Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Is my computer still compromised?


  • This topic is locked This topic is locked

#16
Ninjajonas

Ninjajonas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I ran the fix with otl, it ran fine until it stalled at all processes killed. It looked to be done, so i killed the process and re-opened it before rebooting. It opened a notepad with a log that i attached.

Here is the quickscan from otl

OTL logfile created on: 11/4/2011 1:27:35 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Louise\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.24% Memory free
10.90 Gb Paging File | 10.34 Gb Available in Paging File | 94.79% Paging File free
Paging file location(s): C:\pagefile.sys 8000 16000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.31 Gb Total Space | 68.39 Gb Free Space | 35.02% Space Free | Partition Type: NTFS
Drive E: | 503.32 Gb Total Space | 66.00 Gb Free Space | 13.11% Space Free | Partition Type: NTFS
Drive F: | 549.52 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: COMPUTER | User Name: Louise | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Louise\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
PRC - C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe (Realtek)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVAST Software\Avast\defs\11110201\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\11110201\aswRep.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\3963ce03d445a8619abbf388d590134b\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\b82c00e2d24305ad6cb08556e3779b75\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\11eb4f6606ba01e5128805759121ea6c\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\773a9786013451d3baaeff003dc4230f\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\63406259e94d5c0ff5b79401dfe113ce\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\3da96ee075bab9202626ae44c18d226c\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\80978a322d7dd39f0a71be1251ae395a\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\6d667f19d687361886990f3ca0f49816\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
MOD - C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.dll ()
MOD - C:\WINDOWS\system32\P17.dll ()


========== Win32 Services (SafeList) ==========

SRV - (UleadBurningHelper) -- File not found
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (avgwd) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (Avgrkx86) -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (dtsoftbus01) -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Almico Software)
DRV - (cpuz135) -- C:\WINDOWS\system32\drivers\cpuz135_x32.sys (CPUID)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (ithsgt) -- C:\WINDOWS\system32\drivers\ithsgt.sys ()
DRV - (lilsgt) -- C:\WINDOWS\system32\drivers\lilsgt.sys ()
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (hwusbfake) -- C:\WINDOWS\system32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (VIAHdAudAddService) -- C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (monfilt) -- C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (AsIO) -- C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (Diag69xp) -- C:\WINDOWS\system32\drivers\diag69xp.sys (Realtek Semiconductor Corporation)
DRV - (RTLVLAN) -- C:\WINDOWS\system32\drivers\RTLVLAN.SYS (Realtek Semiconductor Corporation)
DRV - (LANPkt) -- C:\WINDOWS\system32\drivers\LANPkt.sys (Realtek Semiconductor Corporation)
DRV - (P17) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ULCDRHlp) -- C:\WINDOWS\system32\drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.dk/"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Louise\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/09/08 00:05:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/10/25 20:11:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/01 01:30:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/17 15:35:12 | 000,000,000 | ---D | M]

[2010/05/23 21:26:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Extensions
[2011/10/11 02:25:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\ybz4j5iu.default\extensions
[2010/06/09 22:41:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\ybz4j5iu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/11 02:25:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\ybz4j5iu.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/10/20 21:03:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/11 05:59:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/26 00:28:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/15 17:38:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/14 14:33:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/20 21:03:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/08 00:05:37 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011/10/25 20:11:30 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2010/07/11 05:59:34 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/01 01:30:06 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/11/04 00:58:46 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [8169Diag] C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe (Realtek)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\Ai Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\Ai Suite\QFan3\QFanHelp.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [20090604] E:\Spil\Hoyle Puzzle and Board Games 2011\Ereg\encore_reg.exe /r "E:\Spil\Hoyle Puzzle and Board Games 2011\Ereg\encore_reg.rpd" File not found
O4 - HKCU..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe File not found
O4 - HKCU..\Run: [CreativeTaskScheduler] C:\Program Files\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe ()
O4 - HKCU..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer....r_installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://netbank.dans...B/e-Safekey.cab (e-Safekey)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...15108/CTPID.cab (Creative Software AutoUpdate Support Package)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:44:22 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/04/18 16:23:00 | 000,000,041 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{205c3e67-2587-11e0-9638-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{205c3e67-2587-11e0-9638-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{205c3e67-2587-11e0-9638-00248c45794b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{32d2b1ed-2406-11e0-9635-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{32d2b1ed-2406-11e0-9635-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{32d2b1ed-2406-11e0-9635-00248c45794b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{32d2b218-2406-11e0-9635-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{32d2b218-2406-11e0-9635-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{32d2b218-2406-11e0-9635-00248c45794b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{4dbc24da-7b91-11de-929e-00248c45794b}\Shell\AutoRun\command - "" = BITLORD.EXE
O33 - MountPoints2\{a8525d9a-b1f6-11e0-9b62-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{a8525d9a-b1f6-11e0-9b62-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a8525d9a-b1f6-11e0-9b62-00248c45794b}\Shell\AutoRun\command - "" = F:\SETUP.EXE -- [2001/04/30 18:33:00 | 000,032,768 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/04 00:58:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/11/03 22:24:41 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Louise\Desktop\OTL.exe
[2011/10/31 23:46:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Real Lives 2010
[2011/10/31 23:44:42 | 000,409,600 | ---- | C] (ActiveLock) -- C:\WINDOWS\System32\activelock1884.ocx
[2011/10/25 20:12:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Louise\Application Data\AVG2012
[2011/10/25 20:11:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2011/10/25 20:09:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/25 20:09:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011/10/24 19:23:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/20 23:41:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Louise\Desktop\Moderations and Defaults
[2002/04/11 02:41:06 | 000,065,536 | R--- | C] ( ) -- C:\WINDOWS\System32\A3d.dll

========== Files - Modified Within 30 Days ==========

[2011/11/04 01:28:29 | 000,504,616 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/04 01:28:29 | 000,088,336 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/11/04 01:23:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/04 00:58:46 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/11/03 22:24:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Louise\Desktop\OTL.exe
[2011/11/03 00:45:18 | 108,543,528 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/11/03 00:40:54 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/01 21:07:49 | 000,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/31 23:23:37 | 000,000,469 | ---- | M] () -- C:\WINDOWS\QTW.INI
[2011/10/31 23:17:27 | 000,176,720 | ---- | M] () -- C:\WINDOWS\xobglu32.dll
[2011/10/31 23:17:27 | 000,063,488 | ---- | M] () -- C:\WINDOWS\xobglu16.dll
[2011/10/25 20:11:30 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/10/23 17:27:51 | 000,079,872 | ---- | M] () -- C:\Documents and Settings\Louise\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/20 23:26:40 | 000,001,072 | ---- | M] () -- C:\Documents and Settings\Louise\Desktop\TS3EP05.exe.lnk
[2011/10/20 21:04:42 | 000,001,839 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\The Sims™ 3 Pets.lnk
[2011/10/20 20:08:21 | 000,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Origin.lnk
[2011/10/17 00:15:18 | 000,002,359 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nudansk Ordbog 19.0.lnk

