\Users\Removed\AppData\LocalLow\boost_interprocess

            ***** [Registry] *****

            Key Deleted : HKCU\Software\AVG Secure Search
            Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
            Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
            Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
            Key Deleted : HKLM\Software\AVG Secure Search
            Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
            Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
            Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
            Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
            Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
            Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
            Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
            Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
            Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
            Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
            Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
            Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
            Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
            Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
            Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
            Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
            Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
            Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
            Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
            Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
            Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
            Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
            Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
            Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
            Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
            Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

            ***** [Internet Browsers] *****

            -\\ Internet Explorer v9.0.8112.16421

            Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
            Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
            Restored : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
            Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
            Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
            Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
            Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

            -\\ Mozilla Firefox v14.0.1 (en-GB)

            Profile name : default
            File : C:\Users\Removed\AppData\Roaming\Mozilla\Firefox\Profiles\rda0e265.default\prefs.js

            Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\12.2.5.32");
            Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
            Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");

            -\\ Google Chrome v [Unable to get version]

            File : C:\Users\Removed\AppData\Local\Google\Chrome\User Data\Default\Preferences

            [OK] File is clean.

            -\\ Opera v12.2.1578.0

            File : C:\Users\Removed\AppData\Roaming\Opera\Opera\operaprefs.ini

            [OK] File is clean.

            *************************

            AdwCleaner[R1].txt - [6359 octets] - [16/09/2012 21:56:47]
            AdwCleaner[S1].txt - [384 octets] - [17/09/2012 13:38:51]
            AdwCleaner[R2].txt - [6501 octets] - [17/09/2012 14:00:03]
            AdwCleaner[S2].txt - [7030 octets] - [17/09/2012 14:00:36]

            ########## EOF - C:\AdwCleaner[S2].txt - [7090 octets] ##########







            aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
            Run date: 2012-09-17 14:35:40
            -----------------------------
            14:35:40.139    OS Version: Windows x64 6.1.7601 Service Pack 1
            14:35:40.139    Number of processors: 2 586 0x602
            14:35:40.140    ComputerName: Removed  UserName:
            14:35:46.959    Initialize success
            14:37:39.623    AVAST engine defs: 12091400
            14:40:18.858    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
            14:40:18.863    Disk 0 Vendor: ST9500420AS 0006HPM1 Size: 476940MB BusType: 11
            14:40:18.900    Disk 0 MBR read successfully
            14:40:18.905    Disk 0 MBR scan
            14:40:18.916    Disk 0 unknown MBR code
            14:40:18.939    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
            14:40:18.951    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       462737 MB offset 409600
            14:40:18.983    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        13899 MB offset 948094976
            14:40:19.000    Disk 0 Partition 4 00     0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
            14:40:19.051    Disk 0 scanning C:\Windows\system32\drivers
            14:40:30.887    Service scanning
            14:41:02.990    Modules scanning
            14:41:03.011    Disk 0 trace - called modules:
            14:41:03.364    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
            14:41:03.376    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004666060]
            14:41:03.386    3 CLASSPNP.SYS[fffff8800105d43f] -> nt!IofCallDriver -> [0xfffffa8004665890]
            14:41:03.392    5 hpdskflt.sys[fffff88002383189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800452a060]
            14:41:05.061    AVAST engine scan C:\Windows
            14:41:09.147    AVAST engine scan C:\Windows\system32
            14:46:15.758    AVAST engine scan C:\Windows\system32\drivers
            14:46:33.039    AVAST engine scan C:\Users\Removed
            14:53:21.743    AVAST engine scan C:\ProgramData
            14:54:21.910    Scan finished successfully
            14:55:45.656    Disk 0 MBR has been saved successfully to "C:\Users\Removed\Desktop\MBR.dat"
            14:55:45.661    The log file has been saved successfully to "C:\Users\Removed\Desktop\aswMBR.txt"









            RogueKiller V8.0.3 [09/13/2012] by Tigzy
            mail: tigzyRK<at>gmail<dot>com
            Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
            Blog: http://tigzyrk.blogspot.com

            Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
            Started in : Normal mode
            User : Removed [Admin rights]
            Mode : Scan -- Date : 09/17/2012 15:02:42

            ¤¤¤ Bad processes : 0 ¤¤¤

            ¤¤¤ Registry Entries : 8 ¤¤¤
            [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
            [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
            [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
            [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
            [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
            [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
            [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
            [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

            ¤¤¤ Particular Files / Folders: ¤¤¤

            ¤¤¤ Driver : [NOT LOADED] ¤¤¤

            ¤¤¤ Infection :  ¤¤¤

            ¤¤¤ HOSTS File: ¤¤¤
            --> C:\Windows\system32\drivers\etc\hosts

            127.0.0.1       localhost


            ¤¤¤ MBR Check: ¤¤¤

            +++++ PhysicalDrive0: ST9500420AS ATA Device +++++
            --- User ---
            [MBR] 4d822fb75cdf67da02dbdffb9b10b1f1
            [BSP] 918612b482af7efa21b604febea66b0e : Windows Vista/7 MBR Code
            Partition table:
            0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
            1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 462737 Mo
            2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 948094976 | Size: 13899 Mo
            3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 976560128 | Size: 103 Mo
            User = LL1 ... OK!
            User = LL2 ... OK!

            Finished : << RKreport[1].txt >>
            RKreport[1].txt
            « Last Edit: September 17, 2012, 09:02:54 AM by Sirim »

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Suspected Malware Cause of Multiple DLL Errors.
            « Reply #7 on: September 17, 2012, 04:18:33 PM »
            To Run the SFC /SCANNOW Command in Windows 7
            1. Open an elevated command prompt.

            2. To Scan and Repair System Files
            NOTE: Scans the integrity of all protected system files and repairs the system files if needed.
            A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below)
            NOTE: This may take some time to finish.



            B) Go to step 4.

            3. To Only Verify if the System Files are Corrupted
            NOTE: Scans and only verifies the integrity of all proteced system files only.
            A) In the elevated command prompt, type sfc /verifyonly and press Enter.

            4. When the scan is complete, hopefully you will see all is ok like the screenshot below.
            NOTE: If not, then you can attempt to run a System Restore using a restore point dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work.



            5. When done, close the elevated command prompt.
            *********************************************************
            We need to fix the Master Boot Record using aswMBR now.

            • Double click aswMBR.exe to run it like before
            • Once the scan finishes click FixMBR to remove the infection as illustrated below


            • Once the scan finishes click Save log to save the log to your Desktop



            • Copy and paste the contents of aswMBR.txt back here for review
            .
            ***************************************************
            Download Combofix from any of the links below, and save it to your DESKTOP

            Link 1
            Link 2
            Link 3

            To prevent your anti-virus application interfering with  ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
            • Close any open windows and double click ComboFix.exe to run it.

              You will see the following image:


            Click I Agree to start the program.

            ComboFix will then extract the necessary files and you will see this:



            As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to  have this pre-installed on your machine before doing any malware  removal. This will not occur in Windows Vista and 7

            It will allow you to boot up into a special recovery/repair  mode that will allow us to more easily help you should your computer  have a problem after an attempted removal of malware.

            If you did not have it installed, you will see the prompt below. Choose YES.



            Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

            **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



            Click on Yes, to continue scanning for malware.

            When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

            Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

            Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
            Windows 8 and Windows 10 dual boot with two SSD's

            Sirim

              Topic Starter


              Rookie

              Thanked: 2
              • Experience: Familiar
              • OS: Windows 7
              Re: Suspected Malware Cause of Multiple DLL Errors.
              « Reply #8 on: September 17, 2012, 07:29:24 PM »
              Thanks again for your continued help.

              I ran sfc /scannow for a second time. The new log is included below. Briefly looking over them, the only observable difference appears to have been the date and time.

              I then ran aswMBR, first scanning for a second time and then fixing. The logs are included below.

              Finally, I ran combofix, while my antivirus software was temporarily disabled. The log is included below.








              2012-09-18 00:06:42, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:06:42, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:06:45, Info                  CSI    0000000c [SR] Verify complete
              2012-09-18 00:06:45, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:06:45, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
              2012-09-18 00:06:47, Info                  CSI    00000010 [SR] Verify complete
              2012-09-18 00:06:48, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:06:48, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:06:50, Info                  CSI    00000014 [SR] Verify complete
              2012-09-18 00:06:50, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:06:50, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:06:53, Info                  CSI    00000018 [SR] Verify complete
              2012-09-18 00:06:54, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:06:54, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:06:56, Info                  CSI    0000001c [SR] Verify complete
              2012-09-18 00:06:57, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:06:57, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
              2012-09-18 00:06:59, Info                  CSI    00000020 [SR] Verify complete
              2012-09-18 00:07:00, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:00, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:03, Info                  CSI    00000024 [SR] Verify complete
              2012-09-18 00:07:03, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:03, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:06, Info                  CSI    00000028 [SR] Verify complete
              2012-09-18 00:07:06, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:06, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:08, Info                  CSI    0000002c [SR] Verify complete
              2012-09-18 00:07:08, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:08, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:09, Info                  CSI    00000030 [SR] Cannot repair member file [l:22{11}]"sysmain.sdb" of Microsoft-Windows-Application-Experience-Mitigations-C1, Version = 6.1.7601.17571, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:07:11, Info                  CSI    00000032 [SR] Cannot repair member file [l:22{11}]"sysmain.sdb" of Microsoft-Windows-Application-Experience-Mitigations-C1, Version = 6.1.7601.17571, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:07:11, Info                  CSI    00000033 [SR] This component was referenced by [l:154{77}]"Package_2_for_KB2492386~31bf3856ad364e35~amd64~~6.1.1.0.2492386-6_neutral_GDR"
              2012-09-18 00:07:11, Info                  CSI    00000036 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\apppatch\apppatch64"\[l:22{11}]"sysmain.sdb"; source file in store is also corrupted
              2012-09-18 00:07:11, Info                  CSI    00000038 [SR] Verify complete
              2012-09-18 00:07:12, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:12, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:18, Info                  CSI    0000003d [SR] Verify complete
              2012-09-18 00:07:18, Info                  CSI    0000003e [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:18, Info                  CSI    0000003f [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:23, Info                  CSI    00000044 [SR] Verify complete
              2012-09-18 00:07:23, Info                  CSI    00000045 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:23, Info                  CSI    00000046 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:27, Info                  CSI    00000049 [SR] Verify complete
              2012-09-18 00:07:28, Info                  CSI    0000004a [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:28, Info                  CSI    0000004b [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:33, Info                  CSI    0000004d [SR] Verify complete
              2012-09-18 00:07:33, Info                  CSI    0000004e [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:33, Info                  CSI    0000004f [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:41, Info                  CSI    00000071 [SR] Verify complete
              2012-09-18 00:07:41, Info                  CSI    00000072 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:41, Info                  CSI    00000073 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:44, Info                  CSI    00000075 [SR] Cannot repair member file [l:14{7}]"dps.dll" of Microsoft-Windows-DiagnosticInfrastructure-Server, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:07:46, Info                  CSI    0000007a [SR] Cannot repair member file [l:14{7}]"dps.dll" of Microsoft-Windows-DiagnosticInfrastructure-Server, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:07:46, Info                  CSI    0000007b [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:07:46, Info                  CSI    0000007e [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:14{7}]"dps.dll"; source file in store is also corrupted
              2012-09-18 00:07:46, Info                  CSI    00000080 [SR] Verify complete
              2012-09-18 00:07:46, Info                  CSI    00000081 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:46, Info                  CSI    00000082 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:50, Info                  CSI    00000084 [SR] Verify complete
              2012-09-18 00:07:51, Info                  CSI    00000085 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:51, Info                  CSI    00000086 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:07:56, Info                  CSI    00000088 [SR] Verify complete
              2012-09-18 00:07:56, Info                  CSI    00000089 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:07:56, Info                  CSI    0000008a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:02, Info                  CSI    0000008c [SR] Verify complete
              2012-09-18 00:08:02, Info                  CSI    0000008d [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:02, Info                  CSI    0000008e [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:09, Info                  CSI    00000090 [SR] Verify complete
              2012-09-18 00:08:09, Info                  CSI    00000091 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:09, Info                  CSI    00000092 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:18, Info                  CSI    000000b5 [SR] Verify complete
              2012-09-18 00:08:18, Info                  CSI    000000b6 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:18, Info                  CSI    000000b7 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:25, Info                  CSI    000000b9 [SR] Verify complete
              2012-09-18 00:08:25, Info                  CSI    000000ba [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:25, Info                  CSI    000000bb [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:38, Info                  CSI    000000bd [SR] Verify complete
              2012-09-18 00:08:39, Info                  CSI    000000be [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:39, Info                  CSI    000000bf [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:46, Info                  CSI    000000c3 [SR] Verify complete
              2012-09-18 00:08:47, Info                  CSI    000000c4 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:47, Info                  CSI    000000c5 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:48, Info                  CSI    000000c7 [SR] Verify complete
              2012-09-18 00:08:48, Info                  CSI    000000c8 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:48, Info                  CSI    000000c9 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:49, Info                  CSI    000000cb [SR] Verify complete
              2012-09-18 00:08:50, Info                  CSI    000000cc [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:50, Info                  CSI    000000cd [SR] Beginning Verify and Repair transaction
              2012-09-18 00:08:56, Info                  CSI    000000d4 [SR] Verify complete
              2012-09-18 00:08:56, Info                  CSI    000000d5 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:08:56, Info                  CSI    000000d6 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:02, Info                  CSI    000000e4 [SR] Verify complete
              2012-09-18 00:09:02, Info                  CSI    000000e5 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:02, Info                  CSI    000000e6 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:04, Info                  CSI    000000e8 [SR] Verify complete
              2012-09-18 00:09:04, Info                  CSI    000000e9 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:04, Info                  CSI    000000ea [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:08, Info                  CSI    000000ec [SR] Verify complete
              2012-09-18 00:09:08, Info                  CSI    000000ed [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:08, Info                  CSI    000000ee [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:12, Info                  CSI    000000f0 [SR] Verify complete
              2012-09-18 00:09:12, Info                  CSI    000000f1 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:12, Info                  CSI    000000f2 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:19, Info                  CSI    000000f5 [SR] Verify complete
              2012-09-18 00:09:20, Info                  CSI    000000f6 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:20, Info                  CSI    000000f7 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:25, Info                  CSI    000000fa [SR] Verify complete
              2012-09-18 00:09:25, Info                  CSI    000000fb [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:25, Info                  CSI    000000fc [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:27, Info                  CSI    000000fe [SR] Verify complete
              2012-09-18 00:09:27, Info                  CSI    000000ff [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:27, Info                  CSI    00000100 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:30, Info                  CSI    00000102 [SR] Verify complete
              2012-09-18 00:09:30, Info                  CSI    00000103 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:30, Info                  CSI    00000104 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:34, Info                  CSI    00000106 [SR] Cannot repair member file [l:22{11}]"odbcint.dll" of Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-DriverManager-Rll, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:09:37, Info                  CSI    00000108 [SR] Cannot repair member file [l:22{11}]"odbcint.dll" of Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-DriverManager-Rll, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:09:37, Info                  CSI    00000109 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:09:37, Info                  CSI    0000010c [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"odbcint.dll"; source file in store is also corrupted
              2012-09-18 00:09:39, Info                  CSI    0000010e [SR] Verify complete
              2012-09-18 00:09:40, Info                  CSI    0000010f [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:40, Info                  CSI    00000110 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:44, Info                  CSI    00000112 [SR] Verify complete
              2012-09-18 00:09:44, Info                  CSI    00000113 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:44, Info                  CSI    00000114 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:09:47, Info                  CSI    00000116 [SR] Cannot repair member file [l:20{10}]"mapi32.dll" of Microsoft-Windows-Mapi, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:09:51, Info                  CSI    00000118 [SR] Cannot repair member file [l:20{10}]"mapi32.dll" of Microsoft-Windows-Mapi, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:09:51, Info                  CSI    00000119 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:09:51, Info                  CSI    0000011c [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:20{10}]"mapi32.dll"; source file in store is also corrupted
              2012-09-18 00:09:54, Info                  CSI    00000121 [SR] Verify complete
              2012-09-18 00:09:54, Info                  CSI    00000122 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:09:54, Info                  CSI    00000123 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:02, Info                  CSI    00000138 [SR] Verify complete
              2012-09-18 00:10:02, Info                  CSI    00000139 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:02, Info                  CSI    0000013a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:08, Info                  CSI    0000013c [SR] Verify complete
              2012-09-18 00:10:08, Info                  CSI    0000013d [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:08, Info                  CSI    0000013e [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:10, Info                  CSI    00000140 [SR] Cannot repair member file [l:30{15}]"NlsData0000.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:10:19, Info                  CSI    00000142 [SR] Cannot repair member file [l:30{15}]"NlsData0000.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:10:19, Info                  CSI    00000143 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:10:23, Info                  CSI    00000146 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:30{15}]"NlsData0000.dll"; source file in store is also corrupted
              2012-09-18 00:10:26, Info                  CSI    00000148 [SR] Verify complete
              2012-09-18 00:10:27, Info                  CSI    00000149 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:27, Info                  CSI    0000014a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:36, Info                  CSI    0000014d [SR] Verify complete
              2012-09-18 00:10:36, Info                  CSI    0000014e [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:36, Info                  CSI    0000014f [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:42, Info                  CSI    00000151 [SR] Cannot repair member file [l:22{11}]"ntprint.dll" of Microsoft-Windows-Printing-ClassInstallerAndPrintUI-Ntprint, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:10:44, Info                  CSI    00000153 [SR] Cannot repair member file [l:22{11}]"ntprint.dll" of Microsoft-Windows-Printing-ClassInstallerAndPrintUI-Ntprint, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:10:44, Info                  CSI    00000154 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:10:44, Info                  CSI    00000157 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"ntprint.dll"; source file in store is also corrupted
              2012-09-18 00:10:44, Info                  CSI    00000159 [SR] Verify complete
              2012-09-18 00:10:44, Info                  CSI    0000015a [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:44, Info                  CSI    0000015b [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:50, Info                  CSI    0000015d [SR] Verify complete
              2012-09-18 00:10:51, Info                  CSI    0000015e [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:51, Info                  CSI    0000015f [SR] Beginning Verify and Repair transaction
              2012-09-18 00:10:56, Info                  CSI    00000161 [SR] Verify complete
              2012-09-18 00:10:56, Info                  CSI    00000162 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:10:56, Info                  CSI    00000163 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:01, Info                  CSI    00000167 [SR] Verify complete
              2012-09-18 00:11:01, Info                  CSI    00000168 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:01, Info                  CSI    00000169 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:13, Info                  CSI    0000016b [SR] Verify complete
              2012-09-18 00:11:13, Info                  CSI    0000016c [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:13, Info                  CSI    0000016d [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:21, Info                  CSI    00000170 [SR] Verify complete
              2012-09-18 00:11:21, Info                  CSI    00000171 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:21, Info                  CSI    00000172 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:28, Info                  CSI    00000174 [SR] Verify complete
              2012-09-18 00:11:28, Info                  CSI    00000175 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:28, Info                  CSI    00000176 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:33, Info                  CSI    00000179 [SR] Verify complete
              2012-09-18 00:11:34, Info                  CSI    0000017a [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:34, Info                  CSI    0000017b [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:44, Info                  CSI    0000017e [SR] Verify complete
              2012-09-18 00:11:44, Info                  CSI    0000017f [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:44, Info                  CSI    00000180 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:51, Info                  CSI    00000182 [SR] Verify complete
              2012-09-18 00:11:52, Info                  CSI    00000183 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:52, Info                  CSI    00000184 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:11:57, Info                  CSI    00000186 [SR] Verify complete
              2012-09-18 00:11:57, Info                  CSI    00000187 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:11:57, Info                  CSI    00000188 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:02, Info                  CSI    0000018a [SR] Verify complete
              2012-09-18 00:12:03, Info                  CSI    0000018b [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:03, Info                  CSI    0000018c [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:10, Info                  CSI    0000018f [SR] Verify complete
              2012-09-18 00:12:10, Info                  CSI    00000190 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:10, Info                  CSI    00000191 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:15, Info                  CSI    00000193 [SR] Verify complete
              2012-09-18 00:12:15, Info                  CSI    00000194 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:15, Info                  CSI    00000195 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:22, Info                  CSI    00000198 [SR] Verify complete
              2012-09-18 00:12:22, Info                  CSI    00000199 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:22, Info                  CSI    0000019a [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:29, Info                  CSI    0000019d [SR] Verify complete
              2012-09-18 00:12:29, Info                  CSI    0000019e [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:29, Info                  CSI    0000019f [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:35, Info                  CSI    000001a2 [SR] Verify complete
              2012-09-18 00:12:35, Info                  CSI    000001a3 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:35, Info                  CSI    000001a4 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:44, Info                  CSI    000001a7 [SR] Verify complete
              2012-09-18 00:12:44, Info                  CSI    000001a8 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:44, Info                  CSI    000001a9 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:52, Info                  CSI    000001ab [SR] Verify complete
              2012-09-18 00:12:53, Info                  CSI    000001ac [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:53, Info                  CSI    000001ad [SR] Beginning Verify and Repair transaction
              2012-09-18 00:12:56, Info                  CSI    000001af [SR] Verify complete
              2012-09-18 00:12:56, Info                  CSI    000001b0 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:12:56, Info                  CSI    000001b1 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:00, Info                  CSI    000001b3 [SR] Verify complete
              2012-09-18 00:13:00, Info                  CSI    000001b4 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:00, Info                  CSI    000001b5 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:03, Info                  CSI    000001b7 [SR] Verify complete
              2012-09-18 00:13:04, Info                  CSI    000001b8 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:04, Info                  CSI    000001b9 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:09, Info                  CSI    000001bb [SR] Verify complete
              2012-09-18 00:13:09, Info                  CSI    000001bc [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:09, Info                  CSI    000001bd [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:18, Info                  CSI    000001bf [SR] Verify complete
              2012-09-18 00:13:18, Info                  CSI    000001c0 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:18, Info                  CSI    000001c1 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:22, Info                  CSI    000001c3 [SR] Verify complete
              2012-09-18 00:13:22, Info                  CSI    000001c4 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:22, Info                  CSI    000001c5 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:28, Info                  CSI    000001c7 [SR] Verify complete
              2012-09-18 00:13:28, Info                  CSI    000001c8 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:28, Info                  CSI    000001c9 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:39, Info                  CSI    000001cb [SR] Verify complete
              2012-09-18 00:13:40, Info                  CSI    000001cc [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:40, Info                  CSI    000001cd [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:50, Info                  CSI    000001cf [SR] Verify complete
              2012-09-18 00:13:50, Info                  CSI    000001d0 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:50, Info                  CSI    000001d1 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:55, Info                  CSI    000001d3 [SR] Verify complete
              2012-09-18 00:13:55, Info                  CSI    000001d4 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:55, Info                  CSI    000001d5 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:13:57, Info                  CSI    000001d7 [SR] Verify complete
              2012-09-18 00:13:57, Info                  CSI    000001d8 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:13:57, Info                  CSI    000001d9 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:01, Info                  CSI    000001db [SR] Verify complete
              2012-09-18 00:14:01, Info                  CSI    000001dc [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:01, Info                  CSI    000001dd [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:05, Info                  CSI    000001df [SR] Verify complete
              2012-09-18 00:14:05, Info                  CSI    000001e0 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:05, Info                  CSI    000001e1 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:12, Info                  CSI    000001e9 [SR] Verify complete
              2012-09-18 00:14:12, Info                  CSI    000001ea [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:12, Info                  CSI    000001eb [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:19, Info                  CSI    000001ed [SR] Verify complete
              2012-09-18 00:14:19, Info                  CSI    000001ee [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:19, Info                  CSI    000001ef [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:26, Info                  CSI    000001f1 [SR] Verify complete
              2012-09-18 00:14:26, Info                  CSI    000001f2 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:26, Info                  CSI    000001f3 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:29, Info                  CSI    000001f5 [SR] Verify complete
              2012-09-18 00:14:29, Info                  CSI    000001f6 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:29, Info                  CSI    000001f7 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:35, Info                  CSI    000001f9 [SR] Verify complete
              2012-09-18 00:14:35, Info                  CSI    000001fa [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:35, Info                  CSI    000001fb [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:43, Info                  CSI    000001fe [SR] Verify complete
              2012-09-18 00:14:43, Info                  CSI    000001ff [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:43, Info                  CSI    00000200 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:47, Info                  CSI    00000202 [SR] Verify complete
              2012-09-18 00:14:47, Info                  CSI    00000203 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:47, Info                  CSI    00000204 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:49, Info                  CSI    00000206 [SR] Verify complete
              2012-09-18 00:14:49, Info                  CSI    00000207 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:49, Info                  CSI    00000208 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:14:58, Info                  CSI    0000020b [SR] Verify complete
              2012-09-18 00:14:58, Info                  CSI    0000020c [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:14:58, Info                  CSI    0000020d [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:09, Info                  CSI    00000211 [SR] Verify complete
              2012-09-18 00:15:10, Info                  CSI    00000212 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:10, Info                  CSI    00000213 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:11, Info                  CSI    00000215 [SR] Cannot repair member file [l:22{11}]"pnrpnsp.dll" of Microsoft-Windows-PeerToPeerPNRP, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:15:16, Info                  CSI    00000217 [SR] Cannot repair member file [l:22{11}]"pnrpnsp.dll" of Microsoft-Windows-PeerToPeerPNRP, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:15:16, Info                  CSI    00000218 [SR] This component was referenced by [l:168{84}]"Microsoft-Windows-PeerToPeer-Full-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.P2P"
              2012-09-18 00:15:16, Info                  CSI    0000021b [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:22{11}]"pnrpnsp.dll"; source file in store is also corrupted
              2012-09-18 00:15:17, Info                  CSI    00000220 [SR] Verify complete
              2012-09-18 00:15:17, Info                  CSI    00000221 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:17, Info                  CSI    00000222 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:26, Info                  CSI    0000022d [SR] Verify complete
              2012-09-18 00:15:26, Info                  CSI    0000022e [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:26, Info                  CSI    0000022f [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:36, Info                  CSI    00000236 [SR] Verify complete
              2012-09-18 00:15:36, Info                  CSI    00000237 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:36, Info                  CSI    00000238 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:41, Info                  CSI    0000023a [SR] Verify complete
              2012-09-18 00:15:42, Info                  CSI    0000023b [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:42, Info                  CSI    0000023c [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:46, Info                  CSI    00000240 [SR] Verify complete
              2012-09-18 00:15:46, Info                  CSI    00000241 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:46, Info                  CSI    00000242 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:52, Info                  CSI    00000244 [SR] Verify complete
              2012-09-18 00:15:52, Info                  CSI    00000245 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:52, Info                  CSI    00000246 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:15:59, Info                  CSI    0000026b [SR] Verify complete
              2012-09-18 00:15:59, Info                  CSI    0000026c [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:15:59, Info                  CSI    0000026d [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:04, Info                  CSI    0000026f [SR] Verify complete
              2012-09-18 00:16:04, Info                  CSI    00000270 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:04, Info                  CSI    00000271 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:05, Info                  CSI    00000273 [SR] Cannot repair member file [l:18{9}]"dxva2.dll" of Microsoft-Windows-DirectXVideoAcceleration, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:16:09, Info                  CSI    00000275 [SR] Cannot repair member file [l:18{9}]"dxva2.dll" of Microsoft-Windows-DirectXVideoAcceleration, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:16:09, Info                  CSI    00000276 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:16:09, Info                  CSI    00000279 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:18{9}]"dxva2.dll"; source file in store is also corrupted
              2012-09-18 00:16:10, Info                  CSI    0000027b [SR] Verify complete
              2012-09-18 00:16:10, Info                  CSI    0000027c [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:10, Info                  CSI    0000027d [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:14, Info                  CSI    0000027f [SR] Verify complete
              2012-09-18 00:16:14, Info                  CSI    00000280 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:14, Info                  CSI    00000281 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:20, Info                  CSI    0000028f [SR] Verify complete
              2012-09-18 00:16:20, Info                  CSI    00000290 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:20, Info                  CSI    00000291 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:29, Info                  CSI    00000296 [SR] Verify complete
              2012-09-18 00:16:29, Info                  CSI    00000297 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:29, Info                  CSI    00000298 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:36, Info                  CSI    000002a3 [SR] Verify complete
              2012-09-18 00:16:36, Info                  CSI    000002a4 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:36, Info                  CSI    000002a5 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:38, Info                  CSI    000002a7 [SR] Verify complete
              2012-09-18 00:16:39, Info                  CSI    000002a8 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:39, Info                  CSI    000002a9 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:46, Info                  CSI    000002ac [SR] Verify complete
              2012-09-18 00:16:46, Info                  CSI    000002ad [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:46, Info                  CSI    000002ae [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:49, Info                  CSI    000002b0 [SR] Verify complete
              2012-09-18 00:16:49, Info                  CSI    000002b1 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:49, Info                  CSI    000002b2 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:16:55, Info                  CSI    000002b4 [SR] Verify complete
              2012-09-18 00:16:55, Info                  CSI    000002b5 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:16:55, Info                  CSI    000002b6 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:17:01, Info                  CSI    000002b8 [SR] Verify complete
              2012-09-18 00:17:01, Info                  CSI    000002b9 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:17:01, Info                  CSI    000002ba [SR] Beginning Verify and Repair transaction
              2012-09-18 00:17:06, Info                  CSI    000002bc [SR] Verify complete
              2012-09-18 00:17:06, Info                  CSI    000002bd [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:17:06, Info                  CSI    000002be [SR] Beginning Verify and Repair transaction
              2012-09-18 00:17:10, Info                  CSI    000002c0 [SR] Cannot repair member file [l:22{11}]"MP3DMOD.DLL" of Microsoft-Windows-MP3DMOD, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:17:15, Info                  CSI    000002d7 [SR] Cannot repair member file [l:22{11}]"MP3DMOD.DLL" of Microsoft-Windows-MP3DMOD, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:17:15, Info                  CSI    000002d8 [SR] This component was referenced by [l:178{89}]"Microsoft-Media-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.MediaFoundation"
              2012-09-18 00:17:15, Info                  CSI    000002db [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:22{11}]"MP3DMOD.DLL"; source file in store is also corrupted
              2012-09-18 00:17:15, Info                  CSI    000002e0 [SR] Verify complete
              2012-09-18 00:17:16, Info                  CSI    000002e1 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:17:16, Info                  CSI    000002e2 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:17:23, Info                  CSI    000002e4 [SR] Verify complete
              2012-09-18 00:17:23, Info                  CSI    000002e5 [SR] Verifying 100 (0x0000000000000064) components
              2012-09-18 00:17:23, Info                  CSI    000002e6 [SR] Beginning Verify and Repair transaction
              2012-09-18 00:17:32, Info                  CSI    000002e8 [SR] Cannot repair member file [l:24{12}]"asycfilt.dll" of Microsoft-Windows-OLE-Automation-AsyncFilters, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:17:33, Info                  CSI    000002ea [SR] Cannot repair member file [l:24{12}]"asycfilt.dll" of Microsoft-Windows-OLE-Automation-AsyncFilters, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
              2012-09-18 00:17:33, Info                  CSI    000002eb [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
              2012-09-18 00:17:33, Info                  CSI    000002ee [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"asycfilt.dll"; source file in store is also corrupted
              2012-09-18 00:17

              Sirim

                Topic Starter


                Rookie

                Thanked: 2
                • Experience: Familiar
                • OS: Windows 7
                Re: Suspected Malware Cause of Multiple DLL Errors.
                « Reply #9 on: September 17, 2012, 07:32:09 PM »
                [continued]

                2012-09-18 00:17:33, Info                  CSI    000002ee [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"asycfilt.dll"; source file in store is also corrupted
                2012-09-18 00:17:51, Info                  CSI    000002f0 [SR] Verify complete
                2012-09-18 00:17:51, Info                  CSI    000002f1 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:17:51, Info                  CSI    000002f2 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:17:56, Info                  CSI    000002f4 [SR] Verify complete
                2012-09-18 00:17:56, Info                  CSI    000002f5 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:17:56, Info                  CSI    000002f6 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:00, Info                  CSI    000002fa [SR] Verify complete
                2012-09-18 00:18:00, Info                  CSI    000002fb [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:00, Info                  CSI    000002fc [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:05, Info                  CSI    000002fe [SR] Verify complete
                2012-09-18 00:18:05, Info                  CSI    000002ff [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:05, Info                  CSI    00000300 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:11, Info                  CSI    00000302 [SR] Verify complete
                2012-09-18 00:18:11, Info                  CSI    00000303 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:11, Info                  CSI    00000304 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:16, Info                  CSI    00000306 [SR] Verify complete
                2012-09-18 00:18:16, Info                  CSI    00000307 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:16, Info                  CSI    00000308 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:21, Info                  CSI    0000030b [SR] Verify complete
                2012-09-18 00:18:21, Info                  CSI    0000030c [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:21, Info                  CSI    0000030d [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:25, Info                  CSI    0000030f [SR] Verify complete
                2012-09-18 00:18:26, Info                  CSI    00000310 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:26, Info                  CSI    00000311 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:31, Info                  CSI    00000313 [SR] Verify complete
                2012-09-18 00:18:32, Info                  CSI    00000314 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:32, Info                  CSI    00000315 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:37, Info                  CSI    00000317 [SR] Verify complete
                2012-09-18 00:18:38, Info                  CSI    00000318 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:38, Info                  CSI    00000319 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:46, Info                  CSI    0000031c [SR] Verify complete
                2012-09-18 00:18:46, Info                  CSI    0000031d [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:46, Info                  CSI    0000031e [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:51, Info                  CSI    00000320 [SR] Verify complete
                2012-09-18 00:18:51, Info                  CSI    00000321 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:51, Info                  CSI    00000322 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:18:55, Info                  CSI    00000324 [SR] Verify complete
                2012-09-18 00:18:56, Info                  CSI    00000325 [SR] Verifying 100 (0x0000000000000064) components
                2012-09-18 00:18:56, Info                  CSI    00000326 [SR] Beginning Verify and Repair transaction
                2012-09-18 00:19:01, Info                  CSI    00000328 [SR] Verify complete
                2012-09-18 00:19:01, Info                  CSI    00000329 [SR] Verifying 90 (0x000000000000005a) components
                2012-09-18 00:19:01, Info                  CSI    0000032a [SR] Beginning Verify and Repair transaction
                2012-09-18 00:19:06, Info                  CSI    0000032c [SR] Verify complete
                2012-09-18 00:19:06, Info                  CSI    0000032d [SR] Repairing 10 (0x000000000000000a) components
                2012-09-18 00:19:06, Info                  CSI    0000032e [SR] Beginning Verify and Repair transaction
                2012-09-18 00:19:06, Info                  CSI    00000330 [SR] Cannot repair member file [l:22{11}]"sysmain.sdb" of Microsoft-Windows-Application-Experience-Mitigations-C1, Version = 6.1.7601.17571, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:06, Info                  CSI    00000332 [SR] Cannot repair member file [l:14{7}]"dps.dll" of Microsoft-Windows-DiagnosticInfrastructure-Server, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:06, Info                  CSI    00000334 [SR] Cannot repair member file [l:22{11}]"odbcint.dll" of Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-DriverManager-Rll, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:06, Info                  CSI    00000336 [SR] Cannot repair member file [l:20{10}]"mapi32.dll" of Microsoft-Windows-Mapi, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:08, Info                  CSI    00000338 [SR] Cannot repair member file [l:30{15}]"NlsData0000.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    0000033a [SR] Cannot repair member file [l:22{11}]"ntprint.dll" of Microsoft-Windows-Printing-ClassInstallerAndPrintUI-Ntprint, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    0000033c [SR] Cannot repair member file [l:22{11}]"pnrpnsp.dll" of Microsoft-Windows-PeerToPeerPNRP, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    0000033e [SR] Cannot repair member file [l:18{9}]"dxva2.dll" of Microsoft-Windows-DirectXVideoAcceleration, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000340 [SR] Cannot repair member file [l:22{11}]"MP3DMOD.DLL" of Microsoft-Windows-MP3DMOD, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000342 [SR] Cannot repair member file [l:24{12}]"asycfilt.dll" of Microsoft-Windows-OLE-Automation-AsyncFilters, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000344 [SR] Cannot repair member file [l:22{11}]"odbcint.dll" of Microsoft-Windows-Microsoft-Data-Access-Components-(MDAC)-ODBC-DriverManager-Rll, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000345 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:13, Info                  CSI    00000348 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"odbcint.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    0000034a [SR] Cannot repair member file [l:22{11}]"ntprint.dll" of Microsoft-Windows-Printing-ClassInstallerAndPrintUI-Ntprint, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    0000034b [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:13, Info                  CSI    0000034e [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:22{11}]"ntprint.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    00000350 [SR] Cannot repair member file [l:22{11}]"pnrpnsp.dll" of Microsoft-Windows-PeerToPeerPNRP, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_IA32_ON_WIN64 (10), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000351 [SR] This component was referenced by [l:168{84}]"Microsoft-Windows-PeerToPeer-Full-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.P2P"
                2012-09-18 00:19:13, Info                  CSI    00000354 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:22{11}]"pnrpnsp.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    00000358 [SR] Cannot repair member file [l:18{9}]"dxva2.dll" of Microsoft-Windows-DirectXVideoAcceleration, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000359 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:13, Info                  CSI    0000035c [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:18{9}]"dxva2.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    0000035e [SR] Cannot repair member file [l:22{11}]"sysmain.sdb" of Microsoft-Windows-Application-Experience-Mitigations-C1, Version = 6.1.7601.17571, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    0000035f [SR] This component was referenced by [l:154{77}]"Package_2_for_KB2492386~31bf3856ad364e35~amd64~~6.1.1.0.2492386-6_neutral_GDR"
                2012-09-18 00:19:13, Info                  CSI    00000362 [SR] Could not reproject corrupted file [ml:520{260},l:68{34}]"\??\C:\Windows\apppatch\apppatch64"\[l:22{11}]"sysmain.sdb"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    00000364 [SR] Cannot repair member file [l:20{10}]"mapi32.dll" of Microsoft-Windows-Mapi, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000365 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:13, Info                  CSI    00000368 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:20{10}]"mapi32.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    0000036a [SR] Cannot repair member file [l:24{12}]"asycfilt.dll" of Microsoft-Windows-OLE-Automation-AsyncFilters, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    0000036b [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:13, Info                  CSI    0000036e [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:24{12}]"asycfilt.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    00000370 [SR] Cannot repair member file [l:14{7}]"dps.dll" of Microsoft-Windows-DiagnosticInfrastructure-Server, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000371 [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:13, Info                  CSI    00000374 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:14{7}]"dps.dll"; source file in store is also corrupted
                2012-09-18 00:19:13, Info                  CSI    00000376 [SR] Cannot repair member file [l:22{11}]"MP3DMOD.DLL" of Microsoft-Windows-MP3DMOD, Version = 6.1.7600.16385, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:13, Info                  CSI    00000377 [SR] This component was referenced by [l:178{89}]"Microsoft-Media-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.MediaFoundation"
                2012-09-18 00:19:13, Info                  CSI    0000037a [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\Windows\SysWOW64"\[l:22{11}]"MP3DMOD.DLL"; source file in store is also corrupted
                2012-09-18 00:19:14, Info                  CSI    0000037c [SR] Cannot repair member file [l:30{15}]"NlsData0000.dll" of Microsoft-Windows-NaturalLanguage6, Version = 6.1.7601.17514, pA = PROCESSOR_ARCHITECTURE_AMD64 (9), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35}, Type neutral, TypeName neutral, PublicKey neutral in the store, hash mismatch
                2012-09-18 00:19:14, Info                  CSI    0000037d [SR] This component was referenced by [l:202{101}]"Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.WindowsFoundationDelivery"
                2012-09-18 00:19:19, Info                  CSI    00000380 [SR] Could not reproject corrupted file [ml:520{260},l:46{23}]"\??\C:\Windows\System32"\[l:30{15}]"NlsData0000.dll"; source file in store is also corrupted
                2012-09-18 00:19:22, Info                  CSI    00000382 [SR] Repair complete
                2012-09-18 00:19:22, Info                  CSI    00000383 [SR] Committing transaction
                2012-09-18 00:19:22, Info                  CSI    00000387 [SR] Verify and Repair Transaction completed. All files and registry keys listed in this transaction  have been successfully repaired










                aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
                Run date: 2012-09-18 00:25:11
                -----------------------------
                00:25:11.195    OS Version: Windows x64 6.1.7601 Service Pack 1
                00:25:11.195    Number of processors: 2 586 0x602
                00:25:11.195    ComputerName: Removed  UserName:
                00:25:14.487    Initialize success
                00:26:35.909    AVAST engine defs: 12091400
                00:29:16.029    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
                00:29:16.029    Disk 0 Vendor: ST9500420AS 0006HPM1 Size: 476940MB BusType: 11
                00:29:16.059    Disk 0 MBR read successfully
                00:29:16.059    Disk 0 MBR scan
                00:29:16.069    Disk 0 unknown MBR code
                00:29:16.079    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
                00:29:16.099    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       462737 MB offset 409600
                00:29:16.139    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        13899 MB offset 948094976
                00:29:16.179    Disk 0 Partition 4 00     0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
                00:29:16.279    Disk 0 scanning C:\Windows\system32\drivers
                00:29:40.463    Service scanning
                00:30:11.537    Modules scanning
                00:30:11.567    Disk 0 trace - called modules:
                00:30:11.917    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
                00:30:11.937    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004666060]
                00:30:11.947    3 CLASSPNP.SYS[fffff8800105d43f] -> nt!IofCallDriver -> [0xfffffa8004665890]
                00:30:11.957    5 hpdskflt.sys[fffff88002383189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800452a060]
                00:30:17.897    AVAST engine scan C:\Windows
                00:30:53.863    AVAST engine scan C:\Windows\system32
                00:40:15.284    AVAST engine scan C:\Windows\system32\drivers
                00:42:08.934    AVAST engine scan C:\Users\Removed
                00:49:19.240    AVAST engine scan C:\ProgramData
                00:50:22.644    Scan finished successfully
                00:57:41.141    Disk 0 MBR has been saved successfully to "C:\Users\Removed\Desktop\MBR.dat"
                00:57:41.141    The log file has been saved successfully to "C:\Users\Removed\Desktop\aswMBR.txt"


                aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
                Run date: 2012-09-18 00:25:11
                -----------------------------
                00:25:11.195    OS Version: Windows x64 6.1.7601 Service Pack 1
                00:25:11.195    Number of processors: 2 586 0x602
                00:25:11.195    ComputerName: Removed  UserName:
                00:25:14.487    Initialize success
                00:26:35.909    AVAST engine defs: 12091400
                00:29:16.029    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
                00:29:16.029    Disk 0 Vendor: ST9500420AS 0006HPM1 Size: 476940MB BusType: 11
                00:29:16.059    Disk 0 MBR read successfully
                00:29:16.059    Disk 0 MBR scan
                00:29:16.069    Disk 0 unknown MBR code
                00:29:16.079    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          199 MB offset 2048
                00:29:16.099    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       462737 MB offset 409600
                00:29:16.139    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        13899 MB offset 948094976
                00:29:16.179    Disk 0 Partition 4 00     0C    FAT32 LBA MSDOS5.0      103 MB offset 976560128
                00:29:16.279    Disk 0 scanning C:\Windows\system32\drivers
                00:29:40.463    Service scanning
                00:30:11.537    Modules scanning
                00:30:11.567    Disk 0 trace - called modules:
                00:30:11.917    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
                00:30:11.937    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004666060]
                00:30:11.947    3 CLASSPNP.SYS[fffff8800105d43f] -> nt!IofCallDriver -> [0xfffffa8004665890]
                00:30:11.957    5 hpdskflt.sys[fffff88002383189] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800452a060]
                00:30:17.897    AVAST engine scan C:\Windows
                00:30:53.863    AVAST engine scan C:\Windows\system32
                00:40:15.284    AVAST engine scan C:\Windows\system32\drivers
                00:42:08.934    AVAST engine scan C:\Users\Removed
                00:49:19.240    AVAST engine scan C:\ProgramData
                00:50:22.644    Scan finished successfully
                00:57:41.141    Disk 0 MBR has been saved successfully to "C:\Users\Removed\Desktop\MBR.dat"
                00:57:41.141    The log file has been saved successfully to "C:\Users\Removed\Desktop\aswMBR.txt"
                00:58:00.585    Verifying
                00:58:10.605    Disk 0 Windows 601 MBR fixed successfully
                00:58:25.567    Disk 0 MBR has been saved successfully to "C:\Users\Removed\Desktop\MBR.dat"
                00:58:25.567    The log file has been saved successfully to "C:\Users\Removed\Desktop\aswMBR.txt"







                ComboFix 12-09-16.01 - Removed 18/09/2012   1:04.2.2 - x64
                Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.4092.1842 [GMT 1:00]
                Running from: c:\users\Removed\AppData\Local\Opera\Opera\temporary_downloads\ComboFix.exe
                AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
                SP: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
                SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                .
                .
                (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                c:\windows\SysWow64\SET6E5B.tmp
                c:\windows\SysWow64\SETB95F.tmp
                .
                .
                (((((((((((((((((((((((((   Files Created from 2012-08-18 to 2012-09-18  )))))))))))))))))))))))))))))))
                .
                .
                2012-09-18 00:10 . 2012-09-18 00:10   --------   d-----w-   c:\users\Default\AppData\Local\temp
                2012-09-17 14:18 . 2012-09-17 14:18   73696   ----a-w-   c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll
                2012-09-17 14:15 . 2012-09-17 14:15   --------   d-----w-   c:\programdata\McAfee
                2012-09-16 14:28 . 2012-09-16 14:28   --------   d-----w-   c:\users\Removed\AppData\Roaming\SUPERAntiSpyware.com
                2012-09-16 14:28 . 2012-09-16 14:28   --------   d-----w-   c:\program files\SUPERAntiSpyware
                2012-09-16 14:28 . 2012-09-16 14:28   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
                2012-09-16 14:22 . 2012-09-16 14:22   --------   d-----w-   c:\program files (x86)\Trend Micro
                2012-09-16 11:16 . 2012-09-16 11:16   --------   d-----w-   c:\users\Removed\AppData\Roaming\Malwarebytes
                2012-09-16 11:16 . 2012-09-16 11:16   --------   d-----w-   c:\programdata\Malwarebytes
                2012-09-16 11:16 . 2012-09-16 11:16   --------   d-----w-   c:\program files (x86)\Malwarebytes' Anti-Malware
                2012-09-16 11:16 . 2012-09-07 16:04   25928   ----a-w-   c:\windows\system32\drivers\mbam.sys
                2012-09-14 21:30 . 2012-09-14 21:30   --------   d-----w-   c:\program files (x86)\GameSpy Arcade
                2012-09-14 16:30 . 2012-09-14 16:30   --------   d-----w-   c:\program files (x86)\WildTangent Games
                2012-09-09 18:12 . 2012-09-09 18:12   --------   d-----w-   C:\Games
                2012-09-09 18:11 . 2012-09-09 18:13   --------   d-----w-   c:\program files\red alert 2
                2012-09-04 11:49 . 2012-09-04 11:49   31080   ----a-w-   c:\windows\system32\drivers\avgtpx64.sys
                2012-09-01 20:27 . 2012-09-01 20:27   --------   d-----w-   c:\programdata\Battle.net
                2012-08-27 12:24 . 2012-07-06 20:07   552960   ----a-w-   c:\windows\system32\drivers\bthport.sys
                .
                .
                .
                ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2012-09-15 01:30 . 2011-09-18 02:42   64462936   ----a-w-   c:\windows\system32\MRT.exe
                2012-09-14 22:00 . 2011-07-02 19:54   102400   ----a-w-   c:\windows\system32\drivers\dfsc.sys
                2012-09-14 22:00 . 2009-07-13 23:19   680448   ----a-w-   c:\windows\system32\adtschema.dll
                2012-09-13 17:44 . 2011-12-11 15:33   234536   ----a-w-   c:\windows\SysWow64\PnkBstrB.exe
                2012-09-13 17:44 . 2011-12-11 15:33   234536   ----a-w-   c:\windows\SysWow64\PnkBstrB.xtr
                2012-08-28 19:24 . 2012-08-15 17:32   477168   ----a-w-   c:\windows\SysWow64\npdeployJava1.dll
                2012-08-28 19:24 . 2011-07-08 07:20   473072   ----a-w-   c:\windows\SysWow64\deployJava1.dll
                2012-08-09 23:11 . 2012-08-09 23:11   30   ----a-w-   c:\windows\system32\tkkc.bat
                2012-07-18 18:15 . 2012-08-15 22:57   3148800   ----a-w-   c:\windows\system32\win32k.sys
                2012-07-04 22:16 . 2012-08-15 22:57   73216   ----a-w-   c:\windows\system32\netapi32.dll
                2012-07-04 22:13 . 2012-08-15 22:57   59392   ----a-w-   c:\windows\system32\browcli.dll
                2012-07-04 22:13 . 2012-08-15 22:57   136704   ----a-w-   c:\windows\system32\browser.dll
                2012-07-04 21:14 . 2012-08-15 22:57   41984   ----a-w-   c:\windows\SysWow64\browcli.dll
                .
                .
                (((((((((((((((((((((((((((((   SnapShot@2012-09-16_22.27.17   )))))))))))))))))))))))))))))))))))))))))
                .
                + 2012-09-17 13:02 . 2012-09-17 13:02   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                - 2012-09-16 00:17 . 2012-09-16 11:11   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                - 2012-09-16 00:17 . 2012-09-16 11:11   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                + 2012-09-17 13:02 . 2012-09-17 13:02   2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                - 2012-08-15 17:32 . 2012-08-15 17:32   157680              c:\windows\SysWOW64\javaws.exe
                + 2012-09-17 14:17 . 2012-08-28 19:10   157680              c:\windows\SysWOW64\javaws.exe
                + 2012-09-17 14:17 . 2012-08-28 19:10   149488              c:\windows\SysWOW64\javaw.exe
                - 2012-08-15 17:32 . 2012-08-15 17:32   149488              c:\windows\SysWOW64\javaw.exe
                + 2012-09-17 14:17 . 2012-08-28 19:09   149488              c:\windows\SysWOW64\java.exe
                - 2012-08-15 17:32 . 2012-08-15 17:32   149488              c:\windows\SysWOW64\java.exe
                - 2009-07-14 02:36 . 2012-09-16 11:16   730952              c:\windows\system32\perfh009.dat
                + 2009-07-14 02:36 . 2012-09-17 20:20   730952              c:\windows\system32\perfh009.dat
                + 2009-07-14 02:36 . 2012-09-17 20:20   150746              c:\windows\system32\perfc009.dat
                - 2009-07-14 02:36 . 2012-09-16 11:16   150746              c:\windows\system32\perfc009.dat
                + 2009-07-14 05:01 . 2012-09-17 13:01   372400              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                - 2009-07-14 05:01 . 2012-09-16 00:03   372400              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
                + 2011-06-08 00:42 . 2012-09-16 23:14   2727248              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
                + 2012-09-17 17:59 . 2012-09-17 17:59   5096448              c:\windows\Installer\1103606.msi
                - 2011-06-25 20:26 . 2012-09-16 00:04   28258640              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-380760752-479500143-2808968161-1000-12288.dat
                + 2011-06-25 20:26 . 2012-09-17 13:01   28258640              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-380760752-479500143-2808968161-1000-12288.dat
                .
                (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* empty entries & legit default entries are not shown
                REGEDIT4
                .
                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
                "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 0]
                "AVG_TRAY"="c:\program files (x86)\AVG\AVG10\avgtray.exe" [2012-08-01 2345592]
                .
                c:\users\Removed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                CurseClientStartup.ccip [2012-9-17 0]
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                "ConsentPromptBehaviorAdmin"= 0 (0x0)
                "ConsentPromptBehaviorUser"= 3 (0x3)
                "EnableLUA"= 0 (0x0)
                "EnableUIADesktopToggle"= 0 (0x0)
                "PromptOnSecureDesktop"= 0 (0x0)
                "HideFastUserSwitching"= 0 (0x0)
                .
                [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
                "mixer"=wdmaud.drv
                .
                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
                BootExecute   REG_MULTI_SZ      autocheck autochk *\0c:\progra~2\AVG\AVG10\avgchsva.exe /sync\0c:\progra~2\AVG\AVG10\avgrsa.exe /sync /restart
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
                @=""
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                @="Driver"
                .
                R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600]
                R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2012-01-31 7391072]
                R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
                R2 ccosm;Contrl Center of Storm Media;\JHV-PC-8GIGRAM\Downloads\StormII\stormliv.exe

                R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
                R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
                R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-05 135664]
                R2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 30520]
                R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
                R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-03 160944]
                R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe

                R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2011-11-10 167264]
                R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
                R3 FreeOTFECypherBlowfish;FreeOTFECypherBlowfish;c:\windows\System32\FreeOTFECypherBlowfish.sys [2010-02-07 27760]
                R3 FreeOTFECypherCAST5;FreeOTFECypherCAST5;c:\windows\System32\FreeOTFECypherCAST5.sys [2010-02-07 34928]
                R3 FreeOTFECypherCAST6_Gladman;FreeOTFECypherCAST6_Gladman;c:\windows\System32\FreeOTFECypherCAST6_Gladman.sys [2010-02-07 34928]
                R3 FreeOTFECypherDES;FreeOTFECypherDES;c:\windows\System32\FreeOTFECypherDES.sys [2010-02-07 60016]
                R3 FreeOTFECypherMARS_Gladman;FreeOTFECypherMARS_Gladman;c:\windows\System32\FreeOTFECypherMARS_Gladman.sys [2010-02-07 30832]
                R3 FreeOTFECypherRC6_ltc;FreeOTFECypherRC6_ltc;c:\windows\System32\FreeOTFECypherRC6_ltc.sys [2010-02-07 29296]
                R3 FreeOTFECypherSerpent_Gladman;FreeOTFECypherSerpent_Gladman;c:\windows\System32\FreeOTFECypherSerpent_Gladman.sys [2010-02-07 35952]
                R3 FreeOTFECypherTwofish_ltc;FreeOTFECypherTwofish_ltc;c:\windows\System32\FreeOTFECypherTwofish_ltc.sys [2010-02-07 35440]
                R3 FreeOTFEHashMD;FreeOTFEHashMD;c:\windows\System32\FreeOTFEHashMD.sys [2010-02-07 22640]
                R3 FreeOTFEHashRIPEMD;FreeOTFEHashRIPEMD;c:\windows\System32\FreeOTFEHashRIPEMD.sys [2010-02-07 38512]
                R3 FreeOTFEHashTiger;FreeOTFEHashTiger;c:\windows\System32\FreeOTFEHashTiger.sys [2010-02-07 26224]
                R3 FreeOTFEHashWhirlpool;FreeOTFEHashWhirlpool;c:\windows\System32\FreeOTFEHashWhirlpool.sys [2010-02-07 34928]
                R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
                R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-05 135664]
                R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 140712]
                R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-17 114144]
                R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
                R3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2010-01-28 38368]
                R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
                R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
                R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
                R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
                R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-13 1255736]
                R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
                R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
                R4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files (x86)\PCPitstop\PCPitstopScheduleService.exe [2010-01-04 90352]
                R4 RsFx0105;RsFx0105 Driver;c:\windows\system32\DRIVERS\RsFx0105.sys [2011-09-22 311144]
                R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-09-22 431464]
                S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 26704]
                S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2011-03-16 37456]
                S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2011-01-07 304720]
                S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-03-01 41552]
                S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2011-04-04 377936]
                S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-09-04 31080]
                S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-06-30 254528]
                S1 FreeOTFE;FreeOTFE;c:\windows\System32\FreeOTFE.sys [2010-02-07 38512]
                S1 FreeOTFECypherAES_ltc;FreeOTFECypherAES_ltc;c:\windows\System32\FreeOTFECypherAES_ltc.sys [2010-02-07 50800]
                S1 FreeOTFEHashSHA;FreeOTFEHashSHA;c:\windows\System32\FreeOTFEHashSHA.sys [2010-02-07 29296]
                S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
                S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
                S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
                S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
                S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-05 203264]
                S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG10\avgwdsvc.exe [2011-02-08 269520]
                S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
                S2 InternetEverywhere_Service;InternetEverywhere_Service;c:\program files (x86)\InternetEverywhere\InternetEverywhere_Service.exe [2010-05-21 329168]
                S2 Neurotechnology;Neurotechnology;c:\program files (x86)\VirtualDub-1.9.11 with DShowInputDriver\plugins\Activation\pg.exe [2011-08-04 230720]
                S2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2010-01-28 294880]
                S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-05-27 118864]
                S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-02-10 29264]
                S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 35104]
                S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 70656]
                S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]
                S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 36408]
                .
                .
                --- Other Services/Drivers In Memory ---
                .
                *NewlyCreated* - ASWMBR
                *Deregistered* - aswMBR
                .
                HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
                ezSharedSvc
                .
                [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
                2009-08-20 21:24   451872   ----a-w-   c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
                .
                Contents of the 'Scheduled Tasks' folder
                .
                2012-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-05 20:09]
                .
                2012-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-05 20:09]
                .
                .
                --------- X64 Entries -----------
                .
                .
                ------- Supplementary Scan -------
                .
                uStart Page = hxxp://www.google.co.uk/
                uLocal Page = c:\windows\system32\blank.htm
                mLocal Page = c:\windows\SysWOW64\blank.htm
                IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000
                IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
                FF - ProfilePath - c:\users\Removed\AppData\Roaming\Mozilla\Firefox\Profiles\rda0e265.default\
                FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
                FF - prefs.js: keyword.URL - hxxp://www.google.co.uk/#hl=en&output=search&sclient=psy-ab&q=
                .
                - - - - ORPHANS REMOVED - - - -
                .
                Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
                Wow6432Node-HKLM-Run-vProt - c:\program files (x86)\AVG Secure Search\vprot.exe
                Wow6432Node-HKLM-Run-HF_G_Jul - c:\program files (x86)\AVG Secure Search\HF_G_Jul.exe
                Wow6432Node-HKLM-Run-ROC_ROC_JULY_P1 - c:\program files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe
                .
                .
                .
                --------------------- LOCKED REGISTRY KEYS ---------------------
                .
                [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
                @Denied: (2) (LocalSystem)
                "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4,
                   91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27
                "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8,
                   89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b
                "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
                   1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
                "{326E768D-4182-46FD-9C16-1449A49795F4}"=hex:51,66,7a,6c,4c,1d,38,12,e3,75,7d,
                   36,b0,0f,93,03,e3,00,57,09,a1,c9,d1,e0
                "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1,
                   38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4
                "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
                   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
                "{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
                   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
                "{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
                   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
                "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd,
                   d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b
                "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
                   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
                "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
                   fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
                "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
                   b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
                .
                [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
                @Denied: (2) (LocalSystem)
                "Timestamp"=hex:d9,70,84,23,48,26,cd,01
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
                @Denied: (A 2) (Everyone)
                @="FlashBroker"
                "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
                "Enabled"=dword:00000001
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
                @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                @Denied: (A 2) (Everyone)
                @="Shockwave Flash Object"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
                "ThreadingModel"="Apartment"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                @="0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                @="ShockwaveFlash.ShockwaveFlash.10"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                @="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                @="ShockwaveFlash.ShockwaveFlash"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                @Denied: (A 2) (Everyone)
                @="Macromedia Flash Factory Object"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
                "ThreadingModel"="Apartment"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                @="FlashFactory.FlashFactory.1"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                @="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                @="FlashFactory.FlashFactory"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
                @Denied: (A 2) (Everyone)
                @="IFlashBroker3"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
                @="{00020424-0000-0000-C000-000000000046}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                "Version"="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Environment*]
                "Setup"="EXPIRED"
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                @Denied: (A) (Users)
                @Denied: (A) (Everyone)
                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                "BlindDial"=dword:00000000
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
                @Denied: (A) (Users)
                @Denied: (A) (Everyone)
                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                "BlindDial"=dword:00000000
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
                @Denied: (A) (Users)
                @Denied: (A) (Everyone)
                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                "BlindDial"=dword:00000000
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                @Denied: (Full) (Everyone)
                .
                Completion time: 2012-09-18  01:12:36
                ComboFix-quarantined-files.txt  2012-09-18 00:12
                ComboFix2.txt  2012-09-17 23:14
                .
                Pre-Run: 182,797,524,992 bytes free
                Post-Run: 182,635,413,504 bytes free
                .
                - - End Of File - - 8008A5AC4848D62013CDC8BC94FDC037

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: Suspected Malware Cause of Multiple DLL Errors.
                « Reply #10 on: September 17, 2012, 07:47:55 PM »
                Please download Rooter and Save it to your desktop.
                • Double click it to start the tool.Vista and Windows7 run as administrator.
                • Click Scan.
                • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
                Windows 8 and Windows 10 dual boot with two SSD's

                Sirim

                  Topic Starter


                  Rookie

                  Thanked: 2
                  • Experience: Familiar
                  • OS: Windows 7
                  Re: Suspected Malware Cause of Multiple DLL Errors.
                  « Reply #11 on: September 18, 2012, 06:12:55 AM »
                  Thanks once again for your continued help.

                  I downloaded and ran rooter. Log included below.

                  Rooter.exe (v1.0.2) by Eric_71
                  .
                  SeDebugPrivilege granted successfully ...
                  .
                  Windows 7 Home Edition (6.1.7601) Service Pack 1
                  [32_bits] - AMD64 Family 16 Model 6 Stepping 2, AuthenticAMD
                  .
                  [wscsvc] (Security Center) RUNNING (state:4)
                  [MpsSvc] RUNNING (state:4)
                  Windows Firewall -> Enabled
                  Windows Defender -> Enabled
                  User Account Control (UAC) -> Disabled !
                  .
                  Internet Explorer 9.0.8112.16421
                  Mozilla Firefox 15.0.1 (en-GB)
                  .
                  C:\  [Fixed-NTFS] .. ( Total:451 Go - Free:170 Go )
                  D:\  [Fixed-NTFS] .. ( Total:13 Go - Free:2 Go )
                  E:\  [Fixed-FAT32] .. ( Total:0 Go - Free:0 Go )
                  F:\  [CD_Rom]
                  G:\  [CD_Rom]
                  .
                  Scan : 13:11.36
                  Path : C:\Users\removed\AppData\Local\Opera\Opera\temporary_downloads\Rooter.exe
                  User : removed ( Administrator -> YES )
                  .
                  ----------------------\\ Processes
                  .
                  Locked [System Process] (0)
                  Locked System (4)
                  ______ ?????????? (292)
                  ______ ?????????? (568)
                  ______ ?????????? (640)
                  ______ ?????????? (652)
                  ______ ?????????? (704)
                  ______ ?????????? (724)
                  ______ ?????????? (732)
                  ______ ?????????? (836)
                  ______ ?????????? (912)
                  ______ ?????????? (952)
                  ______ ?????????? (1008)
                  ______ ?????????? (528)
                  ______ ?????????? (552)
                  ______ ?????????? (928)
                  ______ ?????????? (1064)
                  ______ ?????????? (1208)
                  ______ ?????????? (1360)
                  ______ ?????????? (1520)
                  ______ ?????????? (1560)
                  ______ ?????????? (1656)
                  ______ ?????????? (1732)
                  ______ ?????????? (1816)
                  ______ ?????????? (1840)
                  ______ C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (2024)
                  ______ ?????????? (1836)
                  ______ C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (1856)
                  ______ ?????????? (1388)
                  ______ C:\Program Files (x86)\InternetEverywhere\InternetEverywhere_Service.exe (2100)
                  ______ C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (2132)
                  ______ ?????????? (2500)
                  ______ C:\Windows\SysWOW64\PnkBstrA.exe (2684)
                  ______ ?????????? (2788)
                  ______ C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (2812)
                  ______ ?????????? (2912)
                  ______ ?????????? (2952)
                  ______ C:\Program Files (x86)\VirtualDub-1.9.11 with DShowInputDriver\plugins\Activation\pg.exe (2380)
                  ______ ?????????? (3392)
                  ______ ?????????? (3660)
                  ______ ?????????? (3728)
                  ______ ?????????? (3836)
                  ______ ?????????? (3824)
                  ______ ?????????? (4236)
                  ______ c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (4300)
                  ______ ?????????? (4804)
                  ______ ?????????? (1236)
                  ______ ?????????? (1280)
                  ______ ?????????? (5172)
                  ______ C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe (2228)
                  ______ ?????????? (4612)
                  ______ C:\Program Files (x86)\Opera\opera.exe (5148)
                  ______ C:\Program Files (x86)\AVG\AVG10\avgtray.exe (504)
                  ______ C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe (5572)
                  ______ ?????????? (5500)
                  ______ C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (3112)
                  ______ ?????????? (2900)
                  ______ ?????????? (5256)
                  ______ ?????????? (3700)
                  ______ ?????????? (3348)
                  ______ ?????????? (2076)
                  ______ ?????????? (3636)
                  ______ ?????????? (512)
                  ______ C:\Users\removed\AppData\Local\Opera\Opera\temporary_downloads\Rooter.exe (336)
                  .
                  ----------------------\\ Device\Harddisk0\
                  .
                  \Device\Harddisk0 [Sectors : 63 x 512 Bytes]
                  .
                  \Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:1048576 | Length:208666624)
                  \Device\Harddisk0\Partition2 (Start_Offset:209715200 | Length:485214912512)
                  \Device\Harddisk0\Partition3 (Start_Offset:485424627712 | Length:14574157824)
                  \Device\Harddisk0\Partition4 (Start_Offset:499998785536 | Length:108027904)
                  .
                  ----------------------\\ Scheduled Tasks
                  .
                  C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
                  C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
                  C:\Windows\Tasks\SA.DAT
                  C:\Windows\Tasks\SCHEDLGU.TXT
                  .
                  ----------------------\\ Registry
                  .
                  .
                  ----------------------\\ Files & Folders
                  .
                  ----------------------\\ Scan completed at 13:11.44
                  .
                  C:\Rooter$\Rooter_1.txt - (18/09/2012 | 13:11.44)

                  SuperDave

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: Suspected Malware Cause of Multiple DLL Errors.
                  « Reply #12 on: September 18, 2012, 04:18:02 PM »
                  How's your computer running now?

                  I'd like to scan your machine with ESET OnlineScan

                  •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
                  ESET OnlineScan
                  •Click the button.
                  •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
                  • Click on to download the ESET Smart Installer. Save it to your desktop.
                  • Double click on the icon on your desktop.
                  •Check
                  •Click the button.
                  •Accept any security warnings from your browser.
                  •Check
                  •Push the Start button.
                  •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
                  •When the scan completes, push
                  •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
                  •Push the button.
                  •Push
                  A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
                  Windows 8 and Windows 10 dual boot with two SSD's

                  Sirim

                    Topic Starter


                    Rookie

                    Thanked: 2
                    • Experience: Familiar
                    • OS: Windows 7
                    Re: Suspected Malware Cause of Multiple DLL Errors.
                    « Reply #13 on: September 19, 2012, 04:06:00 AM »
                    Thank you for your continued help.

                    I have observed no difference. All the dll error message boxes are still popping up.

                    I ran ESET online scanner. The log is included below.

                    ESETSmartInstaller@High as CAB hook log:
                    OnlineScanner64.ocx - registred OK
                    OnlineScanner.ocx - registred OK
                    # version=7
                    # iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
                    # OnlineScanner.ocx=1.0.0.6583
                    # api_version=3.0.2
                    # EOSSerial=cc13cea59299204d8a18bf0d55899ca2
                    # end=finished
                    # remove_checked=true
                    # archives_checked=true
                    # unwanted_checked=true
                    # unsafe_checked=false
                    # antistealth_checked=true
                    # utc_time=2012-09-19 01:48:49
                    # local_time=2012-09-19 02:48:49 (+0000, GMT Daylight Time)
                    # country="United Kingdom"
                    # lang=1033
                    # osver=6.1.7601 NT Service Pack 1
                    # compatibility_mode=512 16777215 100 0 204775 204775 0 0
                    # compatibility_mode=1032 16777213 100 87 39597 91181439 0 0
                    # compatibility_mode=5893 16776574 100 94 31649659 100475145 0 0
                    # compatibility_mode=8192 67108863 100 0 117 117 0 0
                    # scanned=286607
                    # found=0
                    # cleaned=0
                    # scan_time=9234

                    SuperDave

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Thanked: 1020
                    • Certifications: List
                    • Experience: Expert
                    • OS: Windows 10
                    Re: Suspected Malware Cause of Multiple DLL Errors.
                    « Reply #14 on: September 19, 2012, 04:45:20 PM »
                    I'm going to consult with a colleague about this problem.
                    Windows 8 and Windows 10 dual boot with two SSD's

                    Sirim

                      Topic Starter


                      Rookie

                      Thanked: 2
                      • Experience: Familiar
                      • OS: Windows 7
                      Re: Suspected Malware Cause of Multiple DLL Errors.
                      « Reply #15 on: September 19, 2012, 06:30:36 PM »
                      Okay, thank-you once again for all your help.

                      SuperDave

                      • Malware Removal Specialist
                      • Moderator


                      • Genius
                      • Thanked: 1020
                      • Certifications: List
                      • Experience: Expert
                      • OS: Windows 10
                      Re: Suspected Malware Cause of Multiple DLL Errors.
                      « Reply #16 on: September 20, 2012, 04:49:03 PM »
                      Download Windows Repair (all in one) from this site
                      Install the program then run it.

                      Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:



                      Once that is done then go to Step 3 and allow it to run System File Check by clicking on Do It button:



                      Go to Step 4 and under "System Restore" click on Create button:



                      Go to Start Repairs tab and click Start button.



                      Please ensure that ONLY items seen in the image below are ticked as indicated (they're all checked by default):



                      Click on box next to the Restart System when Finished. Then click on Start.
                      Windows 8 and Windows 10 dual boot with two SSD's

                      Sirim

                        Topic Starter


                        Rookie

                        Thanked: 2
                        • Experience: Familiar
                        • OS: Windows 7
                        Re: Suspected Malware Cause of Multiple DLL Errors.
                        « Reply #17 on: September 20, 2012, 05:42:35 PM »
                        Thanks for the new suggestion.

                        Unfortunately, I was unable to run the program. I first tried with the installer version. It installed with no errors, but then, on launching the application, a message box appeared with message 'Unexpected error'. I then tried the portable version, but the same error occurred on launching the tool. Perhaps it is reliant on a damaged windows DLL? I will schedule another check disk now, via the normal windows interface.

                        SuperDave

                        • Malware Removal Specialist
                        • Moderator


                        • Genius
                        • Thanked: 1020
                        • Certifications: List
                        • Experience: Expert
                        • OS: Windows 10
                        Re: Suspected Malware Cause of Multiple DLL Errors.
                        « Reply #18 on: September 25, 2012, 07:37:57 PM »
                        Sorry for the delay. I'm going to try one more thing and if it doesn't work I will move this topic to The Windows 7 forum.
                        Please go to this site and it will instruct you how to run the Action center. It's suppose to fix a lot of problems.
                        Windows 8 and Windows 10 dual boot with two SSD's