I inherited the Google Redirect thing a little while ago and at first I "solved" my problem by changing browser from IE to Firefox....seemed to work ok there but over time it went back to the way it was on IE...I then moved to Google Chrome as I was checking out new browsers anyway and it was fine for about a month?
Its back and is frustrating...
I have read a few threads on this forum and tried TDSSKiller to no avail...can anyone helps me please
Heres the OTL log:
OTL logfile created on: 15/05/2011 1:11:29 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\pc\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 63.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 293.26 Gb Free Space | 62.96% Space Free | Partition Type: NTFS
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/15 13:10:59 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
PRC - [2011/05/13 13:21:28 | 001,407,280 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\pc\Desktop\TDSSKiller.exe
PRC - [2011/04/05 14:19:16 | 002,692,024 | ---- | M] (Symantec Corporation) -- C:\ProgramData\Norton\NUA.exe
PRC - [2011/03/28 16:15:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/28 16:15:29 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/03/23 04:37:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2010/03/15 11:26:37 | 001,039,360 | ---- | M] () -- C:\Program Files\Winrar\WinRAR.exe
PRC - [2010/02/26 10:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\4.3.0.5\ccsvchst.exe
PRC - [2010/01/18 10:24:08 | 001,733,120 | R--- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2009/07/27 12:10:00 | 001,983,816 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2009/04/11 16:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/11 16:27:20 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2008/09/30 17:46:18 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2008/09/30 17:46:12 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2006/12/23 18:05:20 | 000,143,360 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006/12/23 18:04:42 | 000,905,216 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2006/11/02 22:35:35 | 000,176,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpcumi.exe
========== Modules (SafeList) ==========
MOD - [2011/05/15 13:10:59 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
MOD - [2011/04/21 03:00:24 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.5570_none_509463cabcb6ef2a\msvcr90.dll
MOD - [2011/04/21 03:00:24 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.5570_none_509463cabcb6ef2a\msvcp90.dll
MOD - [2010/09/21 05:26:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\4.3.0.5\asoehook.dll
MOD - [2010/09/01 01:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/02/26 10:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe -- (N360)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/01/21 12:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2011/04/16 06:29:05 | 000,802,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110419.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/04/01 17:07:59 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/04/01 17:07:59 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/03/31 14:00:53 | 001,393,144 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110429.037\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/03/31 14:00:53 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110429.037\NAVENG.SYS -- (NAVENG)
DRV - [2011/03/15 04:58:33 | 000,353,912 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110429.002\IDSvix86.sys -- (IDSVix86)
DRV - [2010/10/27 11:11:56 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/10/27 10:55:05 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/09/08 17:34:53 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/07/10 05:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/06/17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/05/06 14:01:59 | 000,339,504 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\N360\0403000.005\SYMTDIV.SYS -- (SYMTDIv)
DRV - [2010/04/29 15:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0403000.005\Ironx86.SYS -- (SymIRON)
DRV - [2010/04/22 13:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\N360\0403000.005\SYMEFA.SYS -- (SymEFA)
DRV - [2010/04/22 12:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0403000.005\SRTSP.SYS -- (SRTSP)
DRV - [2010/04/22 12:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0403000.005\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/26 10:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0403000.005\ccHPx86.sys -- (ccHP)
DRV - [2010/01/11 20:02:44 | 001,119,232 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/11/27 17:45:22 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C60x86.sys -- (L1C)
DRV - [2009/10/15 13:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\N360\0403000.005\SYMDS.SYS -- (SymDS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 1D 22 DC 7F F6 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://ninemsn.com.au/"
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/08/28 18:45:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/10/27 10:55:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/15 08:52:36 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/15 08:52:36 | 000,000,000 | ---D | M]
[2011/02/20 22:33:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\Mozilla\Extensions
[2011/05/15 09:02:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\qmy5mwfk.default\extensions
[2011/02/21 18:51:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\qmy5mwfk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/19 11:22:51 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\qmy5mwfk.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/03/19 11:19:49 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\qmy5mwfk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/19 11:21:11 | 000,000,000 | ---D | M] (Redirect Remover) -- C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\qmy5mwfk.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2011/02/20 22:33:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/27 10:55:37 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2010/08/28 18:45:45 | 000,000,000 | ---D | M] (Norton IPS) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2011/03/23 04:38:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2011/05/15 12:52:06 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [VIAAUD] File not found
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [NortonUpdateAgent] C:\ProgramData\Norton\NUA.exe (Symantec Corporation)
O4 - Startup: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg...l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\pc\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 07:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ba836a32-317a-11e0-847a-406186f3e578}\Shell - "" = AutoRun
O33 - MountPoints2\{ba836a32-317a-11e0-847a-406186f3e578}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\{d7f051af-e0a5-11df-b946-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d7f051af-e0a5-11df-b946-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/15 13:10:57 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2011/05/15 13:02:07 | 001,407,280 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\pc\Desktop\TDSSKiller.exe
[2011/05/15 13:00:46 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\GooredFix Backups
[2011/05/15 13:00:38 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Users\pc\Desktop\GooredFix.exe
[2011/05/15 12:57:47 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{1B74B227-BABC-4B1E-927E-EE17FF5B3206}
[2011/05/15 12:51:59 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/05/14 07:02:22 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{EE23E3DF-A4AE-441C-A14D-956B5A298FB5}
[2011/05/13 19:01:48 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{9A2E7B46-DC60-44D4-A84B-E0CB6C949F38}
[2011/05/13 07:01:14 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{6237C9CB-F2ED-4D7A-9A9F-D59F7B8549BA}
[2011/05/12 07:03:34 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{2A38AFB8-DC2B-4FE7-BB22-A0C25DF0F114}
[2011/05/11 19:03:00 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{94603D46-1D4C-4CD4-B485-D52C665E71A2}
[2011/05/11 18:00:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/11 17:59:35 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/11 17:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/11 17:56:02 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/11 17:55:38 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/05/11 07:02:25 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{9B7BC8F1-6D47-4A47-A272-FCFA1D074491}
[2011/05/10 19:01:51 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{FC394DD6-3E54-4E53-AE12-03B56501BC13}
[2011/05/04 17:22:54 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{996E0334-AC8F-40F3-A14E-09B01B393862}
[2011/05/04 05:22:21 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{6252B7F2-5434-4FD5-AD60-103B9D1FCDF3}
[2011/05/03 17:21:35 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{8692AC28-A3CE-4647-A922-0877694B35A7}
[2011/05/03 05:21:01 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{6EC451ED-80BA-4F58-B0F2-5F41F8810E17}
[2011/05/02 17:20:27 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{834997CA-BB34-4D60-90F6-5478F5E14C95}
[2011/05/02 05:19:53 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{23AE77A7-887B-4F1D-A0E3-62DD7EB547EC}
[2011/05/01 17:19:18 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{FA0FA6DF-E73F-48BC-9BD3-5D5AB78755D9}
[2011/05/01 05:18:44 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{FCB6F5EF-44BE-4DCB-8EF7-55F8FD3186B7}
[2011/04/30 23:11:28 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonIJScan
[2011/04/30 23:11:27 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Canon
[2011/04/30 22:44:33 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Avira
[2011/04/30 17:18:11 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{AA3910BA-085E-4BB4-90BC-7F745F3D5C7F}
[2011/04/30 11:53:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/04/30 11:53:01 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/04/30 11:52:59 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/04/30 11:52:59 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/04/30 11:52:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/04/30 11:52:57 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/04/30 05:17:37 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{BD326615-C618-4958-ADA5-7C8091C9E098}
[2011/04/29 17:17:03 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{336B9840-981B-48F6-B32F-4893C17E55C6}
[2011/04/29 05:16:30 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{4CBA3D66-8E05-4322-9C2F-DE2354C3E2D5}
[2011/04/28 17:15:51 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{6DEEA9D1-362B-408B-BBC8-ED128AB7912E}
[2011/04/27 15:43:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{264A6C8B-5067-4EB1-BD30-5F4931055EAC}
[2011/04/26 20:46:56 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{EB2AA585-D3E3-4EE6-BE97-4413F1600E17}
[2011/04/25 22:34:31 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{594AD3DA-C440-4F17-9A68-19090DD6C272}
[2011/04/25 10:33:58 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{8A30DCB5-0A2E-4DDD-BD0A-72E23A429BA9}
[2011/04/24 22:32:48 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{AD1C6D00-5D3C-4470-97E3-F3FB6406BBA2}
[2011/04/23 21:40:31 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{C20A84AE-B1C6-4AC2-80AC-0F63C46112FF}
[2011/04/23 09:39:57 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{9EC803BE-BBA0-48ED-BFBE-19F7ADD4A393}
[2011/04/21 23:11:15 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{764DA173-C74B-47FC-AE3C-12B1C2A55045}
[2011/04/21 11:10:41 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{0C4CECA0-85AE-4807-AE82-14D0E1B0752E}
[2011/04/20 23:10:08 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{025CDCB2-862E-4494-A0D7-EAE48EF198DF}
[2011/04/19 11:18:02 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{DECEE91F-8E23-4DF7-9BB0-95DDA7EFF163}
[2011/04/18 21:37:37 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{E9A18667-DA9C-4BF2-A191-B7E8BF7A6FF7}
[2011/04/17 13:44:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/04/16 20:57:32 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{9D87F24E-552E-420E-8986-DF8E3D1DD86F}
[2011/04/16 11:05:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
[2011/04/16 11:05:24 | 000,626,688 | ---- | C] (On2.com) -- C:\Windows\System32\vp7vfw.dll
[2011/04/16 11:05:23 | 000,000,000 | ---D | C] -- C:\Program Files\VSO
[2011/04/15 18:48:54 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\{DD86BE3C-1EEB-4970-ACC1-EAE70DFD9B15}
[2011/04/12 15:36:17 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\pc\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2011/05/15 13:10:59 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2011/05/15 13:02:05 | 000,001,940 | ---- | M] () -- C:\Users\pc\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/15 13:01:28 | 001,280,208 | ---- | M] () -- C:\Users\pc\Desktop\tdsskiller.zip
[2011/05/15 13:01:03 | 000,608,760 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/05/15 13:01:03 | 000,108,268 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/05/15 13:00:30 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Users\pc\Desktop\GooredFix.exe
[2011/05/15 12:55:59 | 000,069,261 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2011/05/15 12:55:58 | 000,069,261 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/05/15 12:55:03 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/15 12:55:03 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/15 12:55:03 | 000,000,304 | -HS- | M] () -- C:\Windows\tasks\XDSA.job
[2011/05/15 12:54:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/15 12:54:42 | 3220,430,848 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/15 12:52:06 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2011/05/15 09:21:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1759715684-315256926-4125069295-1000UA.job
[2011/05/14 23:21:33 | 000,001,989 | ---- | M] () -- C:\Users\pc\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/14 23:21:32 | 000,002,027 | ---- | M] () -- C:\Users\pc\Desktop\Google Chrome.lnk
[2011/05/14 19:15:11 | 000,001,057 | ---- | M] () -- C:\Users\pc\AppData\Roaming\vso_ts_preview.xml
[2011/05/14 19:12:34 | 000,026,624 | ---- | M] () -- C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/14 17:21:00 | 000,000,844 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1759715684-315256926-4125069295-1000Core.job
[2011/05/13 13:21:28 | 001,407,280 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\pc\Desktop\TDSSKiller.exe
[2011/05/11 18:00:09 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 11:53:14 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011/04/21 21:12:12 | 000,000,800 | ---- | M] () -- C:\Users\pc\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2011/04/17 13:44:06 | 000,000,859 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/17 13:42:42 | 020,533,281 | ---- | M] () -- C:\Users\pc\Documents\vlc-1.1.9-win32.exe
[2011/04/16 11:05:29 | 000,001,009 | ---- | M] () -- C:\Users\pc\Application Data\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk
[2011/04/16 11:05:28 | 000,001,017 | ---- | M] () -- C:\Users\pc\Desktop\ConvertXtoDVD 4.lnk
========== Files Created - No Company Name ==========
[2011/05/15 13:01:22 | 001,280,208 | ---- | C] () -- C:\Users\pc\Desktop\tdsskiller.zip
[2011/05/13 19:26:52 | 000,001,940 | ---- | C] () -- C:\Users\pc\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/11 18:00:08 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 11:53:14 | 000,001,847 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011/04/17 13:44:05 | 000,000,859 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/17 13:42:17 | 020,533,281 | ---- | C] () -- C:\Users\pc\Documents\vlc-1.1.9-win32.exe
[2011/04/16 11:05:29 | 000,001,009 | ---- | C] () -- C:\Users\pc\Application Data\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk
[2011/04/16 11:05:28 | 000,001,017 | ---- | C] () -- C:\Users\pc\Desktop\ConvertXtoDVD 4.lnk
[2011/04/12 15:36:17 | 000,087,608 | ---- | C] () -- C:\Users\pc\AppData\Roaming\inst.exe
[2011/04/12 15:36:17 | 000,007,887 | ---- | C] () -- C:\Users\pc\AppData\Roaming\pcouffin.cat
[2011/04/12 15:36:17 | 000,001,144 | ---- | C] () -- C:\Users\pc\AppData\Roaming\pcouffin.inf
[2011/04/12 13:54:07 | 000,001,057 | ---- | C] () -- C:\Users\pc\AppData\Roaming\vso_ts_preview.xml
[2011/02/19 00:09:40 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/02/18 23:42:57 | 000,090,112 | RHS- | C] () -- C:\Windows\System32\WpdConns8.dll
[2011/02/13 16:48:32 | 002,255,360 | ---- | C] () -- C:\Windows\System32\libavcodec.dll
[2011/02/13 16:48:32 | 000,395,776 | ---- | C] () -- C:\Windows\System32\libmplayer.dll
[2011/02/13 16:48:32 | 000,262,144 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2011/02/13 16:48:32 | 000,112,640 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2010/12/18 10:51:54 | 000,001,456 | ---- | C] () -- C:\Users\pc\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/10/26 14:12:15 | 000,069,261 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/10/26 14:12:14 | 000,069,261 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2010/10/26 13:22:59 | 000,000,680 | ---- | C] () -- C:\Users\pc\AppData\Local\d3d9caps.dat
[2010/09/21 20:33:57 | 000,026,624 | ---- | C] () -- C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/18 14:56:48 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/09/18 14:55:16 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/08/27 21:51:55 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006/11/02 22:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 22:47:37 | 003,600,480 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 22:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 20:33:01 | 000,608,760 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 20:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 20:33:01 | 000,108,268 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 20:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 20:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 18:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 18:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 17:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 17:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ==========
[2011/04/30 23:11:28 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Canon
[2011/05/10 19:14:09 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\DMCache
[2011/05/14 13:24:34 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\IDM
[2010/08/27 21:22:06 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\OpenOffice.org
[2010/10/27 17:59:42 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Tific
[2011/05/14 01:19:14 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\uTorrent
[2011/05/14 19:15:12 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Vso
[2011/02/18 23:42:56 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\WinAVI
[2011/05/15 12:53:42 | 000,032,618 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/05/15 12:55:03 | 000,000,304 | -HS- | M] () -- C:\Windows\Tasks\XDSA.job
========== Purity Check ==========
< End of report >
And the extras log :
OTL Extras logfile created on: 15/05/2011 1:11:29 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\pc\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 63.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 293.26 Gb Free Space | 62.96% Space Free | Partition Type: NTFS
Computer Name: PC-PC | User Name: pc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A223176-3D9A-4D34-94FE-FEF302E4BA00}" = lport=2869 | protocol=6 | dir=in | app=system |
"{30AD2CB2-E645-40B4-A3EC-3B6DEBEE6190}" = lport=1900 | protocol=17 | dir=in | name=udp 1900 |
"{5E933B62-C721-40B0-A644-9B5E26DE5346}" = lport=2869 | protocol=6 | dir=in | name=tcp 2869 |
"{AFC42317-28F7-47C0-9527-18DD6B8FDA52}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E060BCFC-B24E-443C-8CB1-AB66AFC6EF67}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{FBA8216E-B2A3-403F-927A-E48A120D9CE9}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01AA002B-AE1E-433D-9228-AA5BBDF9A914}" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{12943CB0-3FB1-4201-A11D-CD7C29E5BB91}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1EF0BBBE-1ED8-4934-8917-956C4AC75AF0}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{2A97802E-9965-47AE-BB34-F9B50E988C8B}" = protocol=6 | dir=in | app=c:\program files\electronic arts\battlefield 2142\bf2142.exe |
"{2DF0D8C3-2B80-4F63-A23F-6B123E4AB650}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{34D13003-9AC6-4463-A44C-9F43967BA051}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{58ADDFD1-04A5-4B59-A34F-06ABE0A51C93}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{6115DECB-234E-448B-90F5-4FD6BC6AD1E8}" = protocol=17 | dir=in | app=c:\program files\electronic arts\battlefield 2142\bf2142.exe |
"{68E82654-CBB1-4B1D-90EF-BC4777B05E08}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C810A29F-FC67-4320-B6DF-B8605AF3BAA9}" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{F84DBAE8-18DA-4A8A-A503-6AD5A297FDC9}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP270_series" = Canon MP270 series MP Drivers
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java 6 Update 24
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAB93551-3FFE-42B2-8315-96252BBC1033}" = Nero 7 Essentials
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.16.360
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED50ECE9-EC54-4C05-B5ED-EE4741A9F2EC}" = Battlefield 2142
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"N360" = Norton 360
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.9
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"Winrar 3.93" = Winrar 3.93
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 16/04/2011 8:33:46 PM | Computer Name = pc-PC | Source = Application Error | ID = 1000
Description = Faulting application BF2.exe, version 0.0.0.0, time stamp 0x4290facc,
faulting module ~df394b.tmp, version 0.0.0.0, time stamp 0x41348c3d, exception
code 0xc0000005, fault offset 0x000c486b, process id 0xe3c, application start time
0x01cbfc96f2443f60.
Error - 17/04/2011 5:05:00 AM | Computer Name = pc-PC | Source = Windows Backup | ID = 4104
Description =
Error - 22/04/2011 7:38:18 PM | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
Error - 24/04/2011 5:00:02 AM | Computer Name = pc-PC | Source = Windows Backup | ID = 4104
Description =
Error - 27/04/2011 1:18:47 PM | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
Error - 8/05/2011 3:03:54 AM | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
Error - 10/05/2011 5:01:27 AM | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
Error - 12/05/2011 4:22:25 AM | Computer Name = pc-PC | Source = Application Error | ID = 1000
Description = Faulting application ConvertXtoDvd.exe, version 4.1.16.360, time stamp
0x4da5ca06, faulting module kernel32.dll, version 6.0.6002.18005, time stamp 0x49e037dd,
exception code 0x0eedfade, fault offset 0x0003fbae, process id 0x9e8, application
start time 0x01cc107dadaf5847.
Error - 14/05/2011 5:14:09 AM | Computer Name = pc-PC | Source = Application Hang | ID = 1002
Description = The program msnmsgr.exe version 15.4.3508.1109 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: ec8 Start Time: 01cc0ef0be32a5c7 Termination Time: 723
Error - 14/05/2011 10:56:23 PM | Computer Name = pc-PC | Source = WinMgmt | ID = 10
Description =
[ System Events ]
Error - 30/12/2010 6:53:20 PM | Computer Name = pc-PC | Source = HTTP | ID = 15016
Description =
Error - 30/12/2010 6:54:56 PM | Computer Name = pc-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 30/12/2010 7:09:42 PM | Computer Name = pc-PC | Source = Service Control Manager | ID = 7011
Description =
Error - 31/12/2010 1:50:20 AM | Computer Name = pc-PC | Source = Microsoft-Windows-Service Pack Installer | ID = 8
Description =
Error - 31/12/2010 7:28:01 PM | Computer Name = pc-PC | Source = HTTP | ID = 15016
Description =
Error - 31/12/2010 7:29:26 PM | Computer Name = pc-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 1/01/2011 7:24:17 PM | Computer Name = pc-PC | Source = HTTP | ID = 15016
Description =
Error - 1/01/2011 7:25:55 PM | Computer Name = pc-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 2/01/2011 5:44:27 AM | Computer Name = pc-PC | Source = Service Control Manager | ID = 7011
Description =
Error - 2/01/2011 5:44:57 AM | Computer Name = pc-PC | Source = Service Control Manager | ID = 7011
Description =
< End of report >
Thanks in advance