========== Files Created - No Company Name ==========

[2011/11/03 00:45:18 | 108,543,528 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/10/31 23:17:27 | 000,176,720 | ---- | C] () -- C:\WINDOWS\xobglu32.dll
[2011/10/31 23:17:27 | 000,063,488 | ---- | C] () -- C:\WINDOWS\xobglu16.dll
[2011/10/25 20:11:30 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/10/25 20:11:02 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/10/20 23:26:40 | 000,001,072 | ---- | C] () -- C:\Documents and Settings\Louise\Desktop\TS3EP05.exe.lnk
[2011/10/20 21:04:42 | 000,001,839 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\The Sims™ 3 Pets.lnk
[2011/08/18 00:45:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2011/06/01 23:15:11 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\QTUninst.dll
[2011/05/24 22:44:26 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
[2011/02/15 19:54:12 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2011/01/19 21:09:47 | 000,071,253 | ---- | C] () -- C:\WINDOWS\Huawei ModemsUninstall.exe
[2010/11/21 22:47:47 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2010/08/02 01:01:28 | 000,000,485 | ---- | C] () -- C:\WINDOWS\KingsC.ini
[2010/07/19 02:28:13 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2010/07/19 02:28:13 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2010/07/19 02:28:13 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2010/07/19 01:41:56 | 000,030,362 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
[2010/05/23 21:25:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/04/17 05:13:33 | 000,000,058 | -H-- | C] () -- C:\WINDOWS\popcreg.dat
[2010/04/17 05:13:33 | 000,000,044 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2010/04/02 16:17:34 | 000,179,091 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010/03/03 21:17:06 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/01/27 01:16:32 | 000,000,059 | ---- | C] () -- C:\WINDOWS\RUNAWAY.INI
[2010/01/04 10:55:38 | 000,004,492 | ---- | C] () -- C:\Documents and Settings\Louise\Application Data\mindhabits.dat
[2010/01/04 07:48:39 | 000,037,888 | ---- | C] () -- C:\WINDOWS\UninstallFaust.exe
[2010/01/04 07:37:32 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/12/26 06:08:17 | 000,000,458 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/12/23 15:23:59 | 000,000,241 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2009/12/21 19:36:01 | 000,162,432 | ---- | C] () -- C:\WINDOWS\System32\drivers\ithsgt.sys
[2009/12/21 19:36:00 | 000,012,032 | ---- | C] () -- C:\WINDOWS\System32\drivers\lilsgt.sys
[2009/11/05 10:09:53 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Louise\Local Settings\Application Data\fusioncache.dat
[2009/11/05 01:56:03 | 000,112,410 | ---- | C] () -- C:\WINDOWS\hpoins07.dat
[2009/11/05 01:56:03 | 000,021,124 | ---- | C] () -- C:\WINDOWS\hpomdl07.dat
[2009/10/13 00:40:42 | 000,000,469 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2009/10/10 01:47:41 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009/10/10 01:47:40 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009/10/02 17:33:53 | 000,017,385 | ---- | C] () -- C:\WINDOWS\agyheqek.sys
[2009/10/02 17:33:53 | 000,016,610 | ---- | C] () -- C:\WINDOWS\ywada.dat
[2009/10/02 17:33:53 | 000,014,275 | ---- | C] () -- C:\WINDOWS\System32\esexurica.dll
[2009/09/26 20:56:12 | 000,000,029 | ---- | C] () -- C:\WINDOWS\sfbm.INI
[2009/09/26 20:49:56 | 000,000,102 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2009/09/26 16:34:55 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\Dvbpws.dll
[2009/09/19 01:44:41 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2009/09/19 01:44:41 | 000,011,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\BdaSup.sys
[2009/09/18 22:59:19 | 000,078,085 | ---- | C] () -- C:\WINDOWS\System32\pattern.dat
[2009/09/18 22:59:11 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\fxstudio.dll
[2009/09/18 22:59:11 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\animation2.dll
[2009/08/16 02:04:37 | 000,939,712 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/07/21 03:32:59 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009/07/21 03:32:50 | 000,001,386 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2009/07/21 03:27:10 | 000,233,765 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/07/21 03:24:30 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/07/21 02:25:49 | 000,079,872 | ---- | C] () -- C:\Documents and Settings\Louise\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/10 20:28:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/10 20:27:52 | 000,286,904 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/10 20:04:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2009/06/10 19:29:30 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2009/06/10 19:29:30 | 000,012,400 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2009/06/10 19:29:25 | 000,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/06/10 19:29:25 | 000,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/06/10 18:50:05 | 000,026,909 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2009/06/10 18:49:41 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/06/10 18:49:27 | 000,026,146 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009/06/10 18:49:27 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/06/10 18:45:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/06/10 18:42:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/05/16 03:54:01 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009/05/16 03:54:01 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/05/03 12:38:42 | 000,064,512 | R--- | C] () -- C:\WINDOWS\System32\P17.dll
[2003/10/02 11:48:18 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2002/07/01 15:13:30 | 000,000,243 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\system16driver.dat
[2001/08/23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 12:00:00 | 000,504,616 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 12:00:00 | 000,088,336 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001/07/06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2001/04/01 19:16:48 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\fader.dll
[2000/11/08 01:37:42 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\drumpad.dll
[2000/03/29 01:58:40 | 000,280,576 | ---- | C] () -- C:\WINDOWS\System32\pxd_kom.dll
[2000/03/28 15:27:42 | 000,075,976 | ---- | C] () -- C:\WINDOWS\System32\BASSDEC.dll
[1996/04/03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2011/08/14 14:56:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/10/25 20:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/24 19:26:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/11/11 03:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Beanbag Studios
[2011/05/23 23:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Birdstep Technology
[2009/10/04 15:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Brainiversity2
[2011/03/14 23:09:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/31 01:13:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CrioGames
[2010/02/10 02:16:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/06/15 10:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\e-Safekey
[2011/04/15 00:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA Core
[2011/07/04 00:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA Logs
[2011/06/06 00:51:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/10/04 15:52:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy3
[2011/02/05 02:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2011/01/29 23:54:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Green Clover Games
[2011/08/18 02:22:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ice-Pick Lodge
[2010/03/07 05:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2011/02/13 06:25:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Merscom
[2011/11/03 00:45:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/30 23:06:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin
[2011/02/10 04:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/12/30 01:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2010/04/17 05:14:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/01/24 17:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/01/19 01:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sortasoft
[2011/10/26 20:25:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Soulseek
[2009/10/04 04:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\StoneLoops!
[2009/07/10 18:19:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SugarGames
[2011/10/24 19:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/23 15:54:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackMania United
[2009/09/26 19:08:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/06/10 19:39:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/01/22 23:30:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XLab
[2011/10/25 20:12:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\AVG2012
[2010/12/30 05:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Big Fish Games
[2011/02/15 01:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Braid
[2010/11/21 22:48:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\CheckPoint
[2009/06/13 15:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\DAEMON Tools Lite
[2009/10/04 02:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\ERS G-Studio
[2010/12/22 05:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Fabulous Finds
[2009/10/06 13:02:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\fretsonfire
[2009/07/12 00:39:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\funkitron
[2009/10/04 19:28:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Games
[2011/01/29 23:54:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Green Clover Games
[2011/01/24 00:17:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Hoyle FaceCreator
[2011/01/24 02:25:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Hoyle Puzzle and Board Games
[2009/12/25 01:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Hue Forest Entertainment
[2010/06/24 01:04:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\ImgBurn
[2010/06/24 00:48:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\InfraRecorder
[2010/03/07 05:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Ludia
[2011/02/10 05:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Magic Seeds
[2011/01/27 05:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Meridian93
[2011/02/13 06:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\MysteryStudio
[2011/10/20 20:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Origin
[2011/02/10 04:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\panoramik
[2011/02/10 04:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\PlayFirst
[2009/07/07 08:26:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Politiken
[2011/04/14 23:29:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Rovio
[2011/01/19 01:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Sortasoft
[2011/08/26 21:35:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\SPORE
[2009/10/04 04:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\StoneLoops
[2011/02/05 03:35:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Teggo
[2010/06/19 22:28:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\The Path
[2010/12/22 05:03:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Unity
[2011/11/02 04:01:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\uTorrent
[2009/12/19 04:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\XemiComputers

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5FB7A2BD
@Alternate Data Stream - 169 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52A22573
@Alternate Data Stream - 167 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0FEE2B
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9D6EAEC3
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6E1F359F
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FEECF2C8
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:50DAB5A8
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8061242F
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BD27B7FC
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:247D483C
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DDEB08FD
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96BE5F33
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DA71AE7
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F6E5C7FB
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A96D3F23
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3251D01
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ADF211B1

< End of report >


And here's the Mbam report

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8079

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

11/4/2011 1:38:51 AM
mbam-log-2011-11-04 (01-38-51).txt

Scan type: Quick scan
Objects scanned: 162350
Time elapsed: 2 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Attached Files


  • 0

Advertisements


#17
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Total Files Cleaned = 6,626.00 mb This is why it appeared to freeze - a lot of junk files :)

How is the computer4 behaving now ? Any problems
  • 0

#18
Ninjajonas

Ninjajonas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
The computer looked to be ok, but earlier today AVG picked up a virus in an official EA / origin .exe file. located in C:\Program Files\Origin Games\The Sims 3 Pets Limited\__Installer\Sims3EP05Setup.exe (this file has been on the computer since the mid of october but just caught it today during an avast scan, so it wasn't until the system actually encountered the file, that AVG picked it up.)

This confused me a fair bit, i ran a quickscan with OTL. So far i just ignored it since it seems strange that it should be a real infection.
Could this have anything to do with having 2 Av's running?
Anyways here is the scan, and sorry for being late answering. I haven't had much time the last few days.



OTL logfile created on: 11/6/2011 9:26:41 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Louise\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.59 Gb Available Physical Memory | 79.82% Memory free
10.90 Gb Paging File | 10.24 Gb Available in Paging File | 93.92% Paging File free
Paging file location(s): C:\pagefile.sys 8000 16000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.31 Gb Total Space | 67.92 Gb Free Space | 34.78% Space Free | Partition Type: NTFS
Drive E: | 503.32 Gb Total Space | 64.68 Gb Free Space | 12.85% Space Free | Partition Type: NTFS
Drive F: | 549.52 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: COMPUTER | User Name: Louise | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Louise\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\ASUS\AASP\1.00.67\aaCenter.exe ()
PRC - C:\Program Files\ASUS\PC Probe II\Probe2.exe (ASUS)
PRC - C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
PRC - C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe (Realtek)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVAST Software\Avast\defs\11110601\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\11110601\aswRep.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\3963ce03d445a8619abbf388d590134b\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\b82c00e2d24305ad6cb08556e3779b75\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\11eb4f6606ba01e5128805759121ea6c\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\773a9786013451d3baaeff003dc4230f\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\63406259e94d5c0ff5b79401dfe113ce\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\3da96ee075bab9202626ae44c18d226c\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\80978a322d7dd39f0a71be1251ae395a\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\6d667f19d687361886990f3ca0f49816\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\Program Files\ASUS\AASP\1.00.67\aaCenter.exe ()
MOD - C:\Program Files\ASUS\AASP\1.00.67\aasp.dll ()
MOD - C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
MOD - C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.dll ()
MOD - C:\Program Files\ASUS\PC Probe II\cpuutil.dll ()
MOD - C:\Program Files\ASUS\AASP\1.00.67\cpuutil.dll ()
MOD - C:\Program Files\ASUS\AASP\1.00.67\PowNap.dll ()
MOD - C:\WINDOWS\system32\AsIO.dll ()
MOD - C:\Program Files\ASUS\PC Probe II\PowerDll.dll ()
MOD - C:\Program Files\ASUS\AASP\1.00.67\PowerDll.dll ()
MOD - C:\WINDOWS\system32\P17.dll ()
MOD - C:\Program Files\ASUS\PC Probe II\AsHtmlEngine.dll ()
MOD - C:\Program Files\ASUS\PC Probe II\SoundPlay.dll ()


========== Win32 Services (SafeList) ==========

SRV - (UleadBurningHelper) -- File not found
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (avgwd) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (dtsoftbus01) -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Almico Software)
DRV - (cpuz135) -- C:\WINDOWS\system32\drivers\cpuz135_x32.sys (CPUID)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (ithsgt) -- C:\WINDOWS\system32\drivers\ithsgt.sys ()
DRV - (lilsgt) -- C:\WINDOWS\system32\drivers\lilsgt.sys ()
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (hwusbfake) -- C:\WINDOWS\system32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (VIAHdAudAddService) -- C:\WINDOWS\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (monfilt) -- C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (AsIO) -- C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (Diag69xp) -- C:\WINDOWS\system32\drivers\diag69xp.sys (Realtek Semiconductor Corporation)
DRV - (RTLVLAN) -- C:\WINDOWS\system32\drivers\RTLVLAN.SYS (Realtek Semiconductor Corporation)
DRV - (LANPkt) -- C:\WINDOWS\system32\drivers\LANPkt.sys (Realtek Semiconductor Corporation)
DRV - (P17) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ULCDRHlp) -- C:\WINDOWS\system32\drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.dk/"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Louise\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/09/08 00:05:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/04 21:48:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/01 01:30:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/17 15:35:12 | 000,000,000 | ---D | M]

[2010/05/23 21:26:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Extensions
[2011/10/11 02:25:54 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\ybz4j5iu.default\extensions
[2010/06/09 22:41:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\ybz4j5iu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/11 02:25:54 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\ybz4j5iu.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/10/20 21:03:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/11 05:59:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/26 00:28:59 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/15 17:38:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/14 14:33:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/20 21:03:38 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/08 00:05:37 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011/11/04 21:48:54 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2010/07/11 05:59:34 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/01 01:30:06 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/11/04 00:58:46 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [8169Diag] C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe (Realtek)
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\Ai Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\Ai Suite\QFan3\QFanHelp.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [20090604] E:\Spil\Hoyle Puzzle and Board Games 2011\Ereg\encore_reg.exe /r "E:\Spil\Hoyle Puzzle and Board Games 2011\Ereg\encore_reg.rpd" File not found
O4 - HKCU..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe File not found
O4 - HKCU..\Run: [CreativeTaskScheduler] C:\Program Files\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe ()
O4 - HKCU..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer....r_installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://netbank.dans...B/e-Safekey.cab (e-Safekey)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...15108/CTPID.cab (Creative Software AutoUpdate Support Package)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:44:22 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/04/18 16:23:00 | 000,000,041 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{205c3e67-2587-11e0-9638-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{205c3e67-2587-11e0-9638-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{205c3e67-2587-11e0-9638-00248c45794b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{32d2b1ed-2406-11e0-9635-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{32d2b1ed-2406-11e0-9635-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{32d2b1ed-2406-11e0-9635-00248c45794b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{32d2b218-2406-11e0-9635-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{32d2b218-2406-11e0-9635-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{32d2b218-2406-11e0-9635-00248c45794b}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{4dbc24da-7b91-11de-929e-00248c45794b}\Shell\AutoRun\command - "" = BITLORD.EXE
O33 - MountPoints2\{a8525d9a-b1f6-11e0-9b62-00248c45794b}\Shell - "" = AutoRun
O33 - MountPoints2\{a8525d9a-b1f6-11e0-9b62-00248c45794b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a8525d9a-b1f6-11e0-9b62-00248c45794b}\Shell\AutoRun\command - "" = F:\SETUP.EXE -- [2001/04/30 18:33:00 | 000,032,768 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/04 00:58:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/11/03 22:24:41 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Louise\Desktop\OTL.exe
[2011/10/31 23:46:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Real Lives 2010
[2011/10/31 23:44:42 | 000,409,600 | ---- | C] (ActiveLock) -- C:\WINDOWS\System32\activelock1884.ocx
[2011/10/25 20:12:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Louise\Application Data\AVG2012
[2011/10/25 20:11:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2011/10/25 20:09:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/25 20:09:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2011/10/24 19:23:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/20 23:41:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Louise\Desktop\Moderations and Defaults
[2002/04/11 02:41:06 | 000,065,536 | R--- | C] ( ) -- C:\WINDOWS\System32\A3d.dll

========== Files - Modified Within 30 Days ==========

[2011/11/06 19:57:27 | 000,504,616 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/06 19:57:27 | 000,088,336 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/11/06 19:56:56 | 108,918,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/11/06 19:52:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/06 02:42:58 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/04 21:48:55 | 000,000,712 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/11/04 00:58:46 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/11/03 22:24:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Louise\Desktop\OTL.exe
[2011/11/01 21:07:49 | 000,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/31 23:23:37 | 000,000,469 | ---- | M] () -- C:\WINDOWS\QTW.INI
[2011/10/31 23:17:27 | 000,176,720 | ---- | M] () -- C:\WINDOWS\xobglu32.dll
[2011/10/31 23:17:27 | 000,063,488 | ---- | M] () -- C:\WINDOWS\xobglu16.dll
[2011/10/25 20:11:02 | 000,113,461 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/10/23 17:27:51 | 000,079,872 | ---- | M] () -- C:\Documents and Settings\Louise\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/20 23:26:40 | 000,001,072 | ---- | M] () -- C:\Documents and Settings\Louise\Desktop\TS3EP05.exe.lnk
[2011/10/20 21:04:42 | 000,001,839 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\The Sims™ 3 Pets.lnk
[2011/10/20 20:08:21 | 000,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Origin.lnk
[2011/10/17 00:15:18 | 000,002,359 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nudansk Ordbog 19.0.lnk

========== Files Created - No Company Name ==========

[2011/11/06 19:56:56 | 108,918,098 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/10/31 23:17:27 | 000,176,720 | ---- | C] () -- C:\WINDOWS\xobglu32.dll
[2011/10/31 23:17:27 | 000,063,488 | ---- | C] () -- C:\WINDOWS\xobglu16.dll
[2011/10/25 20:11:30 | 000,000,712 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/10/25 20:11:02 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/10/20 23:26:40 | 000,001,072 | ---- | C] () -- C:\Documents and Settings\Louise\Desktop\TS3EP05.exe.lnk
[2011/10/20 21:04:42 | 000,001,839 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\The Sims™ 3 Pets.lnk
[2011/08/18 00:45:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2011/06/01 23:15:11 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\QTUninst.dll
[2011/05/24 22:44:26 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
[2011/02/15 19:54:12 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2011/01/19 21:09:47 | 000,071,253 | ---- | C] () -- C:\WINDOWS\Huawei ModemsUninstall.exe
[2010/11/21 22:47:47 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2010/08/02 01:01:28 | 000,000,485 | ---- | C] () -- C:\WINDOWS\KingsC.ini
[2010/07/19 02:28:13 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2010/07/19 02:28:13 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2010/07/19 02:28:13 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2010/07/19 01:41:56 | 000,030,362 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
[2010/05/23 21:25:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/04/17 05:13:33 | 000,000,058 | -H-- | C] () -- C:\WINDOWS\popcreg.dat
[2010/04/17 05:13:33 | 000,000,044 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2010/04/02 16:17:34 | 000,179,091 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010/03/03 21:17:06 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/01/27 01:16:32 | 000,000,059 | ---- | C] () -- C:\WINDOWS\RUNAWAY.INI
[2010/01/04 10:55:38 | 000,004,492 | ---- | C] () -- C:\Documents and Settings\Louise\Application Data\mindhabits.dat
[2010/01/04 07:48:39 | 000,037,888 | ---- | C] () -- C:\WINDOWS\UninstallFaust.exe
[2010/01/04 07:37:32 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/12/26 06:08:17 | 000,000,458 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/12/23 15:23:59 | 000,000,241 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2009/12/21 19:36:01 | 000,162,432 | ---- | C] () -- C:\WINDOWS\System32\drivers\ithsgt.sys
[2009/12/21 19:36:00 | 000,012,032 | ---- | C] () -- C:\WINDOWS\System32\drivers\lilsgt.sys
[2009/11/05 10:09:53 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Louise\Local Settings\Application Data\fusioncache.dat
[2009/11/05 01:56:03 | 000,112,410 | ---- | C] () -- C:\WINDOWS\hpoins07.dat
[2009/11/05 01:56:03 | 000,021,124 | ---- | C] () -- C:\WINDOWS\hpomdl07.dat
[2009/10/13 00:40:42 | 000,000,469 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2009/10/10 01:47:41 | 000,271,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009/10/10 01:47:40 | 000,018,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009/10/02 17:33:53 | 000,017,385 | ---- | C] () -- C:\WINDOWS\agyheqek.sys
[2009/10/02 17:33:53 | 000,016,610 | ---- | C] () -- C:\WINDOWS\ywada.dat
[2009/10/02 17:33:53 | 000,014,275 | ---- | C] () -- C:\WINDOWS\System32\esexurica.dll
[2009/09/26 20:56:12 | 000,000,029 | ---- | C] () -- C:\WINDOWS\sfbm.INI
[2009/09/26 20:49:56 | 000,000,102 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2009/09/26 16:34:55 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\Dvbpws.dll
[2009/09/19 01:44:41 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2009/09/19 01:44:41 | 000,011,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\BdaSup.sys
[2009/09/18 22:59:19 | 000,078,085 | ---- | C] () -- C:\WINDOWS\System32\pattern.dat
[2009/09/18 22:59:11 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\fxstudio.dll
[2009/09/18 22:59:11 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\animation2.dll
[2009/08/16 02:04:37 | 000,939,712 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/07/21 03:32:59 | 000,593,920 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009/07/21 03:32:50 | 000,001,386 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2009/07/21 03:27:10 | 000,233,765 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/07/21 03:24:30 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/07/21 02:25:49 | 000,079,872 | ---- | C] () -- C:\Documents and Settings\Louise\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/10 20:28:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/06/10 20:27:52 | 000,286,904 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/10 20:04:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2009/06/10 19:29:30 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2009/06/10 19:29:30 | 000,012,400 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2009/06/10 19:29:25 | 000,011,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/06/10 19:29:25 | 000,010,216 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/06/10 18:50:05 | 000,026,909 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2009/06/10 18:49:41 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/06/10 18:49:27 | 000,026,146 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009/06/10 18:49:27 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/06/10 18:45:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/06/10 18:42:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/05/16 03:54:01 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2009/05/16 03:54:01 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2008/04/14 05:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006/12/31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/05/03 12:38:42 | 000,064,512 | R--- | C] () -- C:\WINDOWS\System32\P17.dll
[2003/10/02 11:48:18 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\P17CPI.dll
[2002/07/01 15:13:30 | 000,000,243 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\system16driver.dat
[2001/08/23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 12:00:00 | 000,504,616 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 12:00:00 | 000,088,336 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 12:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 12:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001/07/06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2001/04/01 19:16:48 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\fader.dll
[2000/11/08 01:37:42 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\drumpad.dll
[2000/03/29 01:58:40 | 000,280,576 | ---- | C] () -- C:\WINDOWS\System32\pxd_kom.dll
[2000/03/28 15:27:42 | 000,075,976 | ---- | C] () -- C:\WINDOWS\System32\BASSDEC.dll
[1996/04/03 20:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2011/08/14 14:56:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/10/25 20:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/24 19:26:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/11/11 03:42:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Beanbag Studios
[2011/05/23 23:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Birdstep Technology
[2009/10/04 15:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Brainiversity2
[2011/03/14 23:09:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/31 01:13:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CrioGames
[2010/02/10 02:16:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/06/15 10:52:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\e-Safekey
[2011/04/15 00:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA Core
[2011/07/04 00:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EA Logs
[2011/06/06 00:51:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/10/04 15:52:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy3
[2011/02/05 02:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2011/01/29 23:54:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Green Clover Games
[2011/08/18 02:22:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ice-Pick Lodge
[2010/03/07 05:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2011/02/13 06:25:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Merscom
[2011/11/06 19:56:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/30 23:06:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin
[2011/02/10 04:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/12/30 01:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2010/04/17 05:14:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/01/24 17:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/01/19 01:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sortasoft
[2011/10/26 20:25:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Soulseek
[2009/10/04 04:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\StoneLoops!
[2009/07/10 18:19:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SugarGames
[2011/10/24 19:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/23 15:54:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackMania United
[2009/09/26 19:08:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/06/10 19:39:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/01/22 23:30:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XLab
[2011/10/25 20:12:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\AVG2012
[2010/12/30 05:09:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Big Fish Games
[2011/02/15 01:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Braid
[2010/11/21 22:48:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\CheckPoint
[2009/06/13 15:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\DAEMON Tools Lite
[2009/10/04 02:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\ERS G-Studio
[2010/12/22 05:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Fabulous Finds
[2009/10/06 13:02:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\fretsonfire
[2009/07/12 00:39:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\funkitron
[2009/10/04 19:28:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Games
[2011/01/29 23:54:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Green Clover Games
[2011/01/24 00:17:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Hoyle FaceCreator
[2011/01/24 02:25:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Hoyle Puzzle and Board Games
[2009/12/25 01:57:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Hue Forest Entertainment
[2010/06/24 01:04:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\ImgBurn
[2010/06/24 00:48:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\InfraRecorder
[2010/03/07 05:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Ludia
[2011/02/10 05:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Magic Seeds
[2011/01/27 05:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Meridian93
[2011/02/13 06:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\MysteryStudio
[2011/10/20 20:09:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Origin
[2011/02/10 04:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\panoramik
[2011/02/10 04:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\PlayFirst
[2009/07/07 08:26:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Politiken
[2011/04/14 23:29:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Rovio
[2011/01/19 01:10:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Sortasoft
[2011/08/26 21:35:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\SPORE
[2009/10/04 04:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\StoneLoops
[2011/02/05 03:35:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Teggo
[2010/06/19 22:28:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\The Path
[2010/12/22 05:03:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\Unity
[2011/11/02 04:01:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\uTorrent
[2009/12/19 04:12:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Louise\Application Data\XemiComputers

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5FB7A2BD
@Alternate Data Stream - 169 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52A22573
@Alternate Data Stream - 167 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0FEE2B
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9D6EAEC3
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6E1F359F
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FEECF2C8
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:50DAB5A8
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8061242F
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BD27B7FC
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:247D483C
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DDEB08FD
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96BE5F33
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DA71AE7
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F6E5C7FB
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A96D3F23
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3251D01
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ADF211B1

< End of report >
  • 0

#19
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

earlier today AVG picked up a virus in an official EA / origin .exe file. located in C:\Program Files\Origin Games\The Sims 3 Pets Limited\__Installer\Sims3EP05Setup.exe (this file has been on the computer since the mid of october but just caught it today during an avast scan, so it wasn't until the system actually encountered the file, that AVG picked it up.)

This confused me a fair bit, i ran a quickscan with OTL. So far i just ignored it since it seems strange that it should be a real infection.
Could this have anything to do with having 2 Av's running?

Two AV's is not good as they will fight like cat and dog over system resources and may well miss something or lock the system up

Could you look in the Avast Virus chest and let me know what Avast classified it as, was it a PUP ?
  • 0

#20
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP