Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

help please with virus


  • Please log in to reply

#1
jerichoy2j

jerichoy2j

    Member

  • Member
  • PipPip
  • 38 posts
i had the think point virus now i have had a few problems with pc including system information volume being denied

OTL logfile created on: 01/11/2010 15:25:20 - Run 1
OTL by OldTimer - Version 3.2.17.2 Folder = C:\Users\HD-SERVER\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 297.99 Gb Total Space | 240.59 Gb Free Space | 80.74% Space Free | Partition Type: NTFS
Drive D: | 1863.01 Gb Total Space | 454.76 Gb Free Space | 24.41% Space Free | Partition Type: NTFS
Drive E: | 1397.26 Gb Total Space | 9.23 Gb Free Space | 0.66% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 1403.74 Gb Free Space | 75.35% Space Free | Partition Type: NTFS
Drive G: | 1863.01 Gb Total Space | 525.52 Gb Free Space | 28.21% Space Free | Partition Type: NTFS
Drive H: | 1863.01 Gb Total Space | 475.95 Gb Free Space | 25.55% Space Free | Partition Type: NTFS
Drive I: | 1397.25 Gb Total Space | 14.74 Gb Free Space | 1.05% Space Free | Partition Type: NTFS
Drive J: | 1397.26 Gb Total Space | 1.32 Gb Free Space | 0.09% Space Free | Partition Type: NTFS
Drive K: | 1397.26 Gb Total Space | 6.85 Gb Free Space | 0.49% Space Free | Partition Type: NTFS
Drive L: | 1397.26 Gb Total Space | 49.22 Gb Free Space | 3.52% Space Free | Partition Type: NTFS
Drive M: | 1397.26 Gb Total Space | 636.42 Gb Free Space | 45.55% Space Free | Partition Type: NTFS
Drive N: | 1397.26 Gb Total Space | 370.57 Gb Free Space | 26.52% Space Free | Partition Type: NTFS
Drive O: | 1397.26 Gb Total Space | 1397.13 Gb Free Space | 99.99% Space Free | Partition Type: NTFS
Drive R: | 1397.26 Gb Total Space | 511.48 Gb Free Space | 36.61% Space Free | Partition Type: NTFS
Drive S: | 1397.26 Gb Total Space | 760.61 Gb Free Space | 54.44% Space Free | Partition Type: NTFS
Drive T: | 931.51 Gb Total Space | 649.66 Gb Free Space | 69.74% Space Free | Partition Type: NTFS
Drive W: | 1397.26 Gb Total Space | 1391.45 Gb Free Space | 99.58% Space Free | Partition Type: NTFS
Drive X: | 1397.26 Gb Total Space | 215.27 Gb Free Space | 15.41% Space Free | Partition Type: NTFS

Computer Name: HD-SERVER-PC | User Name: HD-SERVER | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/01 15:25:04 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\HD-SERVER\Desktop\OTL.exe
PRC - [2010/07/16 01:32:48 | 000,322,352 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/05/06 18:09:06 | 000,415,638 | ---- | M] (Old McDonald's Farm) -- C:\Program Files (x86)\Autorun Eater\billy.exe
PRC - [2010/05/06 17:59:36 | 000,516,216 | ---- | M] (Old McDonald's Farm) -- C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe
PRC - [2010/04/23 20:14:49 | 003,460,032 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
PRC - [2009/09/11 23:34:54 | 000,092,848 | ---- | M] (Binary Fortress Software) -- C:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe
PRC - [2009/07/30 18:39:12 | 001,216,648 | ---- | M] (Ext2Fsd Group (www.ext2fsd.com)) -- C:\Program Files\Ext2Fsd\Ext2Mgr.exe
PRC - [2009/07/27 02:37:50 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2009/07/01 16:37:06 | 000,037,888 | ---- | M] () -- C:\Program Files (x86)\Winamp\winampa.exe
PRC - [2009/01/29 22:20:49 | 000,057,344 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
PRC - [2008/12/05 15:11:54 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe


========== Modules (SafeList) ==========

MOD - [2010/11/01 15:25:04 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\HD-SERVER\Desktop\OTL.exe
MOD - [2010/02/04 18:17:27 | 000,129,984 | ---- | M] (SlySoft, Inc.) -- C:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp1.dll
MOD - [2009/09/11 23:34:52 | 000,048,304 | ---- | M] (Binary Fortress Software) -- C:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.dll
MOD - [2009/07/14 01:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/07/07 01:50:54 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 01:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2010/06/10 20:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/12/11 15:35:28 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/07/14 01:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2009/07/14 01:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2009/07/14 01:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2009/06/10 21:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/12/05 15:11:54 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/07/07 02:30:08 | 007,195,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2010/07/07 02:30:08 | 007,195,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/07/07 01:15:42 | 000,265,728 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/05/06 09:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010/04/23 16:31:09 | 000,123,840 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2010/04/19 19:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/02/23 10:51:14 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2010/02/23 10:51:14 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2010/01/01 17:20:28 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2009/10/16 21:49:27 | 000,161,584 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SI3114r.sys -- (SI3114r)
DRV:64bit: - [2009/10/16 21:49:27 | 000,022,832 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SiWinAcc.sys -- (SiFilter)
DRV:64bit: - [2009/08/09 21:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009/07/14 01:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 01:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 00:09:15 | 000,145,920 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rmcast.sys -- (RMCAST)
DRV:64bit: - [2009/06/17 16:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009/06/17 16:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009/06/10 20:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 20:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/01 12:50:52 | 000,033,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64k.sys -- (Point64)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2007/03/01 14:27:24 | 000,360,448 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aar81xx.sys -- (aar81xx)
DRV:64bit: - [2007/02/16 00:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2010/04/23 16:31:09 | 000,123,840 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2010/02/23 10:51:14 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2010/02/23 10:51:14 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2007/11/06 08:06:52 | 000,035,096 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\Windows\SysWOW64\drivers\hotcore3.sys -- (hotcore3)
DRV - [2007/02/16 00:57:06 | 000,040,648 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys -- (ElbyCDFL)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 32 DB D8 A6 4E CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\{D451D39B-BFC7-4AD8-9533-74BACB071B9E}: C:\Users\HD-SERVER\AppData\Local\{D451D39B-BFC7-4AD8-9533-74BACB071B9E} [2010/10/26 01:27:29 | 000,000,000 | ---D | M]

[2010/02/15 22:49:36 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Mozilla\Extensions
[2010/02/15 22:49:36 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2009/12/11 15:37:34 | 000,001,277 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - Reg Error: Value error. File not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Autorun Eater] C:\Program Files (x86)\Autorun Eater\oldmcdonald.exe (Old McDonald's Farm)
O4 - HKLM..\Run: [CloneCDTray] C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [Ext2 Volume Manager] C:\Program Files\Ext2Fsd\Ext2Mgr.exe (Ext2Fsd Group (www.ext2fsd.com))
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe ()
O4 - HKCU..\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [DisplayFusion] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [EPSON Stylus Photo R285 Series (Copy 1)] C:\Windows\SysWow64\spool\DRIVERS\x64\3\E_IATICKE.EXE File not found
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\HD-SERVER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\HD-SERVER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk = C:\Users\HD-SERVER\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - Reg Error: Value error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0EBBED-0C42-4D0F-82DA-44399B5C420A} http://downloads.vir...er1/xp_mail.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{62b458ff-68dc-11df-8499-00241d7d6427}\Shell - "" = AutoRun
O33 - MountPoints2\{62b458ff-68dc-11df-8499-00241d7d6427}\Shell\AutoRun\command - "" = U:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/01 15:25:01 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Users\HD-SERVER\Desktop\OTL.exe
[2010/11/01 14:48:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\theRenamer
[2010/11/01 14:22:37 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\AppData\Roaming\TVRename
[2010/11/01 14:22:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TVRename
[2010/11/01 13:25:30 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\AppData\Roaming\MediaRenamer
[2010/11/01 13:24:57 | 000,000,000 | ---D | C] -- C:\Program Files\Media Renamer
[2010/11/01 13:19:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SWF Studio
[2010/11/01 13:19:39 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\Tracing\Documents\theRenamer
[2010/10/30 20:42:46 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\Desktop\default
[2010/10/27 01:41:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Systerac
[2010/10/26 01:55:41 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/10/26 01:27:29 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\AppData\Local\{D451D39B-BFC7-4AD8-9533-74BACB071B9E}
[2010/10/26 01:25:33 | 000,000,000 | ---D | C] -- C:\Extracted
[2010/10/25 21:03:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Runtime Software
[2010/10/21 16:23:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Autorun Eater
[2010/10/21 16:23:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Autorun Eater
[2010/10/21 16:03:10 | 000,028,672 | ---- | C] (Unistal Systems Pvt. Ltd.) -- C:\Windows\Getdisk.exe
[2010/10/21 16:03:10 | 000,000,000 | ---D | C] -- C:\Windows\Recover Data for FAT & NTFS
[2010/10/21 16:03:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Recover Data for FAT & NTFS
[2010/10/21 12:29:44 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2010/10/21 12:28:14 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2010/10/16 01:44:05 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\AppData\Roaming\Nord
[2010/10/16 01:29:21 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/10/15 15:39:00 | 000,000,000 | ---D | C] -- C:\Users\HD-SERVER\AppData\Local\Microsoft Help
[2009/12/10 11:13:14 | 000,822,784 | ---- | C] (ACARD Technology Corp.) -- C:\Users\HD-SERVER\AppData\Roaming\ImgMgr.exe
[2009/10/20 22:46:56 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\HD-SERVER\AppData\Roaming\pcouffin.sys
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/01 15:25:04 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Users\HD-SERVER\Desktop\OTL.exe
[2010/11/01 15:10:34 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/01 15:10:34 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/01 10:21:23 | 000,000,946 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Local\7F68A003.il
[2010/11/01 10:21:23 | 000,000,280 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Local\IndexIE_7F68A003.il
[2010/11/01 02:21:15 | 000,004,008 | ---- | M] () -- C:\Users\HD-SERVER\Tracing\Documents\right3[1].gif
[2010/10/30 12:59:38 | 000,001,084 | ---- | M] () -- C:\Users\HD-SERVER\Videos - Shortcut (2).lnk
[2010/10/30 02:01:20 | 000,021,911 | ---- | M] () -- C:\Users\HD-SERVER\Desktop\67521_164306170259654_164305696926368_442474_2875100_n.jpg
[2010/10/28 14:15:40 | 000,861,092 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/10/28 14:15:40 | 000,724,356 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/10/28 14:15:40 | 000,144,596 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/10/28 13:56:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/10/28 13:56:35 | 3220,021,248 | -HS- | M] () -- C:\hiberfil.sys
[2010/10/27 02:01:23 | 003,024,904 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/10/27 01:54:50 | 000,000,816 | RHS- | M] () -- C:\Users\HD-SERVER\ntuser.pol
[2010/10/26 01:36:46 | 000,000,006 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Roaming\start
[2010/10/26 01:34:30 | 000,000,006 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Roaming\completescan
[2010/10/26 01:27:40 | 000,000,010 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Roaming\install
[2010/10/26 01:27:30 | 000,000,120 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Local\Ktivezaxijoyi.dat
[2010/10/26 01:27:30 | 000,000,000 | ---- | M] () -- C:\Users\HD-SERVER\AppData\Local\Cxebaxedakokoxe.bin
[2010/10/24 14:41:24 | 002,344,960 | ---- | M] () -- C:\Users\HD-SERVER\Desktop\BDedit.exe
[2010/10/18 15:57:00 | 000,319,872 | ---- | M] () -- C:\Windows6.1-KB977178-v2-x64.msu
[2010/10/17 00:59:50 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/01 02:22:33 | 000,004,008 | ---- | C] () -- C:\Users\HD-SERVER\Tracing\Documents\right3[1].gif
[2010/10/30 12:59:38 | 000,001,084 | ---- | C] () -- C:\Users\HD-SERVER\Videos - Shortcut (2).lnk
[2010/10/30 02:03:08 | 000,021,911 | ---- | C] () -- C:\Users\HD-SERVER\Desktop\67521_164306170259654_164305696926368_442474_2875100_n.jpg
[2010/10/27 13:24:16 | 002,094,547 | ---- | C] () -- C:\Users\HD-SERVER\Desktop\Blu-ray Disc2 Postman.psd
[2010/10/27 01:49:39 | 000,000,816 | RHS- | C] () -- C:\Users\HD-SERVER\ntuser.pol
[2010/10/26 01:36:46 | 000,000,006 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\start
[2010/10/26 01:34:30 | 000,000,006 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\completescan
[2010/10/26 01:27:40 | 000,000,010 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\install
[2010/10/26 01:27:30 | 000,000,120 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Local\Ktivezaxijoyi.dat
[2010/10/26 01:27:30 | 000,000,000 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Local\Cxebaxedakokoxe.bin
[2010/10/25 19:06:28 | 000,097,758 | ---- | C] () -- C:\Users\HD-SERVER\Desktop\Lust, Caution [Bluray 720p and 1080p SRT].srt
[2010/10/21 12:12:50 | 000,319,872 | ---- | C] () -- C:\Windows6.1-KB977178-v2-x64.msu
[2010/08/12 01:38:03 | 004,244,744 | ---- | C] () -- C:\Windows\SysWow64\qtp-mt334.dll
[2010/08/12 01:38:03 | 000,247,560 | ---- | C] () -- C:\Windows\SysWow64\prgiso.dll
[2010/08/12 01:38:03 | 000,013,576 | ---- | C] () -- C:\Windows\SysWow64\wnaspi32.dll
[2010/07/31 01:57:11 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/07/20 13:22:22 | 000,000,551 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\AutoGK.ini
[2010/06/21 15:35:15 | 000,003,584 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/19 21:10:16 | 000,116,736 | ---- | C] () -- C:\Windows\SysWow64\libsndfile-1.dll
[2010/05/28 12:45:02 | 000,000,946 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Local\7F68A003.il
[2010/05/28 12:45:02 | 000,000,280 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Local\IndexIE_7F68A003.il
[2010/05/27 08:15:06 | 000,014,848 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2010/05/27 08:15:05 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2010/05/27 08:15:05 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2010/04/25 22:44:14 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll
[2009/11/21 15:21:12 | 000,001,067 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\DVDSubEdit.ini
[2009/11/17 07:18:21 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2009/11/04 10:01:09 | 000,000,760 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\setup_ldm.iss
[2009/10/21 14:10:31 | 000,000,156 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\default.rss
[2009/10/21 14:10:16 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2009/10/20 22:47:02 | 000,000,074 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\pcouffin.log
[2009/10/20 22:46:56 | 000,099,384 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\inst.exe
[2009/10/20 22:46:56 | 000,007,859 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\pcouffin.cat
[2009/10/20 22:46:56 | 000,001,167 | ---- | C] () -- C:\Users\HD-SERVER\AppData\Roaming\pcouffin.inf
[2009/10/19 19:32:23 | 000,846,584 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/07/13 23:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/01/25 21:10:48 | 000,179,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/01/08 23:01:22 | 000,629,760 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2002/10/15 22:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll

========== LOP Check ==========

[2009/10/25 00:53:37 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\BDREBUILDER
[2010/10/25 22:17:02 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\BitTorrent
[2010/10/18 15:23:29 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\DisplayFusion
[2009/10/16 22:05:05 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Epson
[2009/11/13 19:31:34 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\GlobalSCAPE
[2010/06/19 21:11:57 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\HandBrake
[2010/07/12 20:43:46 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Hulubulu
[2009/10/17 14:07:49 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\ImgBurn
[2009/11/03 08:00:42 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Leadertech
[2010/11/01 13:26:12 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\MediaRenamer
[2010/08/04 13:26:22 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\mkvtoolnix
[2010/05/24 07:09:08 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\NewsLeecher
[2010/10/16 01:44:05 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Nord
[2010/08/05 13:20:48 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Notepad++
[2009/11/04 20:49:08 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\RipIt4Me
[2010/06/15 01:09:45 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Sports Interactive
[2009/11/22 00:35:05 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\SupRip
[2010/11/01 14:22:37 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\TVRename
[2010/11/01 15:24:16 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\uTorrent
[2010/02/16 16:17:58 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Vivox
[2009/10/20 22:47:02 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\Vso
[2009/11/24 23:26:28 | 000,000,000 | ---D | M] -- C:\Users\HD-SERVER\AppData\Roaming\YANFOE
[2010/05/29 18:54:37 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP