Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

More Google Redirects


  • This topic is locked This topic is locked

#1
javco

javco

    Member

  • Member
  • PipPip
  • 10 posts
Hey guys,

I was hoping your infinite wisdom might help me sort out this redirect issue I've been dealing with for a few days. I'll run a search on Google, but the links will redirect me to random search engines. Also, every few minutes a new tab will open up with an ad.

This issue came bundled with the Windows 7 Recovery virus that pretends to be antivirus software, which hides everything on my computer and disables the task manager. I was able to take care of those issues, but the google redirect is beyond me.

I run Windows 7 64-bit.

I did a scan with HijackThis and here's what I got:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:55:37 PM, on 5/14/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe
C:\Program Files (x86)\ASUS\AI Manager\AIManager.exe
C:\Program Files (x86)\ASUS\AI Direct Link\AsShare.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane..._2.3.10.115.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.ad...Plus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: Device Handle Service - ASUSTeK Computer Inc. - C:\Windows\SysWOW64\AsHookDevice.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TabletServiceWacom - Unknown owner - C:\Windows\system32\Wacom_Tablet.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9859 bytes

Edited by javco, 20 May 2011 - 02:45 PM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there sorry for the delay - I will need a fresh look at your system and an update on your symptoms please

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply
Posted Image

THEN

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /mp /s
    hklm\software\clients\startmenuinternet|command /rs
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#3
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Thanks for the reply, here's what I got from the scans.

aswMBR
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-21 15:58:40
-----------------------------
15:58:40.382 OS Version: Windows x64 6.1.7600
15:58:40.383 Number of processors: 8 586 0x1A05
15:58:40.383 ComputerName: JAVCO-PC UserName: Javco
15:58:41.817 Initialize success
15:58:47.073 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
15:58:47.074 Disk 0 Vendor: ST31000528AS CC44 Size: 953869MB BusType: 3
15:58:47.076 Device \Driver\atapi -> MajorFunction fffffa8008b0e6c0
15:58:47.078 Disk 0 MBR read successfully
15:58:47.079 Disk 0 MBR scan
15:58:47.081 Disk 0 [email protected] code has been found
15:58:47.083 Disk 0 MBR hidden
15:58:47.085 Disk 0 MBR [TDL4] **ROOTKIT**
15:58:47.087 Disk 0 trace - called modules:
15:58:47.089 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa8008b0e6c0]<<
15:58:47.092 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008aff060]
15:58:47.094 3 CLASSPNP.SYS[fffff88001a8a43f] -> nt!IofCallDriver -> [0xfffffa80087c1520]
15:58:47.097 5 ACPI.sys[fffff88001012781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80087c2060]
15:58:47.099 \Driver\atapi[0xfffffa8008965880] -> IRP_MJ_CREATE -> 0xfffffa8008b0e6c0
15:58:47.103 Scan finished successfully
15:59:08.144 Disk 0 MBR has been saved successfully to "C:\Users\Javco\Desktop\MBR.dat"
15:59:08.147 The log file has been saved successfully to "C:\Users\Javco\Desktop\aswMBR.txt"
  • 0

#4
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
OTL
OTL logfile created on: 5/21/2011 4:04:32 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Javco\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.00 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 82.00% Memory free
18.00 Gb Paging File | 16.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.61 Gb Total Space | 28.03 Gb Free Space | 7.52% Space Free | Partition Type: NTFS
Drive D: | 548.90 Gb Total Space | 350.89 Gb Free Space | 63.93% Space Free | Partition Type: NTFS
Drive F: | 0.03 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.73 Gb Total Space | 1.66 Gb Free Space | 44.51% Space Free | Partition Type: FAT32
Drive I: | 27.81 Gb Total Space | 1.25 Gb Free Space | 4.49% Space Free | Partition Type: FAT32

Computer Name: JAVCO-PC | User Name: Javco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/21 15:59:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Javco\Downloads\OTL.exe
PRC - [2011/05/05 19:20:23 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/04/16 17:48:35 | 000,400,760 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\BitTorrent\bittorrent.exe
PRC - [2009/11/24 19:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 19:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 19:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 19:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/10/30 07:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2009/08/20 00:59:18 | 000,858,112 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Manager\AIManager.exe
PRC - [2009/08/20 00:55:40 | 000,196,608 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Windows\SysWOW64\AsHookDevice.exe
PRC - [2008/12/09 21:54:22 | 001,212,416 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\AI Direct Link\AsShare.exe
PRC - [2008/06/17 14:09:02 | 000,376,832 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe


========== Modules (SafeList) ==========

MOD - [2011/05/21 15:59:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Javco\Downloads\OTL.exe
MOD - [2009/07/13 21:15:31 | 000,154,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll
MOD - [2009/07/13 21:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll
MOD - [2009/07/13 21:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/09/06 15:43:37 | 001,436,424 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010/02/01 15:45:34 | 006,159,656 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Windows\SysNative\Wacom_Tablet.exe -- (TabletServiceWacom)
SRV:64bit: - [2009/11/24 19:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV:64bit: - [2009/11/24 19:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV:64bit: - [2009/11/24 19:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV:64bit: - [2009/11/24 19:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV:64bit: - [2009/06/05 05:42:04 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV - [2011/05/17 20:18:59 | 003,275,864 | ---- | M] () [Auto | Running] -- c:\Program Files (x86)\Common Files\Akamai\netsession_win_8832f4b.dll -- (Akamai)
SRV - [2011/03/01 12:12:30 | 000,147,336 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2011/03/01 12:12:26 | 000,373,640 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/11/08 12:04:20 | 000,407,424 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
SRV - [2010/02/18 19:22:55 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/01/15 08:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/12/29 20:17:24 | 000,321,320 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/08/20 00:55:40 | 000,196,608 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysWOW64\AsHookDevice.exe -- (Device Handle Service)
SRV - [2009/07/26 07:43:14 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/04/02 00:27:27 | 000,090,112 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe -- (AsSysCtrlService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/03/01 12:12:48 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2011/02/18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/09/17 15:40:06 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2010/09/17 15:39:58 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2010/05/10 00:29:02 | 000,145,936 | ---- | M] (Sun Microsystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2010/03/04 14:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/02/24 08:06:20 | 000,726,816 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364)
DRV:64bit: - [2010/01/24 15:32:24 | 000,018,216 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2010/01/05 03:07:42 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/11/24 19:50:05 | 000,022,096 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2009/11/24 19:49:56 | 000,065,616 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2009/09/21 16:29:22 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2009/08/30 22:09:33 | 000,112,240 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:64bit: - [2009/07/15 23:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 16:35:35 | 000,620,544 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/05 05:42:04 | 000,475,136 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/02/06 19:42:12 | 000,061,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2008/07/26 15:26:34 | 000,050,072 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:64bit: - [2008/07/26 15:22:34 | 002,624,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LV302V64.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV:64bit: - [2008/02/06 03:00:00 | 000,054,480 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2007/02/16 11:12:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2006/12/12 15:37:00 | 000,362,496 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr6164.sys -- (rt61x64)
DRV:64bit: - [2005/10/20 16:01:12 | 000,222,720 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RT2500.sys -- (RT2500)
DRV:64bit: - [2005/06/14 14:01:16 | 000,296,448 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\hardlock.sys -- (Hardlock)
DRV - [2010/09/17 15:40:06 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys -- (LMIInfo)
DRV - [2010/07/15 15:55:02 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:2.3.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://slirsredirect...ir=2706&query="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/05 19:20:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/05 19:20:23 | 000,000,000 | ---D | M]

[2009/12/30 08:11:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Javco\AppData\Roaming\Mozilla\Extensions
[2011/05/20 18:00:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\extensions
[2011/04/16 01:44:19 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\extensions\[email protected]
[2010/01/11 23:56:54 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\extensions\[email protected]
[2010/01/07 18:26:13 | 000,001,490 | ---- | M] () -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\searchplugins\AIM Search.xml
[2011/05/21 15:34:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/01/10 06:32:45 | 000,000,000 | ---D | M] (OneClick YouTube Downloader) -- C:\PROGRAM FILES (X86)\ORBITDOWNLOADER\ADDONS\ONECLICKYOUTUBEDOWNLOADER
[2010/01/07 18:26:13 | 000,001,490 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\AIM Search.xml

O1 HOSTS File: ([2011/05/19 17:14:53 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane..._2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 65.32.5.111 65.32.5.112
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/06 15:31:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - Unable to obtain root file information for disk D:\
O32 - AutoRun File - [2001/09/14 12:50:48 | 000,000,037 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-3742353979-2898385441-1418632823-1000..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/05/21 15:42:36 | 000,000,000 | ---D | C] -- C:\Users\Javco\Desktop\New folder (2)
[2011/05/21 15:36:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\Desktop\New folder
[2011/05/21 14:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\M5
[2011/05/19 18:07:22 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/05/19 17:54:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\Adobe
[2011/05/19 17:09:19 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/05/19 16:48:37 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\Apple Computer
[2011/05/19 16:46:36 | 000,000,000 | ---D | C] -- C:\Users\Javco\Desktop\GooredFix Backups
[2011/05/19 16:17:51 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery
[2011/05/15 09:46:38 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\LogMeIn
[2011/05/15 09:46:32 | 000,033,152 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIport.dll
[2011/05/15 09:46:31 | 000,087,456 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIRfsClientNP.dll
[2011/05/15 09:46:31 | 000,072,216 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys
[2011/05/15 09:46:29 | 000,080,768 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIinit.dll
[2011/05/15 09:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\LogMeIn
[2011/05/15 09:46:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn
[2011/05/14 17:45:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/14 17:45:18 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/05/14 17:31:09 | 000,000,000 | ---D | C] -- C:\!KillBox
[2011/05/14 17:28:50 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/05/14 17:28:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HijackThis
[2011/05/14 15:21:13 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/05/14 15:16:05 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinAce
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Swiff Player
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPER © Version 2010.bld.38 (May 2, 2010)
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sun VirtualBox
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Starcraft
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoundMAX
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pixologic
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orbit
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Next Video Converter
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mass Effect 2
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mass Effect
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JMicron Technology Corp
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Instant Wireless
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Download Manager
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! Antivirus
[2011/05/14 15:15:59 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
[2011/05/14 15:15:59 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS
[2011/05/14 15:15:59 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2011/05/14 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AIM
[2011/05/14 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe
[2011/05/14 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
[2011/05/14 15:15:57 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/05/14 15:11:50 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/05/14 15:11:50 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/05/14 15:11:50 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/05/14 15:11:46 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/05/14 14:52:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/13 17:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/13 17:04:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware2
[2011/05/08 16:04:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/08 16:03:48 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/08 16:03:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/05/08 16:03:48 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/08 16:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/08 16:02:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour

========== Files - Modified Within 30 Days ==========

[2012/10/20 00:48:55 | 2643,326,976 | ---- | M] () -- C:\Users\Javco\Desktop\n-prpcs4.iso
[2011/05/21 15:59:08 | 000,000,512 | ---- | M] () -- C:\Users\Javco\Desktop\MBR.dat
[2011/05/21 15:34:10 | 000,001,618 | -HS- | M] () -- C:\Users\Javco\AppData\Local\e4p658450oy660al14dx
[2011/05/21 15:34:10 | 000,001,618 | -HS- | M] () -- C:\ProgramData\e4p658450oy660al14dx
[2011/05/21 15:33:58 | 000,331,776 | -HS- | M] () -- C:\Users\Javco\AppData\Local\owu.exe
[2011/05/21 15:33:58 | 000,331,776 | -HS- | M] () -- C:\Users\Javco\AppData\Local\ljm.exe
[2011/05/21 13:48:24 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/21 13:48:24 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/21 13:46:05 | 000,727,172 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/21 13:46:05 | 000,623,890 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/05/21 13:46:05 | 000,107,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/05/21 13:41:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/21 13:40:55 | 2945,802,239 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/19 17:14:53 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/05/17 16:36:32 | 000,000,241 | ---- | M] () -- C:\Users\Javco\Desktop\gt1.dxr
[2011/05/15 09:46:28 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/05/14 17:50:05 | 000,202,422 | ---- | M] () -- C:\Users\Javco\Desktop\cc_20110514_174858.reg
[2011/05/14 17:28:50 | 000,002,957 | ---- | M] () -- C:\Users\Javco\Desktop\HiJackThis.lnk
[2011/05/14 04:41:02 | 000,001,152 | ---- | M] () -- C:\Windows\SysWow64\windrv.sys
[2011/05/13 17:04:41 | 000,001,148 | ---- | M] () -- C:\Users\Javco\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/05/13 16:28:54 | 000,000,120 | ---- | M] () -- C:\Users\Javco\AppData\Local\Uxihilekihiba.dat
[2011/05/13 16:28:54 | 000,000,000 | ---- | M] () -- C:\Users\Javco\AppData\Local\Jfabaxuvedidaki.bin
[2011/05/05 15:03:12 | 000,295,050 | ---- | M] () -- C:\Users\Javco\Desktop\IMG_0213.JPG
[2011/05/02 22:02:04 | 000,014,697 | ---- | M] () -- C:\Windows\SysNative\Wacom_Tablet.dat

========== Files Created - No Company Name ==========

[2011/05/21 15:59:08 | 000,000,512 | ---- | C] () -- C:\Users\Javco\Desktop\MBR.dat
[2011/05/21 15:34:04 | 000,001,618 | -HS- | C] () -- C:\Users\Javco\AppData\Local\e4p658450oy660al14dx
[2011/05/21 15:34:04 | 000,001,618 | -HS- | C] () -- C:\ProgramData\e4p658450oy660al14dx
[2011/05/21 15:33:58 | 000,331,776 | -HS- | C] () -- C:\Users\Javco\AppData\Local\owu.exe
[2011/05/21 15:33:58 | 000,331,776 | -HS- | C] () -- C:\Users\Javco\AppData\Local\ljm.exe
[2011/05/17 16:33:16 | 000,000,241 | ---- | C] () -- C:\Users\Javco\Desktop\gt1.dxr
[2011/05/15 09:46:28 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/05/14 17:49:10 | 000,202,422 | ---- | C] () -- C:\Users\Javco\Desktop\cc_20110514_174858.reg
[2011/05/14 17:28:50 | 000,002,957 | ---- | C] () -- C:\Users\Javco\Desktop\HiJackThis.lnk
[2011/05/14 15:16:03 | 000,001,864 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/05/14 15:15:57 | 000,001,547 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/05/14 15:15:57 | 000,001,352 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/05/14 15:15:57 | 000,001,326 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/14 15:15:57 | 000,001,246 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2011/05/14 15:15:57 | 000,001,210 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2011/05/14 15:15:56 | 000,002,557 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2011/05/14 15:15:56 | 000,002,519 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/14 15:15:56 | 000,002,441 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/05/14 15:15:56 | 000,002,068 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPER © Uninstall.lnk
[2011/05/14 15:15:56 | 000,002,044 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPER ©.lnk
[2011/05/14 15:15:56 | 000,001,584 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CS4.lnk
[2011/05/14 15:15:56 | 000,001,440 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Drive CS4.lnk
[2011/05/14 15:15:56 | 000,001,411 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS4.lnk
[2011/05/14 15:15:56 | 000,001,345 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/14 15:15:56 | 000,001,330 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2011/05/14 15:15:56 | 000,001,287 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS4.lnk
[2011/05/14 15:15:56 | 000,001,219 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS4.lnk
[2011/05/14 15:15:56 | 000,001,207 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CS4.lnk
[2011/05/14 15:15:56 | 000,001,196 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS4.lnk
[2011/05/14 15:15:56 | 000,001,183 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe OnLocation CS4.lnk
[2011/05/14 15:15:56 | 000,001,162 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4 (64 Bit).lnk
[2011/05/14 15:15:56 | 000,001,141 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4.lnk
[2011/05/14 15:15:56 | 000,001,135 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Encore CS4.lnk
[2011/05/14 15:15:56 | 000,001,103 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS4.lnk
[2011/05/14 15:11:50 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/05/14 15:11:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/05/14 15:11:50 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/05/14 15:11:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/05/14 15:11:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/05/14 04:41:02 | 000,001,152 | ---- | C] () -- C:\Windows\SysWow64\windrv.sys
[2011/05/13 17:04:41 | 000,001,148 | ---- | C] () -- C:\Users\Javco\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/05/05 15:03:03 | 000,295,050 | ---- | C] () -- C:\Users\Javco\Desktop\IMG_0213.JPG
[2011/05/05 00:51:31 | 2643,326,976 | ---- | C] () -- C:\Users\Javco\Desktop\n-prpcs4.iso
[2011/04/11 13:45:01 | 000,007,668 | ---- | C] () -- C:\Users\Javco\AppData\Local\Resmon.ResmonCfg
[2011/03/20 04:48:23 | 000,002,186 | -HS- | C] () -- C:\Users\Javco\AppData\Local\6bp428eo4c3th65clhdiju8r62o373573
[2011/03/20 04:48:23 | 000,002,186 | -HS- | C] () -- C:\ProgramData\6bp428eo4c3th65clhdiju8r62o373573
[2010/09/06 13:00:14 | 000,000,120 | ---- | C] () -- C:\Users\Javco\AppData\Local\Uxihilekihiba.dat
[2010/09/06 13:00:14 | 000,000,000 | ---- | C] () -- C:\Users\Javco\AppData\Local\Jfabaxuvedidaki.bin
[2010/08/12 09:55:26 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2010/08/12 09:55:26 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2010/08/12 09:55:26 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2010/08/12 09:55:26 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2010/08/12 09:55:26 | 000,000,073 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2010/08/12 09:55:26 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2010/07/29 11:24:26 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2010/07/28 20:59:16 | 000,034,308 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll
[2010/07/13 14:21:54 | 000,037,604 | ---- | C] () -- C:\Windows\scunin.dat
[2010/06/30 18:14:01 | 000,000,056 | ---- | C] () -- C:\Windows\kgt2k.INI
[2010/05/04 02:45:17 | 000,000,012 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\lipoqz.dat
[2010/05/03 02:38:37 | 000,761,639 | ---- | C] () -- C:\Windows\Counter Strike 1.6 Reloaded Uninstaller.exe
[2010/05/02 12:06:37 | 000,000,093 | ---- | C] () -- C:\Users\Javco\AppData\Local\fusioncache.dat
[2010/05/02 02:59:32 | 000,743,126 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/02 02:42:13 | 000,669,184 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2010/02/16 05:52:49 | 002,923,100 | ---- | C] () -- C:\Users\Javco\AppData\Local\train2sv.bin
[2010/01/19 00:10:30 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/01/09 16:33:56 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\IsUser11b.dll
[2009/10/10 01:08:49 | 000,221,184 | ---- | C] () -- C:\Windows\SysWow64\drivers\ServiceHelp.dll
[2009/10/10 01:08:21 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2009/10/10 01:08:21 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2009/10/10 01:07:58 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2009/10/10 01:07:58 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2009/10/10 00:58:31 | 000,007,443 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2009/10/10 00:58:27 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2009/10/10 00:58:26 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2009/08/07 20:51:34 | 000,178,430 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/05/14 15:29:30 | 000,008,520 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/01/26 20:49:04 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2009/01/19 20:53:38 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2007/01/10 08:44:26 | 001,457,024 | R--- | C] () -- C:\Windows\SysWow64\SSCProt.dll

========== LOP Check ==========

[2011/04/15 23:22:36 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\.minecraft
[2010/01/07 18:27:22 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\acccore
[2011/01/17 15:44:26 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Autodesk
[2010/03/24 18:59:25 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Bioshock
[2011/05/21 16:07:35 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\BitTorrent
[2010/06/18 21:58:52 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Braid
[2010/01/05 08:20:28 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\DAEMON Tools Lite
[2010/03/28 23:40:06 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Facebook
[2010/01/14 20:25:14 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\GrabPro
[2010/09/06 16:54:34 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Orbit
[2010/06/27 17:39:49 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Ubisoft
[2011/04/05 08:54:07 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2009/07/13 21:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SysWOW64\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\ERDNT\cache86\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\ERDNT\cache86\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\ERDNT\cache64\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/07/13 21:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\ERDNT\cache64\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/05/05 19:20:23 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/05/05 19:20:23 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/05/05 19:20:23 | 000,552,464 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: "C:\Users\Javco\AppData\Local\ljm.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [2011/05/21 15:33:58 | 000,331,776 | -HS- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2011/05/05 19:20:23 | 000,912,344 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Users\Javco\AppData\Local\ljm.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2011/05/21 15:33:58 | 000,331,776 | -HS- | M] ()
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2009/07/13 21:14:21 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2009/07/13 21:14:21 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2009/07/13 21:14:21 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2009/07/13 21:17:29 | 000,673,048 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Users\Javco\AppData\Local\ljm.exe" -a "C:\Program Files (x86)\Internet Explorer\iexplore.exe" [2011/05/21 15:33:58 | 000,331,776 | -HS- | M] ()

< End of report >
  • 0

#5
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Had to separate the Extras into two separate posts.

Extras
OTL Extras logfile created on: 5/21/2011 4:04:32 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Javco\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.00 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 82.00% Memory free
18.00 Gb Paging File | 16.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.61 Gb Total Space | 28.03 Gb Free Space | 7.52% Space Free | Partition Type: NTFS
Drive D: | 548.90 Gb Total Space | 350.89 Gb Free Space | 63.93% Space Free | Partition Type: NTFS
Drive F: | 0.03 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.73 Gb Total Space | 1.66 Gb Free Space | 44.51% Space Free | Partition Type: FAT32
Drive I: | 27.81 Gb Total Space | 1.25 Gb Free Space | 4.49% Space Free | Partition Type: FAT32

Computer Name: JAVCO-PC | User Name: Javco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3742353979-2898385441-1418632823-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe" = C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe" = C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Users\Javco\Desktop\SC2 Keygen.exe" = C:\Users\Javco\Desktop\SC2 Keygen.exe:*:Enabled:@xpsp2res.dll,-22019
"C:\Windows\SysWOW64\time.exe" = C:\Windows\SysWOW64\time.exe:*:Enabled:@xpsp2res.dll,-22019
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe" = C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe" = C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Users\Javco\Desktop\SC2 Keygen.exe" = C:\Users\Javco\Desktop\SC2 Keygen.exe:*:Enabled:@xpsp2res.dll,-22019
"C:\Windows\SysWOW64\time.exe" = C:\Windows\SysWOW64\time.exe:*:Enabled:@xpsp2res.dll,-22019


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{23170F69-40C1-2702-0912-000001000000}" = 7-Zip 9.12 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{470DA0AE-96BF-4F9C-888C-360DEF2DE71E}" = Autodesk DirectConnect 2010 R1 (64-bit)
"{47374ACF-9023-40e7-9830-ECED0DCBC3DC}" = Autodesk Maya 2011 English Documentation 64-bit
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{54E4B319-0CE0-448D-B299-EE05BC30E4D1}" = Windows Live Family Safety
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{887CB4A1-5DB4-4924-A2C6-CDCB72376CC7}" = Autodesk Maya 2011 64-bit
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B89C55B6-D6DF-415B-98CD-E6AD404AD5C5}" = Autodesk Mudbox 2011 64-bit
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DBF6B4E9-CD43-476A-895D-4D688D41CE63}" = Composite 2011 (64-bit)
"{DDE113EA-5DB0-4F68-BB58-5F67DD2308B4}" = Autodesk MatchMover 2011 64-bit
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E982A82F-7A72-4165-A05B-40F5C073E165}" = Sun VirtualBox
"CCleaner" = CCleaner
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR archiver
  • 0

#6
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
After several tries, for whatever reason, I kept getting an error when trying to finish sending the Extras text, so I've attached the Extras.txt file to this post.

Attached Files


  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK here we go - a long fix as I try to get them all in one fell swoop


Re-Run aswMBR

Click Scan

On completion of the scan

Click the Fix Button
Posted Image

Save the log as before and post in your next reply

THEN

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    [2011/05/21 15:34:10 | 000,001,618 | -HS- | M] () -- C:\Users\Javco\AppData\Local\e4p658450oy660al14dx
    [2011/05/21 15:34:10 | 000,001,618 | -HS- | M] () -- C:\ProgramData\e4p658450oy660al14dx
    [2011/05/21 15:33:58 | 000,331,776 | -HS- | M] () -- C:\Users\Javco\AppData\Local\owu.exe
    [2011/05/21 15:33:58 | 000,331,776 | -HS- | M] () -- C:\Users\Javco\AppData\Local\ljm.exe
    [2011/05/13 16:28:54 | 000,000,120 | ---- | M] () -- C:\Users\Javco\AppData\Local\Uxihilekihiba.dat
    [2011/05/13 16:28:54 | 000,000,000 | ---- | M] () -- C:\Users\Javco\AppData\Local\Jfabaxuvedidaki.bin
    [2011/03/20 04:48:23 | 000,002,186 | -HS- | C] () -- C:\Users\Javco\AppData\Local\6bp428eo4c3th65clhdiju8r62o373573
    [2011/03/20 04:48:23 | 000,002,186 | -HS- | C] () -- C:\ProgramData\6bp428eo4c3th65clhdiju8r62o373573
    [2010/09/06 13:00:14 | 000,000,120 | ---- | C] () -- C:\Users\Javco\AppData\Local\Uxihilekihiba.dat
    [2010/09/06 13:00:14 | 000,000,000 | ---- | C] () -- C:\Users\Javco\AppData\Local\Jfabaxuvedidaki.bin

    :Files
    ipconfig /flushdns /c
    C:\Users\Javco\AppData\Local\e4p658450oy660al14dx
    C:\ProgramData\e4p658450oy660al14dx
    C:\Users\Javco\AppData\Local\owu.exe
    C:\Users\Javco\AppData\Local\ljm.exe
    C:\Users\Javco\AppData\Local\Uxihilekihiba.dat
    C:\Users\Javco\AppData\Local\Jfabaxuvedidaki.bin
    C:\Users\Javco\AppData\Local\6bp428eo4c3th65clhdiju8r62o373573
    C:\ProgramData\6bp428eo4c3th65clhdiju8r62o373573
    C:\Users\Javco\AppData\Local\Uxihilekihiba.dat
    C:\Users\Javco\AppData\Local\Jfabaxuvedidaki.bin

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

FINALLY

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
  • 0

#8
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I'm not sure if I was supposed to do this, but after I ran aswMBR again (scan+fix), I was prompted to restart, which I did. While rebooting, my computer went on to a Startup Repair screen, which did its thing, and then rebooted. It warns it might take several reboots before finally finishing, but it has rebooted at least 20 times by now and I seem to be stuck on a Startup Repair loop. Out of the report it provides, these seem to be the only processes that fail.

Boot Manager Failed to find OS Loader

Repair Action: File Repair
Result: Failed. Error Code = 0x490

Repair Action: Boot Configuration Data Store Repair
Result: Failed. Error Code = 0x490

I'm looking into this myself, but any advice would definitely be appreciated.

Edited by javco, 22 May 2011 - 03:29 PM.

  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Are you able to access the safe mode menu ?

[*]Select Repair your computer.
[*]Select the operating system you want to repair, and then click Next.
[*]Select command prompt
[*]Type in the following command

Bootrec.exe /FixMbr

[*]Once finished type Exit

If that option is not available do you have the Vista CD so that we can access the recovery console ?
  • 0

#10
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I managed to get to the command prompt in another fashion, but your command worked great. Thanks.

Should I continue with your previous post, starting from OTL or aswmbr?
  • 0

Advertisements


#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yes please, it seems as though this variant on a 64bit win 7 is proving a bit of a pain with aswMBR - I will report this to the Author

Continue with the OTL step now as aswMBR will report a clean MBR.
  • 0

#12
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Alright, here are the logs.

OTL
OTL logfile created on: 5/23/2011 4:29:25 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Javco\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.00 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 81.00% Memory free
18.00 Gb Paging File | 16.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.61 Gb Total Space | 27.56 Gb Free Space | 7.40% Space Free | Partition Type: NTFS
Drive D: | 548.90 Gb Total Space | 350.89 Gb Free Space | 63.93% Space Free | Partition Type: NTFS
Drive E: | 3.42 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.73 Gb Total Space | 1.38 Gb Free Space | 37.10% Space Free | Partition Type: FAT32

Computer Name: JAVCO-PC | User Name: Javco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/21 15:59:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Javco\Downloads\OTL.exe
PRC - [2009/11/24 19:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 19:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 19:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 19:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/08/20 00:59:18 | 000,858,112 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Manager\AIManager.exe
PRC - [2009/08/20 00:55:40 | 000,196,608 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Windows\SysWOW64\AsHookDevice.exe
PRC - [2008/12/11 16:45:22 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
PRC - [2008/12/09 21:54:22 | 001,212,416 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\AI Direct Link\AsShare.exe
PRC - [2008/06/17 14:09:02 | 000,376,832 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Direct Link\AsCmd.exe


========== Modules (SafeList) ==========

MOD - [2011/05/21 15:59:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Javco\Downloads\OTL.exe
MOD - [2009/07/13 21:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/09/06 15:43:37 | 001,436,424 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010/02/01 15:45:34 | 006,159,656 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Windows\SysNative\Wacom_Tablet.exe -- (TabletServiceWacom)
SRV:64bit: - [2009/11/24 19:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV:64bit: - [2009/11/24 19:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV:64bit: - [2009/11/24 19:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV:64bit: - [2009/11/24 19:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV:64bit: - [2009/06/05 05:42:04 | 000,111,616 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AEADISRV.EXE -- (AEADIFilters)
SRV - [2011/05/17 20:18:59 | 003,275,864 | ---- | M] () [Auto | Running] -- c:\Program Files (x86)\Common Files\Akamai\netsession_win_8832f4b.dll -- (Akamai)
SRV - [2011/03/01 12:12:30 | 000,147,336 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2011/03/01 12:12:26 | 000,373,640 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/11/08 12:04:20 | 000,407,424 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
SRV - [2010/02/18 19:22:55 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/01/15 08:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/12/29 20:17:24 | 000,321,320 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/08/20 00:55:40 | 000,196,608 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysWOW64\AsHookDevice.exe -- (Device Handle Service)
SRV - [2009/07/26 07:43:14 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/04/02 00:27:27 | 000,090,112 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe -- (AsSysCtrlService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/03/01 12:12:48 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2011/02/18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/09/17 15:40:06 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2010/09/17 15:39:58 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2010/05/10 00:29:02 | 000,145,936 | ---- | M] (Sun Microsystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2010/03/04 14:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/02/24 08:06:20 | 000,726,816 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364)
DRV:64bit: - [2010/01/24 15:32:24 | 000,018,216 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2010/01/05 03:07:42 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/11/24 19:50:05 | 000,022,096 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2009/11/24 19:49:56 | 000,065,616 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2009/09/21 16:29:22 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2009/08/30 22:09:33 | 000,112,240 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID)
DRV:64bit: - [2009/07/15 23:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 16:35:35 | 000,620,544 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/05 05:42:04 | 000,475,136 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ADIHdAud.sys -- (ADIHdAudAddService)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/02/06 19:42:12 | 000,061,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2008/07/26 15:26:34 | 000,050,072 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:64bit: - [2008/07/26 15:22:34 | 002,624,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LV302V64.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV:64bit: - [2008/02/06 03:00:00 | 000,054,480 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2007/02/16 11:12:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2006/12/12 15:37:00 | 000,362,496 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr6164.sys -- (rt61x64)
DRV:64bit: - [2005/10/20 16:01:12 | 000,222,720 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RT2500.sys -- (RT2500)
DRV:64bit: - [2005/06/14 14:01:16 | 000,296,448 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\hardlock.sys -- (Hardlock)
DRV - [2010/09/17 15:40:06 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys -- (LMIInfo)
DRV - [2010/07/15 15:55:02 | 000,086,584 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:2.3.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://slirsredirect...ir=2706&query="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/05 19:20:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/05 19:20:23 | 000,000,000 | ---D | M]

[2009/12/30 08:11:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Javco\AppData\Roaming\Mozilla\Extensions
[2011/05/22 18:27:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\extensions
[2011/04/16 01:44:19 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\extensions\[email protected]
[2010/01/11 23:56:54 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\extensions\[email protected]
[2010/01/07 18:26:13 | 000,001,490 | ---- | M] () -- C:\Users\Javco\AppData\Roaming\Mozilla\Firefox\Profiles\gb7oir7h.default\searchplugins\AIM Search.xml
[2011/05/23 16:23:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/01/10 06:32:45 | 000,000,000 | ---D | M] (OneClick YouTube Downloader) -- C:\PROGRAM FILES (X86)\ORBITDOWNLOADER\ADDONS\ONECLICKYOUTUBEDOWNLOADER
[2010/01/07 18:26:13 | 000,001,490 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\AIM Search.xml

O1 HOSTS File: ([2011/05/23 16:26:57 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane..._2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 65.32.5.111 65.32.5.112
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/06 15:31:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - Unable to obtain root file information for disk D:\
O32 - AutoRun File - [2009/08/04 12:00:00 | 000,000,028 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/23 16:26:56 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/05/22 15:26:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\Apple
[2011/05/21 15:42:36 | 000,000,000 | ---D | C] -- C:\Users\Javco\Desktop\New folder (2)
[2011/05/21 15:36:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\Desktop\New folder
[2011/05/21 14:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\M5
[2011/05/19 18:07:22 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/05/19 17:54:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\Adobe
[2011/05/19 17:09:19 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/05/19 16:48:37 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\Apple Computer
[2011/05/19 16:46:36 | 000,000,000 | ---D | C] -- C:\Users\Javco\Desktop\GooredFix Backups
[2011/05/19 16:17:51 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 Recovery
[2011/05/15 09:46:38 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Local\LogMeIn
[2011/05/15 09:46:32 | 000,033,152 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIport.dll
[2011/05/15 09:46:31 | 000,087,456 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIRfsClientNP.dll
[2011/05/15 09:46:31 | 000,072,216 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys
[2011/05/15 09:46:29 | 000,080,768 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIinit.dll
[2011/05/15 09:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\LogMeIn
[2011/05/15 09:46:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn
[2011/05/14 17:45:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/05/14 17:45:18 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/05/14 17:31:09 | 000,000,000 | ---D | C] -- C:\!KillBox
[2011/05/14 17:28:50 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/05/14 17:28:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HijackThis
[2011/05/14 15:21:13 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/05/14 15:16:05 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinAce
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Swiff Player
[2011/05/14 15:16:04 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPER © Version 2010.bld.38 (May 2, 2010)
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sun VirtualBox
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Starcraft
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SoundMAX
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skype
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pixologic
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orbit
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Next Video Converter
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/05/14 15:16:03 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mass Effect 2
[2011/05/14 15:16:02 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mass Effect
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JMicron Technology Corp
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Instant Wireless
[2011/05/14 15:16:01 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Download Manager
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent
[2011/05/14 15:16:00 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! Antivirus
[2011/05/14 15:15:59 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
[2011/05/14 15:15:59 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS
[2011/05/14 15:15:59 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aimersoft
[2011/05/14 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AIM
[2011/05/14 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe
[2011/05/14 15:15:58 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
[2011/05/14 15:15:57 | 000,000,000 | ---D | C] -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/05/14 15:11:50 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/05/14 15:11:50 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/05/14 15:11:50 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/05/14 15:11:46 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/05/14 14:52:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/13 17:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/13 17:04:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware2
[2011/05/08 16:04:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/08 16:03:48 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/08 16:03:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/05/08 16:03:48 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/08 16:02:41 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/08 16:02:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour

========== Files - Modified Within 30 Days ==========

[2012/10/20 00:48:55 | 2643,326,976 | ---- | M] () -- C:\Users\Javco\Desktop\n-prpcs4.iso
[2011/05/23 16:28:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/23 16:28:28 | 2945,802,239 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/23 16:27:43 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/23 16:27:43 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/23 16:26:57 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2011/05/23 05:26:10 | 000,632,453 | ---- | M] () -- C:\Users\Javco\Desktop\wallpaper-797100.jpg
[2011/05/22 18:26:42 | 000,727,172 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/05/22 18:26:42 | 000,623,890 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/05/22 18:26:42 | 000,107,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/05/22 15:58:21 | 000,000,512 | ---- | M] () -- C:\Users\Javco\Desktop\MBR.dat
[2011/05/17 16:36:32 | 000,000,241 | ---- | M] () -- C:\Users\Javco\Desktop\gt1.dxr
[2011/05/15 09:46:28 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/05/14 17:50:05 | 000,202,422 | ---- | M] () -- C:\Users\Javco\Desktop\cc_20110514_174858.reg
[2011/05/14 17:28:50 | 000,002,957 | ---- | M] () -- C:\Users\Javco\Desktop\HiJackThis.lnk
[2011/05/14 04:41:02 | 000,001,152 | ---- | M] () -- C:\Windows\SysWow64\windrv.sys
[2011/05/13 17:04:41 | 000,001,148 | ---- | M] () -- C:\Users\Javco\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/05/05 15:03:12 | 000,295,050 | ---- | M] () -- C:\Users\Javco\Desktop\IMG_0213.JPG
[2011/05/02 22:02:04 | 000,014,697 | ---- | M] () -- C:\Windows\SysNative\Wacom_Tablet.dat

========== Files Created - No Company Name ==========

[2011/05/23 05:26:10 | 000,632,453 | ---- | C] () -- C:\Users\Javco\Desktop\wallpaper-797100.jpg
[2011/05/21 15:59:08 | 000,000,512 | ---- | C] () -- C:\Users\Javco\Desktop\MBR.dat
[2011/05/17 16:33:16 | 000,000,241 | ---- | C] () -- C:\Users\Javco\Desktop\gt1.dxr
[2011/05/15 09:46:28 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/05/14 17:49:10 | 000,202,422 | ---- | C] () -- C:\Users\Javco\Desktop\cc_20110514_174858.reg
[2011/05/14 17:28:50 | 000,002,957 | ---- | C] () -- C:\Users\Javco\Desktop\HiJackThis.lnk
[2011/05/14 15:16:03 | 000,001,864 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/05/14 15:15:57 | 000,001,547 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/05/14 15:15:57 | 000,001,352 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/05/14 15:15:57 | 000,001,326 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/05/14 15:15:57 | 000,001,246 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2011/05/14 15:15:57 | 000,001,210 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2011/05/14 15:15:56 | 000,002,557 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2011/05/14 15:15:56 | 000,002,519 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/14 15:15:56 | 000,002,441 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/05/14 15:15:56 | 000,002,068 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPER © Uninstall.lnk
[2011/05/14 15:15:56 | 000,002,044 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPER ©.lnk
[2011/05/14 15:15:56 | 000,001,584 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CS4.lnk
[2011/05/14 15:15:56 | 000,001,440 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Drive CS4.lnk
[2011/05/14 15:15:56 | 000,001,411 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS4.lnk
[2011/05/14 15:15:56 | 000,001,345 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/05/14 15:15:56 | 000,001,330 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2011/05/14 15:15:56 | 000,001,287 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS4.lnk
[2011/05/14 15:15:56 | 000,001,219 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS4.lnk
[2011/05/14 15:15:56 | 000,001,207 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CS4.lnk
[2011/05/14 15:15:56 | 000,001,196 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS4.lnk
[2011/05/14 15:15:56 | 000,001,183 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe OnLocation CS4.lnk
[2011/05/14 15:15:56 | 000,001,162 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4 (64 Bit).lnk
[2011/05/14 15:15:56 | 000,001,141 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4.lnk
[2011/05/14 15:15:56 | 000,001,135 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Encore CS4.lnk
[2011/05/14 15:15:56 | 000,001,103 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS4.lnk
[2011/05/14 15:11:50 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/05/14 15:11:50 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/05/14 15:11:50 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/05/14 15:11:50 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/05/14 15:11:50 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/05/14 04:41:02 | 000,001,152 | ---- | C] () -- C:\Windows\SysWow64\windrv.sys
[2011/05/13 17:04:41 | 000,001,148 | ---- | C] () -- C:\Users\Javco\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/05/05 15:03:03 | 000,295,050 | ---- | C] () -- C:\Users\Javco\Desktop\IMG_0213.JPG
[2011/05/05 00:51:31 | 2643,326,976 | ---- | C] () -- C:\Users\Javco\Desktop\n-prpcs4.iso
[2011/04/11 13:45:01 | 000,007,668 | ---- | C] () -- C:\Users\Javco\AppData\Local\Resmon.ResmonCfg
[2010/08/12 09:55:26 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\sysprs7.dll
[2010/08/12 09:55:26 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2010/08/12 09:55:26 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2010/08/12 09:55:26 | 000,000,205 | ---- | C] () -- C:\Windows\SysWow64\lsprst7.dll
[2010/08/12 09:55:26 | 000,000,073 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2010/08/12 09:55:26 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2010/07/29 11:24:26 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2010/07/28 20:59:16 | 000,034,308 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll
[2010/07/13 14:21:54 | 000,037,604 | ---- | C] () -- C:\Windows\scunin.dat
[2010/06/30 18:14:01 | 000,000,056 | ---- | C] () -- C:\Windows\kgt2k.INI
[2010/05/04 02:45:17 | 000,000,012 | ---- | C] () -- C:\Users\Javco\AppData\Roaming\lipoqz.dat
[2010/05/03 02:38:37 | 000,761,639 | ---- | C] () -- C:\Windows\Counter Strike 1.6 Reloaded Uninstaller.exe
[2010/05/02 12:06:37 | 000,000,093 | ---- | C] () -- C:\Users\Javco\AppData\Local\fusioncache.dat
[2010/05/02 02:59:32 | 000,743,126 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/02 02:42:13 | 000,669,184 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2010/02/16 05:52:49 | 002,923,100 | ---- | C] () -- C:\Users\Javco\AppData\Local\train2sv.bin
[2010/01/19 00:10:30 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/01/09 16:33:56 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\IsUser11b.dll
[2009/10/10 01:08:49 | 000,221,184 | ---- | C] () -- C:\Windows\SysWow64\drivers\ServiceHelp.dll
[2009/10/10 01:08:21 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2009/10/10 01:08:21 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2009/10/10 01:07:58 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2009/10/10 01:07:58 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2009/10/10 00:58:31 | 000,007,443 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2009/10/10 00:58:27 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2009/10/10 00:58:26 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2009/08/07 20:51:34 | 000,178,430 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/05/14 15:29:30 | 000,008,520 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/01/26 20:49:04 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2009/01/19 20:53:38 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2007/01/10 08:44:26 | 001,457,024 | R--- | C] () -- C:\Windows\SysWow64\SSCProt.dll

========== LOP Check ==========

[2011/04/15 23:22:36 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\.minecraft
[2010/01/07 18:27:22 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\acccore
[2011/01/17 15:44:26 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Autodesk
[2010/03/24 18:59:25 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Bioshock
[2011/05/22 22:03:46 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\BitTorrent
[2010/06/18 21:58:52 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Braid
[2010/01/05 08:20:28 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\DAEMON Tools Lite
[2010/03/28 23:40:06 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Facebook
[2010/01/14 20:25:14 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\GrabPro
[2010/09/06 16:54:34 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Orbit
[2010/06/27 17:39:49 | 000,000,000 | ---D | M] -- C:\Users\Javco\AppData\Roaming\Ubisoft
[2011/04/05 08:54:07 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >





Extras
OTL Extras logfile created on: 5/23/2011 4:29:26 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Javco\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

9.00 Gb Total Physical Memory | 7.00 Gb Available Physical Memory | 81.00% Memory free
18.00 Gb Paging File | 16.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.61 Gb Total Space | 27.56 Gb Free Space | 7.40% Space Free | Partition Type: NTFS
Drive D: | 548.90 Gb Total Space | 350.89 Gb Free Space | 63.93% Space Free | Partition Type: NTFS
Drive E: | 3.42 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 3.73 Gb Total Space | 1.38 Gb Free Space | 37.10% Space Free | Partition Type: FAT32

Computer Name: JAVCO-PC | User Name: Javco | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe" = C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe" = C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Users\Javco\Desktop\SC2 Keygen.exe" = C:\Users\Javco\Desktop\SC2 Keygen.exe:*:Enabled:@xpsp2res.dll,-22019
"C:\Windows\SysWOW64\time.exe" = C:\Windows\SysWOW64\time.exe:*:Enabled:@xpsp2res.dll,-22019
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe" = C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe" = C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Users\Javco\Desktop\SC2 Keygen.exe" = C:\Users\Javco\Desktop\SC2 Keygen.exe:*:Enabled:@xpsp2res.dll,-22019
"C:\Windows\SysWOW64\time.exe" = C:\Windows\SysWOW64\time.exe:*:Enabled:@xpsp2res.dll,-22019


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{23170F69-40C1-2702-0912-000001000000}" = 7-Zip 9.12 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{470DA0AE-96BF-4F9C-888C-360DEF2DE71E}" = Autodesk DirectConnect 2010 R1 (64-bit)
"{47374ACF-9023-40e7-9830-ECED0DCBC3DC}" = Autodesk Maya 2011 English Documentation 64-bit
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{54E4B319-0CE0-448D-B299-EE05BC30E4D1}" = Windows Live Family Safety
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{887CB4A1-5DB4-4924-A2C6-CDCB72376CC7}" = Autodesk Maya 2011 64-bit
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B89C55B6-D6DF-415B-98CD-E6AD404AD5C5}" = Autodesk Mudbox 2011 64-bit
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DBF6B4E9-CD43-476A-895D-4D688D41CE63}" = Composite 2011 (64-bit)
"{DDE113EA-5DB0-4F68-BB58-5F67DD2308B4}" = Autodesk MatchMover 2011 64-bit
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{E982A82F-7A72-4165-A05B-40F5C073E165}" = Sun VirtualBox
"CCleaner" = CCleaner
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2AD89908-0987-4B9E-8AB4-905899E4D754}_is1" = Next Video Converter 3.50
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3880FBF3-6227-41AA-B53F-A8EA05216CC1}" = ILLUSION アンリミテッドボツ
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2011.0.0
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4AF95DE2-B54D-4C3F-9494-FD3B558E2C2D}" = AI Manager
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{52B65911-1559-4ED5-9461-46957FDD48CD}" = Borderlands
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{566BB41D-F006-4956-A5D3-94D8DFFA7F51}" = Adobe Setup
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
"{6084D038-3401-4C9D-A216-86E6EEA25AFB}" = ZBrush3
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{65179FD8-04C0-40A7-87FC-007F2CD5BF1E}" = LogMeIn
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6F6594CB-DA1B-4FFB-B397-CACE3D5F668B}" = Windows Live Movie Maker Beta
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8CE08C3C-8FF4-45D9-925E-4F3CE2D7FA7D}" = Adobe Setup
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype™
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla
"{A99C800B-C5F3-48B9-AE2F-A9BE1C553111}" = ILLUSION 勇者からは逃げられない!
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B78823CD-488F-43B4-80D6-FAEADAE40EC4}" = Instant Wireless USB Adapter
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C312984C-E386-4C2D-B33E-7B54355FB16E}" = AI Direct Link
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{DCDC9660-55C9-4FBA-9840-72C54D39138D}" = CPU Level Up
"{DE3BB35E-C0CE-4CA1-9CB4-CD9E69364BD9}" = Adobe Premiere Pro CS4
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F112F66E-25CA-42DD-983C-6118EB38F606}" = Microsoft Games for Windows - LIVE
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_26b63376f4efc354dae41af6b5e3343" = Adobe Premiere Pro CS4
"Adobe_2a31ae7a5c43ff52d8577782dd34e04" = Adobe Illustrator CS4
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"AIM_7" = AIM 7
"Aimersoft DVD Creator_is1" = Aimersoft DVD Creator(Build 2.2.7.3)
"Akamai" = Akamai NetSession Interface
"avast!" = avast! Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BitTorrent" = BitTorrent
"Call of Duty Modern Warfare 2_is1" = Call of Duty Modern Warfare 2
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Counter Strike 1.6 Reloaded" = Counter Strike 1.6 Reloaded
"Download Manager" = Download Manager 2.3.10
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Gears of War_is1" = Gears of War
"hon" = Heroes of Newerth
"Host OpenAL (ADI)" = Host OpenAL (ADI)
"InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype™
"InstallShield_{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox (3.6.17)" = Mozilla Firefox (3.6.17)
"Orbit_is1" = Orbit Downloader
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Starcraft" = Starcraft
"StarCraft II" = StarCraft II
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Steam App 2130" = Dark Messiah Might and Magic Multi-Player
"Steam App 400" = Portal
"Steam App 440" = Team Fortress 2
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 564" = Left 4 Dead 2 Add-on Support
"Steam App 630" = Alien Swarm
"Steam App 70" = Half-Life
"SUPER ©" = SUPER © Version 2010.bld.38 (May 2, 2010)
"Swiff Player_is1" = Swiff Player 1.5
"VLC media player" = VLC media player 1.0.3
"Wacom Tablet Driver" = Wacom Tablet
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"WinAce Archiver" = WinAce Archiver
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 2/28/2010 2:36:09 AM | Computer Name = Javco-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\Cursors\aero_busy.ani failed, 00000005.

Error - 1/5/2009 7:08:39 PM | Computer Name = Javco-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://s256.hotfile....o Islands 4.iso
failed, 00000084.

Error - 1/5/2009 7:44:06 PM | Computer Name = Javco-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://s274.hotfile....o Islands 4.iso
failed, 00000084.

Error - 9/28/2010 6:32:17 PM | Computer Name = Javco-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\Cursors\aero_busy.ani failed, 00000005.

Error - 11/19/2010 12:52:09 PM | Computer Name = Javco-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\Cursors\aero_busy.ani failed, 00000005.

Error - 12/14/2010 2:06:10 PM | Computer Name = Javco-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\Cursors\aero_busy.ani failed, 00000005.

[ Application Events ]
Error - 5/11/2011 7:27:50 PM | Computer Name = Javco-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Autodesk\Composite
2011\python\lib\distutils\command\wininst-8_d.exe". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 5/11/2011 7:29:09 PM | Computer Name = Javco-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 5/11/2011 10:21:10 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/12/2011 4:21:39 AM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/12/2011 2:51:02 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/12/2011 8:52:45 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/13/2011 4:16:17 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/13/2011 4:27:26 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/13/2011 4:43:34 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 5/13/2011 4:57:15 PM | Computer Name = Javco-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download....uthrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ System Events ]
Error - 5/20/2011 4:56:47 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 5/21/2011 1:41:05 PM | Computer Name = Javco-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:23:34 AM on ?5/?21/?2011 was unexpected.

Error - 5/21/2011 1:41:15 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7000
Description = The Hardlock service failed to start due to the following error: %%577

Error - 5/21/2011 4:25:54 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7000
Description = The Hardlock service failed to start due to the following error: %%577

Error - 5/22/2011 3:33:27 AM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the LanmanServer service.

Error - 5/22/2011 3:33:57 AM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 5/22/2011 3:06:39 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7000
Description = The Hardlock service failed to start due to the following error: %%577

Error - 5/22/2011 6:13:20 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7000
Description = The Hardlock service failed to start due to the following error: %%577

Error - 5/23/2011 4:22:56 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7000
Description = The Hardlock service failed to start due to the following error: %%577

Error - 5/23/2011 4:28:44 PM | Computer Name = Javco-PC | Source = Service Control Manager | ID = 7000
Description = The Hardlock service failed to start due to the following error: %%577


< End of report >





MBAM
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6657

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

5/23/2011 4:37:12 PM
mbam-log-2011-05-23 (16-37-12).txt

Scan type: Quick scan
Objects scanned: 177504
Time elapsed: 1 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Javco\AppData\Local\ljm.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Javco\AppData\Local\ljm.exe" -a "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Javco\AppData\Local\ljm.exe" -a "C:\Program Files (x86)\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Nice MBAM got the outstanding registry entries - what problems are you experiencing now ?
  • 0

#14
javco

javco

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Well, since the aswmbr/startup repair issue before, I noticed I wasn't getting any popups. And I just ran a few google searches, opening all the links on the first page and they all actually took me to where they should. It seems like the beast has been slain. You sir, are worthy of having a bronze statue erected in your likeness, with a sword and shield in-hand, bearing the words "Sir Essexboy - Slayer of Viruses and All Things Malware."

Thanks for all the help!
  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Thank you for your kind words :unsure:


Subject to no further problems :yes:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :)

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version

SPRING CLEAN

To manually create a new Restore Point

  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create

Now we can purge the infected ones

  • GoStart > All programs > Accessories > system tools page
  • Select Performance Information and Tools
  • Right click Disc cleanup an select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Posted Image Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP