Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Internet Explorer opens by itself but doesnt show a window


  • This topic is locked This topic is locked

#1
optimusprlme

optimusprlme

    New Member

  • Member
  • Pip
  • 1 posts
I have recently been having a problem with my hp g62 laptop. My laptop keeps opening up new internet explorer windows in my task manager, but none show up on my screen. I hear noises in the backround and a box that says my browser history is being cleared pops up once in a while. I ran malware bytes anti- malware and it seemed to fix the problem for a short time but it came back and came back hard now its interfering with the day to day running of my laptop. The OTL log will be pasted

OTL logfile created on: 9/6/2011 7:46:09 AM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\Morgan\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.75 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 58.29% Memory free
7.49 Gb Paging File | 5.59 Gb Available in Paging File | 74.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.94 Gb Total Space | 196.02 Gb Free Space | 43.37% Space Free | Partition Type: NTFS
Drive D: | 13.53 Gb Total Space | 1.94 Gb Free Space | 14.33% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 92.75 Mb Free Space | 93.67% Space Free | Partition Type: FAT32
Drive F: | 6.99 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: OPTIMUS_PRIME | User Name: Morgan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2011/09/06 07:45:58 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\Morgan\Downloads\OTL.exe
PRC - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\Users\Morgan\AppData\Local\Temp\hki282.exe
PRC - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe
PRC - [2011/09/03 23:34:02 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/27 20:11:04 | 000,039,428 | ---- | M] () -- C:\games\PowerISO\PWRISOVM.EXE
PRC - [2011/07/06 19:52:38 | 000,449,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/12/27 14:21:51 | 000,395,640 | ---- | M] (BitTorrent, Inc.) -- C:\utorrent\uTorrent.exe
PRC - [2009/07/13 22:14:28 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PING.EXE


========== Modules (No Company Name) ==========

MOD - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\Users\Morgan\AppData\Local\Temp\hki282.exe
MOD - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe
MOD - [2011/09/03 23:34:02 | 001,001,432 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2011/08/27 20:11:04 | 000,039,428 | ---- | M] () -- C:\games\PowerISO\PWRISOVM.EXE
MOD - [2011/06/15 17:15:53 | 006,271,136 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2010/02/22 15:19:10 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
MOD - [2010/02/22 15:19:08 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
MOD - [2010/02/22 15:19:08 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/03/11 00:29:46 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/02/05 14:50:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2010/01/27 18:01:04 | 000,102,968 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe -- (HP Wireless Assistant Service)
SRV:64bit: - [2009/07/13 22:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/03/27 23:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2011/08/05 16:58:10 | 003,542,616 | ---- | M] () [Auto | Running] -- c:\Program Files (x86)\Common Files\Akamai\netsession_win_2da1ebd.dll -- (Akamai)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/02/22 16:22:01 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/02/04 20:26:31 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/01/04 15:03:42 | 000,238,328 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/09/30 16:09:02 | 000,040,960 | ---- | M] (l o s t c r e a t i o n s) [Auto | Running] -- C:\games\Sudowin\Server\Sudowin.Server.exe -- (Sudowin)
SRV - [2007/05/31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/08/28 12:20:37 | 000,310,728 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2011/08/28 12:19:12 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011/07/06 19:52:42 | 000,025,912 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2010/09/02 17:40:39 | 000,502,256 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010/06/05 05:32:40 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/04/12 05:55:00 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2010/03/11 00:39:52 | 006,403,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/03/10 23:34:06 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/02/22 17:00:12 | 000,239,136 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/02/05 21:49:04 | 000,316,464 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/01/28 15:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/12/22 06:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2009/11/27 22:45:06 | 000,295,424 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/10/08 00:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/10/08 00:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/08/23 23:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/07/21 19:03:34 | 001,208,320 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:64bit: - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 22:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009/06/10 18:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 18:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 18:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 17:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 17:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/06/10 17:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:64bit: - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/02/24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009/07/13 22:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/02/24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2786678
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://search.condui...d=CT2786678&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.21\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/03 23:34:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.21\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/03 23:34:03 | 000,000,000 | ---D | M]

[2010/08/16 22:51:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Morgan\AppData\Roaming\Mozilla\Extensions
[2011/09/06 07:26:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Morgan\AppData\Roaming\Mozilla\Firefox\Profiles\ph9nbohw.default\extensions
[2010/12/27 14:28:27 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Morgan\AppData\Roaming\Mozilla\Firefox\Profiles\ph9nbohw.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2010/12/27 14:28:27 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Morgan\AppData\Roaming\Mozilla\Firefox\Profiles\ph9nbohw.default\extensions\[email protected]
[2010/12/27 14:28:31 | 000,000,863 | ---- | M] () -- C:\Users\Morgan\AppData\Roaming\Mozilla\Firefox\Profiles\ph9nbohw.default\searchplugins\conduit.xml
[2011/01/18 16:42:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/01/18 16:42:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/17 16:21:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/24 15:02:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/09 07:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2011/03/10 12:30:17 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/03/10 12:30:17 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/03/10 12:30:17 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/03/10 12:30:17 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] File not found
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\games\PowerISO\PWRISOVM.EXE ()
O4 - HKLM..\Run: [StartCCC] File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKCU..\Run: [Steam] File not found
O4 - Startup: C:\Users\Morgan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\utils)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{061C3C7D-894C-4A3F-BDEA-9D4F0C992DED}: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E38CE15D-CC62-41B6-955B-C54C4622D671}: DhcpNameServer = 192.168.16.250
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/25 01:56:52 | 000,000,046 | -H-- | M] () - F:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/30 12:08:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/08/29 20:15:21 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/08/29 20:09:01 | 000,000,000 | ---D | C] -- C:\ProgramData\xOcean
[2011/08/29 20:08:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BlastShark
[2011/08/29 19:54:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/08/29 19:54:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/08/29 19:54:29 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/08/29 19:54:20 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/08/29 19:54:18 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/08/29 19:54:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/08/29 16:46:31 | 000,000,000 | ---D | C] -- C:\Users\Morgan\AppData\Roaming\Malwarebytes
[2011/08/29 16:46:22 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/08/29 16:46:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/29 16:46:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/08/29 16:46:18 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/08/29 16:46:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/08/28 22:32:45 | 000,000,000 | ---D | C] -- C:\Users\Morgan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Astonia35
[2011/08/28 22:32:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astonia35
[2011/08/28 21:53:39 | 000,000,000 | ---D | C] -- C:\Users\Morgan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Machinarium
[2011/08/28 21:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Machinarium
[2011/08/28 13:12:33 | 000,000,000 | ---D | C] -- C:\Users\Morgan\Documents\Battlestations-Pacific
[2011/08/27 18:40:46 | 000,000,000 | ---D | C] -- C:\Users\Morgan\AppData\Roaming\Real
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/06 07:23:41 | 000,023,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/06 07:23:41 | 000,023,024 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/06 07:23:04 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/06 07:23:04 | 000,619,642 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/09/06 07:23:04 | 000,107,792 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe_
[2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe
[2011/09/06 07:16:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/06 07:15:53 | 3015,884,800 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/05 16:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At37.job
[2011/09/05 13:20:40 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At32.job
[2011/09/05 13:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At34.job
[2011/09/05 12:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At33.job
[2011/09/05 04:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At25.job
[2011/09/05 03:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At24.job
[2011/09/05 02:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At23.job
[2011/09/04 18:00:00 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\At46.job
[2011/09/04 18:00:00 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\At45.job
[2011/09/04 18:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At39.job
[2011/09/04 17:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At38.job
[2011/09/04 15:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At36.job
[2011/09/04 14:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At35.job
[2011/09/04 10:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At31.job
[2011/09/04 09:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At30.job
[2011/09/04 08:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At29.job
[2011/09/04 07:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At28.job
[2011/09/04 06:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At27.job
[2011/09/04 05:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At26.job
[2011/09/04 01:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At22.job
[2011/09/04 00:12:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At21.job
[2011/09/03 23:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At44.job
[2011/09/03 22:31:01 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\At20.job
[2011/09/03 22:27:00 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\At19.job
[2011/09/03 22:23:00 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\At18.job
[2011/09/03 22:19:02 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\At17.job
[2011/09/03 22:15:00 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\At16.job
[2011/09/03 22:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At43.job
[2011/09/03 21:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At42.job
[2011/09/03 20:20:00 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\At5.job
[2011/09/03 20:20:00 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\At15.job
[2011/09/03 20:20:00 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\At13.job
[2011/09/03 20:15:00 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\At4.job
[2011/09/03 20:15:00 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\At14.job
[2011/09/03 20:15:00 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\At11.job
[2011/09/03 20:10:00 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\At9.job
[2011/09/03 20:10:00 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\At3.job
[2011/09/03 20:10:00 | 000,000,330 | ---- | M] () -- C:\Windows\tasks\At12.job
[2011/09/03 20:05:00 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\At7.job
[2011/09/03 20:05:00 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\At2.job
[2011/09/03 20:05:00 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\At10.job
[2011/09/03 20:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At41.job
[2011/09/03 19:00:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\At40.job
[2011/09/03 19:00:00 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\At8.job
[2011/09/03 19:00:00 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\At6.job
[2011/09/03 19:00:00 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\At1.job
[2011/08/30 12:06:49 | 000,001,665 | ---- | M] () -- C:\Users\Public\Desktop\Play Hellgate.lnk
[2011/08/29 16:46:22 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/29 06:52:26 | 414,632,445 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/08/28 22:32:45 | 000,000,695 | ---- | M] () -- C:\Users\Morgan\Desktop\Astonia35.lnk
[2011/08/28 21:53:39 | 000,000,748 | ---- | M] () -- C:\Users\Morgan\Desktop\Machinarium.lnk
[2011/08/28 12:20:37 | 000,310,728 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2011/08/28 12:19:12 | 000,043,168 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2011/08/28 11:35:06 | 000,453,832 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/27 22:14:02 | 000,000,112 | ---- | M] () -- C:\ProgramData\8t5mvLH.dat
[2011/08/27 18:48:44 | 000,000,774 | ---- | M] () -- C:\Users\Morgan\Desktop\Super Meat Boy.lnk
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/05 04:02:10 | 000,113,152 | ---- | C] () -- C:\ProgramData\5UpUx7cV.exe_
[2011/09/05 04:02:10 | 000,113,152 | ---- | C] () -- C:\ProgramData\5UpUx7cV.exe
[2011/08/30 12:06:49 | 000,001,665 | ---- | C] () -- C:\Users\Public\Desktop\Play Hellgate.lnk
[2011/08/29 19:54:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/08/29 19:54:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/08/29 19:54:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/08/29 19:54:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/08/29 19:54:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/08/29 16:46:22 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/28 22:32:45 | 000,000,695 | ---- | C] () -- C:\Users\Morgan\Desktop\Astonia35.lnk
[2011/08/28 21:53:39 | 000,000,748 | ---- | C] () -- C:\Users\Morgan\Desktop\Machinarium.lnk
[2011/08/28 21:52:49 | 000,000,382 | ---- | C] () -- C:\Windows\tasks\At46.job
[2011/08/28 21:45:08 | 000,000,382 | ---- | C] () -- C:\Windows\tasks\At45.job
[2011/08/28 12:19:12 | 000,310,728 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2011/08/28 12:19:12 | 000,043,168 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2011/08/27 20:13:02 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At44.job
[2011/08/27 20:13:02 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At43.job
[2011/08/27 20:13:01 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At42.job
[2011/08/27 20:13:01 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At41.job
[2011/08/27 20:13:00 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At40.job
[2011/08/27 20:13:00 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At39.job
[2011/08/27 20:12:59 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At38.job
[2011/08/27 20:12:59 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At37.job
[2011/08/27 20:12:58 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At36.job
[2011/08/27 20:12:58 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At35.job
[2011/08/27 20:12:58 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At34.job
[2011/08/27 20:12:57 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At33.job
[2011/08/27 20:12:57 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At32.job
[2011/08/27 20:12:56 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At31.job
[2011/08/27 20:12:56 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At30.job
[2011/08/27 20:12:55 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At29.job
[2011/08/27 20:12:55 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At28.job
[2011/08/27 20:12:55 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At27.job
[2011/08/27 20:12:54 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At26.job
[2011/08/27 20:12:54 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At25.job
[2011/08/27 20:12:53 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At24.job
[2011/08/27 20:12:53 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At23.job
[2011/08/27 20:12:49 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At22.job
[2011/08/27 20:12:49 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\At21.job
[2011/08/27 20:12:19 | 000,000,112 | ---- | C] () -- C:\ProgramData\8t5mvLH.dat
[2011/08/27 18:41:10 | 000,000,774 | ---- | C] () -- C:\Users\Morgan\Desktop\Super Meat Boy.lnk
[2011/08/27 18:40:29 | 000,000,324 | ---- | C] () -- C:\Windows\tasks\At20.job
[2011/08/27 18:40:28 | 000,000,324 | ---- | C] () -- C:\Windows\tasks\At19.job
[2011/08/27 18:40:27 | 000,000,324 | ---- | C] () -- C:\Windows\tasks\At18.job
[2011/08/27 18:40:26 | 000,000,324 | ---- | C] () -- C:\Windows\tasks\At17.job
[2011/08/27 18:40:25 | 000,000,324 | ---- | C] () -- C:\Windows\tasks\At16.job
[2011/08/26 20:46:06 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\At15.job
[2011/08/26 20:46:03 | 000,000,328 | ---- | C] () -- C:\Windows\tasks\At14.job
[2011/08/26 20:46:01 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\At13.job
[2011/08/26 20:45:58 | 000,000,330 | ---- | C] () -- C:\Windows\tasks\At12.job
[2011/08/26 20:45:55 | 000,000,328 | ---- | C] () -- C:\Windows\tasks\At11.job
[2011/08/26 20:45:51 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\At10.job
[2011/08/26 20:45:49 | 000,000,330 | ---- | C] () -- C:\Windows\tasks\At9.job
[2011/08/26 20:45:47 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\At8.job
[2011/08/26 20:45:45 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\At7.job
[2011/08/26 20:45:42 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\At6.job
[2011/08/26 20:44:42 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\At5.job
[2011/08/26 20:44:41 | 000,000,328 | ---- | C] () -- C:\Windows\tasks\At4.job
[2011/08/26 20:44:40 | 000,000,330 | ---- | C] () -- C:\Windows\tasks\At3.job
[2011/08/26 20:44:39 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\At2.job
[2011/08/26 20:44:37 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\At1.job
[2011/07/11 01:48:08 | 000,003,584 | ---- | C] () -- C:\Users\Morgan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/28 10:49:19 | 000,000,060 | ---- | C] () -- C:\Windows\TRIMSURV.INI
[2011/02/04 16:53:04 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2011/02/03 15:11:44 | 000,000,140 | ---- | C] () -- C:\Users\Morgan\AppData\Roaming\wklnhst.dat
[2010/12/19 19:37:43 | 000,000,063 | ---- | C] () -- C:\Windows\WININIT.INI
[2010/08/16 22:51:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/06/05 05:35:37 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/06/05 05:28:40 | 000,000,268 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini
[2010/06/05 05:28:40 | 000,000,209 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini
[2010/03/31 06:54:43 | 000,000,188 | ---- | C] () -- C:\Windows\SysWow64\HPWA.ini
[2010/02/23 17:15:02 | 000,001,105 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/02/09 22:58:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL
[2009/07/14 02:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 23:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 23:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 21:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 20:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 18:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 18:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/04/22 01:19:06 | 000,172,173 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2008/10/07 10:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2000/04/04 12:15:00 | 000,000,899 | ---- | C] () -- C:\Windows\TIMEZONE.INI

< End of report >

thank you for your time.
  • 0

Advertisements


#2
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hello and welcome to the forums!

My secret agent name on the forums is SweetTech (you can call me Agent ST for short), it's a pleasure to meet you. :unsure:

I would be glad to take a look at your log and help you with solving any malware problems.

If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:


  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
  • Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together :)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.

____________________________________________________

Can you please post the contents of the Extras.txt log for me to review?



Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:
  • uTorrent
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

How to Uninstall the P2P Programs:

Remove Program

For Vista Users:
  • Click on Start > Control Panel and double click on Programs and Features.
  • Locate uTorrent and click on the Uninstall button to uninstall it.
  • Close Control Panel when done.

PLEASE NOTE: When your uninstalling the P2P Program(s) some questions are worded in various ways to try and deceive you and keep you from uninstalling their Program.


NEXT:



OTL Fix

We need to run an OTL Fix
  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox.
    :Services
    :Processes
    KILLALLPROCESSES
    :OTL
    PRC - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\Users\Morgan\AppData\Local\Temp\hki282.exe
    PRC - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe
    MOD - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\Users\Morgan\AppData\Local\Temp\hki282.exe
    MOD - [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe
    IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
    [2011/01/18 16:42:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    [2010/08/17 16:21:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2010/12/24 15:02:29 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
    O4 - HKLM..\Run: [HP Software Update] File not found
    O4 - HKLM..\Run: [NortonOnlineBackupReminder] File not found
    O4 - HKLM..\Run: [StartCCC] File not found
    O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
    O4 - HKCU..\Run: [Steam] File not found
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
    [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe_
    [2011/09/06 07:20:23 | 000,113,152 | ---- | M] () -- C:\ProgramData\5UpUx7cV.exe
    [2011/08/27 22:14:02 | 000,000,112 | ---- | M] () -- C:\ProgramData\8t5mvLH.dat
    [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [2011/09/05 04:02:10 | 000,113,152 | ---- | C] () -- C:\ProgramData\5UpUx7cV.exe_
    [2011/09/05 04:02:10 | 000,113,152 | ---- | C] () -- C:\ProgramData\5UpUx7cV.exe
    
    :Reg
    
    :Files
    C:\Windows\tasks\At*.job
    echo,Y|cacls "%WinDir%\system32\drivers\etc\hosts" /G everyone:f /c
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
    
  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click the OK button.
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

  • 0

#3
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP