After downloading one of the Google desktop gadgets on to the Google desktop, I got a threat warning from AVG and I permitted it to remove the threat, but I am not sure if my PC is still infected. Just want to make sure my security isn't compromised. Here are the screenshots. Thank you very much in advance for the help.
http://imm.io/7kFB
http://imm.io/7kFC
(Also, does anyone know what the problem with my volume bar could be? It hasn't been working since weeks. But the volume of songs works just fine. There is no sound of the ding when I increase/decrease volume on the volume bar next to the clock. Also, the only time there is no sound is on startup/shutdown. Please note that this problem is unrelated to the problem above because I have been experiencing this problem since 2-3 weeks and the virus problem happened just yesterday. So they're totally UNRELATED.
Also, another thing I've been noticing is that even after closing my IE 8 explorer, the processes named iexplore.exe don't disappear from the task manager. Moreover, it hogs as much as 200K all the time. The same goes for Firefox. I tried RAMBOOSTER but it doesn't solve this problem for me.)
Thanks in advance!
---------------------------------------------------------------------------------
Here's the OTL log:
OTL logfile created on: 7/26/2011 5:37:29 AM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\NK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 0.43 Gb Available Physical Memory | 22.94% Memory free
3.72 Gb Paging File | 1.29 Gb Available in Paging File | 34.54% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 214.84 Gb Total Space | 194.83 Gb Free Space | 90.68% Space Free | Partition Type: NTFS
Drive D: | 18.03 Gb Total Space | 16.36 Gb Free Space | 90.74% Space Free | Partition Type: NTFS
Computer Name: NK-F5FFDC7 | User Name: NK | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/07/26 05:37:02 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\NK\Desktop\OTL.exe
PRC - [2011/07/16 00:16:16 | 000,358,400 | ---- | M] (Antiz) -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\NK\Poker\Softwares\PokerRatings\PokerRatings.exe
PRC - [2011/07/08 12:46:28 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/29 13:37:45 | 002,971,648 | ---- | M] () -- C:\Program Files\Cake Poker\cake.exe
PRC - [2011/06/23 19:49:28 | 006,539,608 | ---- | M] (PokerStars) -- C:\Program Files\PokerStars\PokerStars.exe
PRC - [2011/06/16 07:55:12 | 006,276,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2011/06/14 09:16:22 | 004,624,896 | ---- | M] (Bodog) -- C:\Program Files\Bodog Poker\BPGame.exe
PRC - [2011/05/25 11:39:21 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/05/19 22:42:20 | 004,358,214 | ---- | M] (ABSOLUTE POKER) -- C:\Program Files\Absolute Poker\mainclient.exe
PRC - [2011/05/16 03:43:20 | 002,268,160 | ---- | M] (Playtech) -- C:\Program Files\William Hill Poker\casino.exe
PRC - [2011/05/16 01:23:20 | 000,325,512 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2011/05/15 04:22:22 | 000,499,712 | ---- | M] () -- C:\Program Files\Absolute Poker\aphh.exe
PRC - [2011/05/04 06:14:36 | 007,307,264 | ---- | M] (Hold'em Manager) -- C:\Program Files\RVG Software\Holdem Manager\HoldemManager.exe
PRC - [2011/05/04 06:05:22 | 001,908,736 | ---- | M] (Hold'em Manager) -- C:\Program Files\RVG Software\Holdem Manager\HMImport.exe
PRC - [2011/04/18 17:40:08 | 002,334,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/04/14 05:36:42 | 001,080,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/03/28 03:00:52 | 000,351,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2011/03/16 16:05:20 | 001,025,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/03/16 16:05:14 | 000,656,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2011/03/15 21:14:00 | 000,663,552 | ---- | M] (IdleMiner) -- C:\Program Files\Bodog Hand Grabber\BodogHandGrabber.exe
PRC - [2011/03/09 19:24:44 | 002,708,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgfws.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 05:33:20 | 000,658,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/02/08 05:32:42 | 000,750,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe
PRC - [2011/01/28 10:45:33 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe
PRC - [2011/01/28 10:43:43 | 004,538,368 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\PostgreSQL\8.4\bin\postgres.exe
PRC - [2009/09/26 00:27:38 | 000,245,248 | ---- | M] () -- C:\Program Files\AutoHotkey\AutoHotkey.exe
PRC - [2008/04/14 11:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/11/17 07:32:54 | 000,561,664 | ---- | M] (J.Pajula) -- C:\Program Files\RamBooster 2.0\Rambooster.exe
PRC - [2002/12/20 04:47:56 | 000,057,344 | ---- | M] (Thong Nguyen) -- C:\Program Files\PowerMenu\PowerMenu.exe
========== Modules (SafeList) ==========
MOD - [2011/07/26 05:37:02 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\NK\Desktop\OTL.exe
MOD - [2011/05/21 09:58:38 | 000,010,752 | ---- | M] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\NK\Poker\Softwares\PokerRatings\hotkey.dll
MOD - [2011/05/16 01:23:34 | 000,064,600 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll
MOD - [2010/08/23 21:42:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010/03/18 09:15:26 | 000,770,384 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\NK\Poker\Softwares\PokerRatings\msvcr100.dll
MOD - [2002/12/20 04:46:50 | 000,073,728 | ---- | M] (Thong Nguyen) -- C:\Program Files\PowerMenu\PowerMenuHook.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/07/22 04:00:55 | 003,029,208 | ---- | M] (Emsi Software GmbH) [Disabled | Stopped] -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/25 11:39:21 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/03/09 19:24:44 | 002,708,024 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgfws.exe -- (avgfws)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2011/01/28 10:45:33 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [On_Demand | Running] -- C:\Program Files\PostgreSQL\8.4\bin\pg_ctl.exe -- (postgresql-8.4)
========== Driver Services (SafeList) ==========
DRV - [2011/07/06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/04/14 21:28:42 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/04/05 00:59:56 | 000,297,168 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/03/16 16:03:20 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/03/01 14:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 08:13:02 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/20 21:30:06 | 000,073,728 | ---- | M] (Emsi Software GmbH) [File_System | On_Demand | Stopped] -- C:\Program Files\Emsisoft Anti-Malware\a2accx86.sys -- (a2acc)
DRV - [2011/02/10 07:53:54 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 07:53:52 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/07 06:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd)
DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx)
DRV - [2007/09/20 16:37:40 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2007/09/20 16:37:38 | 000,053,632 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2007/05/10 15:58:08 | 004,419,584 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2003/04/09 11:17:14 | 000,227,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cccp106.sys -- (CCCP106) CIF USB Camera (2110A)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\NK\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/07/12 17:26:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/20 18:25:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/15 04:27:56 | 000,000,000 | ---D | M]
[2011/07/20 18:25:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\NK\Application Data\Mozilla\Extensions
[2011/07/21 02:52:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\NK\Application Data\Mozilla\Firefox\Profiles\974zlf84.default\extensions
[2011/07/21 02:52:33 | 000,000,000 | ---D | M] (Qualys BrowserCheck) -- C:\Documents and Settings\NK\Application Data\Mozilla\Firefox\Profiles\974zlf84.default\extensions\{7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D}
[2011/07/21 00:52:12 | 000,000,000 | ---D | M] (Awesome screenshot: Capture and Annotate) -- C:\Documents and Settings\NK\Application Data\Mozilla\Firefox\Profiles\974zlf84.default\extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
[2011/07/20 18:25:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/06/17 04:47:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\NK\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974ZLF84.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\NK\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974ZLF84.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\NK\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974ZLF84.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\NK\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974ZLF84.DEFAULT\EXTENSIONS\[email protected]
[2011/05/16 03:06:49 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/07/08 12:46:28 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/06/17 04:47:17 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 13:30:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2001/08/23 17:30:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe (J.Pajula)
O4 - Startup: C:\Documents and Settings\NK\Start Menu\Programs\Startup\PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe (Thong Nguyen)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} https://browsercheck....com/qbc_ax.cab (Qualys BrowserCheck)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 59.185.0.23 59.185.0.50
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/05/15 02:12:53 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{679785f2-8703-11e0-9f38-001b2207096f}\Shell - "" = AutoRun
O33 - MountPoints2\{679785f2-8703-11e0-9f38-001b2207096f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{679785f2-8703-11e0-9f38-001b2207096f}\Shell\AutoRun\command - "" = F:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/26 05:36:58 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\NK\Desktop\OTL.exe
[2011/07/23 03:40:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011/07/22 03:52:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Emsisoft Anti-Malware
[2011/07/22 03:52:02 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2011/07/22 03:52:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\My Documents\Anti-Malware
[2011/07/22 02:34:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\Local Settings\Application Data\Help
[2011/07/22 02:34:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\Application Data\Help
[2011/07/22 02:30:06 | 000,000,000 | ---D | C] -- C:\Program Files\RamBooster 2.0
[2011/07/21 00:00:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\NK\Recent
[2011/07/20 18:25:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\Application Data\Mozilla
[2011/07/20 17:33:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\Application Data\Google
[2011/07/20 17:09:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\Local Settings\Application Data\WMTools Downloaded Files
[2011/07/20 15:25:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Desktop
[2011/07/20 15:25:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\My Documents\My Google Gadgets
[2011/06/29 15:19:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NK\Application Data\Foxit Software
[2011/06/29 13:37:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Cake Poker
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/26 05:37:02 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\NK\Desktop\OTL.exe
[2011/07/25 22:08:40 | 125,314,454 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/07/25 13:19:45 | 000,493,384 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/07/25 13:19:45 | 000,083,802 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/07/25 13:15:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/07/25 02:57:52 | 003,747,968 | ---- | M] () -- C:\Documents and Settings\NK\Desktop\04 - Senorita.mp3
[2011/07/25 02:08:31 | 000,104,642 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/07/23 03:40:31 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/07/22 20:35:05 | 000,658,369 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/07/22 03:52:15 | 000,000,766 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Emsisoft Anti-Malware.lnk
[2011/07/21 04:04:03 | 000,001,251 | ---- | M] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\Songs.lnk
[2011/07/21 03:13:17 | 000,518,343 | ---- | M] () -- C:\shot0.png
[2011/07/21 00:03:31 | 000,001,611 | ---- | M] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerRatings.lnk
[2011/07/20 19:32:15 | 000,007,168 | ---- | M] () -- C:\Documents and Settings\NK\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/20 18:25:47 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/07/20 16:13:29 | 000,000,122 | ---- | M] () -- C:\WINDOWS\_vmtxp.ini
[2011/07/19 21:21:22 | 000,001,614 | ---- | M] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\Names.lnk
[2011/07/13 23:35:23 | 000,120,544 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/12 17:19:27 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/07/06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/05 15:54:22 | 000,000,812 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/07/05 15:20:42 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/25 02:57:44 | 003,747,968 | ---- | C] () -- C:\Documents and Settings\NK\Desktop\04 - Senorita.mp3
[2011/07/22 03:52:15 | 000,000,766 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Emsisoft Anti-Malware.lnk
[2011/07/22 02:30:07 | 000,001,626 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Launch RamBooster 2.0.lnk
[2011/07/21 04:03:27 | 000,001,251 | ---- | C] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\Songs.lnk
[2011/07/21 03:13:17 | 000,518,343 | ---- | C] () -- C:\shot0.png
[2011/07/20 18:25:47 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/07/20 16:23:06 | 000,001,611 | ---- | C] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\PokerRatings.lnk
[2011/07/20 16:07:13 | 000,000,122 | ---- | C] () -- C:\WINDOWS\_vmtxp.ini
[2011/07/19 21:21:22 | 000,001,614 | ---- | C] () -- C:\Documents and Settings\NK\Application Data\Microsoft\Internet Explorer\Quick Launch\Names.lnk
[2011/07/19 00:44:24 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\NK\Start Menu\Programs\BitTorrent.lnk
[2011/07/05 20:15:19 | 000,004,805 | ---- | C] () -- C:\WINDOWS\System32\nvnrm.nvu
[2011/06/18 01:32:47 | 000,273,344 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/06/18 01:32:47 | 000,273,344 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/06/18 01:32:47 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/06/18 01:32:26 | 002,123,582 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/05/29 23:31:01 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\NK\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/28 17:25:16 | 000,227,200 | ---- | C] () -- C:\WINDOWS\System32\drivers\cccp106.sys
[2011/05/28 17:25:16 | 000,036,864 | ---- | C] () -- C:\WINDOWS\JPGL.DLL
[2011/05/28 17:25:16 | 000,032,768 | ---- | C] () -- C:\WINDOWS\DIV_IYUV.DLL
[2011/05/28 17:25:15 | 002,093,106 | ---- | C] () -- C:\WINDOWS\select.exe
[2011/05/28 17:25:15 | 000,192,512 | ---- | C] () -- C:\WINDOWS\select2.exe
[2011/05/28 17:25:15 | 000,127,038 | ---- | C] () -- C:\WINDOWS\Clement.exe
[2011/05/28 17:25:15 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\dcccp106.dll
[2011/05/28 17:25:15 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vcccp106.dll
[2011/05/28 17:25:15 | 000,036,864 | ---- | C] () -- C:\WINDOWS\CleanDev.exe
[2011/05/28 17:25:15 | 000,015,542 | ---- | C] () -- C:\WINDOWS\cccp106.ini
[2011/05/28 17:25:15 | 000,000,321 | ---- | C] () -- C:\WINDOWS\DC2110a.ini
[2011/05/18 23:15:03 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011/05/16 02:51:16 | 000,000,011 | ---- | C] () -- C:\WINDOWS\YAHELITE_BUDDY.INI
[2011/05/16 02:45:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\YAHELITE_cookie.INI
[2011/05/16 02:44:01 | 000,004,667 | ---- | C] () -- C:\WINDOWS\YAHELITE.INI
[2011/05/15 07:35:19 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/05/15 07:34:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\HMHud.INI
[2011/05/15 07:32:44 | 000,120,544 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/15 05:18:13 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/05/15 03:02:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/05/15 02:19:14 | 000,001,732 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2011/05/15 02:14:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/05/15 02:10:28 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/14 11:25:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/10/04 14:44:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/12/31 13:27:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 17:30:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 17:30:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 17:30:00 | 000,493,384 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 17:30:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 17:30:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 17:30:00 | 000,083,802 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 17:30:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 17:30:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 17:30:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 17:30:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/05/15 04:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2011/05/15 03:10:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/05/15 03:10:34 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/06/18 02:11:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/05/15 03:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/15 06:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XHEO INC
[2011/05/15 04:20:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\Absolute Poker
[2011/05/15 04:08:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\acccore
[2011/05/15 03:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\AVG10
[2011/07/20 15:06:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\BitTorrent
[2011/06/29 15:19:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\Foxit Software
[2011/06/15 02:40:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\HEM Data
[2011/05/15 04:30:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\OpenOffice.org
[2011/05/22 08:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\Qualys
[2011/05/15 07:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\Roaming
[2011/05/29 02:52:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\UBNet
[2011/05/15 02:29:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NK\Application Data\WinPatrol
========== Purity Check ==========
< End of report >
Edited by geekyandhow, 26 July 2011 - 07:17 AM.