Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

System Restore Scareware [Closed]


  • This topic is locked This topic is locked

#1
cancer0707

cancer0707

    New Member

  • Member
  • Pip
  • 6 posts
Start menu options wipeout Prgrams (empty)
Multiple Windows-Delayed Write Failed Error once closed reappear within 20 minutes
Activated Guest user accout seeking relief. Follow me over there as well.
No Desktop Icons except My Computer & Recycle Bin

Your assistance is much appreciated. Cancer0707

OTL Extras logfile created on: 11/12/2011 7:29:05 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.98 Gb Total Physical Memory | 1.07 Gb Available Physical Memory | 53.78% Memory free
3.83 Gb Paging File | 3.13 Gb Available in Paging File | 81.65% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 16.40 Gb Free Space | 29.34% Space Free | Partition Type: NTFS
Drive F: | 465.65 Gb Total Space | 7.09 Gb Free Space | 1.52% Space Free | Partition Type: FAT32
Drive K: | 3.12 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: WHARTON-01 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"57096:TCP" = 57096:TCP:*:Enabled:Pando
"57096:UDP" = 57096:UDP:*:Enabled:Pando
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe" = C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe:*:Enabled:CyberLink PowerDVD 11.0 -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe" = C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe:*:Enabled:CyberLink PowerDVD 11.0 RC Service -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe" = C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe:*:Enabled:CyberLink Media Server -- (CyberLink)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Pando Networks\Pando\Pando.exe" = C:\Program Files\Pando Networks\Pando\Pando.exe:*:Enabled:Pando -- (Pando Networks)
"C:\Program Files\Barnes & Noble\NOOKstudy\NOOKstudy.exe" = C:\Program Files\Barnes & Noble\NOOKstudy\NOOKstudy.exe:*:Enabled:NOOKstudy -- (Barnes & Noble, Inc.)
"C:\Documents and Settings\user\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\user\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
"C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe" = C:\Program Files\CyberLink\PowerDVD11\PowerDVD11.exe:*:Enabled:CyberLink PowerDVD 11.0 -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe" = C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe:*:Enabled:CyberLink PowerDVD 11.0 RC Service -- (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe" = C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe:*:Enabled:CyberLink Media Server -- (CyberLink)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player -- ()
"C:\Program Files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe" = C:\Program Files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe:*:Enabled:Verizon Media Manager -- ()
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0F052922-4BCE-4763-A540-00857554336D}" = Redist
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX870_series" = Canon MX870 series MP Drivers
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{20EAC554-95F9-4926-8D9A-C4FF3EC44C72}" = AVG 2011
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 27
"{27614800-84A9-484E-9CCB-43ED2F1205F5}" = Chessmaster Grandmaster Edition
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{2BA09774-34F7-4A06-8C7E-B69E44CB9EB0}" = DriverBoost
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{581CE7EA-A30D-0000-1211-088635773309}" = Hawking Hi-Gain Wireless-G USB Dish Adapter
"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update
"{67625D2D-363B-4C33-9B28-5C500611FFBC}" = BlackBerry Desktop Software 4.1.1
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{695B13B2-7919-4EC5-8601-092F0D2DE069}" = AVG 2011
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{93249DC5-F4BC-4AF7-B4BF-E52927302B5E}" = AKME FFmpeg 0.7.9
"{93CF9FA6-2A5E-4F8E-923E-F7D8741CB312}" = BabasChess
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A66DBCC6-8802-3D15-9FDF-9552742C08B0}" = Google Talk Plugin
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AFE68D65-01D4-4B1A-902D-2660BC0C503F}" = Certblaster CompTIA Network+ (2009 Edition)
"{B1C2398C-6FAB-46D1-806C-5942F0829994}" = ParetoLogic Data Recovery
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CDC85536-A0EF-4401-82A6-25D8EFC7EFAC}" = VZAccess Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}" = OverDrive Media Console
"{D755C7A3-C03E-4460-8C00-AC6E55505FB5}" = LightScribe 1.4.74.1
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.9.347
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"{F240855E-57B8-4807-9A00-7047211D9793}" = Curitel PC Card Software
"{F7F23DFB-31E1-B7EC-7A6D-7668B595ADAE}" = FlipShare
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.12
"Astroburn Pro" = Astroburn Pro
"AVG" = AVG 2011
"Belarc Advisor" = Belarc Advisor 8.1
"BlackBerry_{67625D2D-363B-4C33-9B28-5C500611FFBC}" = BlackBerry Desktop Software 4.1.1
"CDuke_is1" = CDuke
"ClipboardHistory" = Clipboard History
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dasher" = Dasher
"DVD Decrypter" = DVD Decrypter (Remove Only)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"Firstload" = Firstload
"HP Photo & Imaging" = HP Image Zone 4.2
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = InCD
"InstallShield_{27614800-84A9-484E-9CCB-43ED2F1205F5}" = Chessmaster Grandmaster Edition
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer
"InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"Magic ISO Maker v5.5 (build 0261)" = Magic ISO Maker v5.5 (build 0261)
"MainApp.exe_is1" = CloneDVD 4.1.0.23
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"NOOKstudy" = NOOKstudy
"Recuva" = Recuva
"Scrabble" = Scrabble
"Search Toolbar" = Search Toolbar
"Storm Codec 5" = Storm Codec
"Total Audio Converter_is1" = TotalAudioConverter
"Verizon Media Manager" = Verizon Media Manager
"VLC media player" = VLC media player 1.1.11
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR 4.00 beta 3 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wondershare Video to DVD Burner_is1" = Wondershare Video to DVD Burner(Build 2.5.8.3)
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/4/2011 9:04:57 PM | Computer Name = WHARTON-01 | Source = Bonjour Service | ID = 100
Description =

Error - 5/4/2011 9:04:57 PM | Computer Name = WHARTON-01 | Source = Bonjour Service | ID = 100
Description =

Error - 5/4/2011 9:05:07 PM | Computer Name = WHARTON-01 | Source = Bonjour Service | ID = 100
Description =

Error - 5/4/2011 9:05:07 PM | Computer Name = WHARTON-01 | Source = Bonjour Service | ID = 100
Description =

Error - 5/4/2011 9:05:07 PM | Computer Name = WHARTON-01 | Source = Bonjour Service | ID = 100
Description =

Error - 5/5/2011 6:29:47 PM | Computer Name = WHARTON-01 | Source = Application Hang | ID = 1002
Description = Hanging application DesktopMgr.exe, version 4.1.1.9, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/5/2011 6:29:47 PM | Computer Name = WHARTON-01 | Source = Application Hang | ID = 1002
Description = Hanging application DesktopMgr.exe, version 4.1.1.9, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/8/2011 1:11:38 AM | Computer Name = WHARTON-01 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/8/2011 1:20:57 AM | Computer Name = WHARTON-01 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/9/2011 12:14:57 AM | Computer Name = WHARTON-01 | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ OSession Events ]
Error - 8/10/2011 3:46:37 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 35396
seconds with 2100 seconds of active time. This session ended with a crash.

Error - 8/10/2011 3:51:29 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 294
seconds with 60 seconds of active time. This session ended with a crash.

Error - 8/10/2011 6:22:52 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 8994
seconds with 1080 seconds of active time. This session ended with a crash.

Error - 8/11/2011 2:03:52 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 1633
seconds with 240 seconds of active time. This session ended with a crash.

Error - 8/22/2011 10:12:42 AM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 1214
seconds with 0 seconds of active time. This session ended with a crash.

Error - 8/29/2011 9:51:23 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7018
seconds with 180 seconds of active time. This session ended with a crash.

Error - 8/29/2011 10:39:52 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 14924
seconds with 120 seconds of active time. This session ended with a crash.

Error - 9/7/2011 1:22:59 AM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 2012
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/23/2011 6:54:15 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 126408
seconds with 60 seconds of active time. This session ended with a crash.

Error - 11/5/2011 8:50:40 PM | Computer Name = WHARTON-01 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 243
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11/10/2011 11:43:59 AM | Computer Name = WHARTON-01 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom2, has a bad block.

Error - 11/10/2011 11:44:06 AM | Computer Name = WHARTON-01 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom2, has a bad block.

Error - 11/10/2011 11:44:13 AM | Computer Name = WHARTON-01 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom2, has a bad block.

Error - 11/10/2011 11:44:20 AM | Computer Name = WHARTON-01 | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom2, has a bad block.

Error - 11/10/2011 1:05:54 PM | Computer Name = WHARTON-01 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC000007F'
while processing the file 'desktop.ini' on the volume 'HarddiskVolume3'. It has
stopped monitoring the volume.

Error - 11/10/2011 1:06:04 PM | Computer Name = WHARTON-01 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 11/11/2011 8:01:56 PM | Computer Name = WHARTON-01 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.3 for the Network Card with network
address 000E7B376F29 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 11/12/2011 7:54:44 PM | Computer Name = WHARTON-01 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.3 for the Network Card with network
address 000E7B376F29 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 11/12/2011 7:55:41 PM | Computer Name = WHARTON-01 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 11/12/2011 7:56:53 PM | Computer Name = WHARTON-01 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%5


< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there you posted the wrong part of OTL could you re-run it again with the following scripts please

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

Only one log will be generated please post that

Now to get the files and folders back : I will need two runs with this programme


RUN 1

Download RogueKiller to your desktop

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 2 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe

RUN 2

  • Quit all running programs
  • For Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • When prompted, type 6 and validate
  • The RKreport.txt shall be generated next to the executable.
  • If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.
  • 0

#3
cancer0707

cancer0707

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
After Rogue Killer Desktop background has returned however icons are absent.

Thanks a million. Attached File  RKreport2.txt   1.11KB   23 downloads


RogueKiller V6.1.8 [11/14/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: user [Admin rights]
Mode: Shortcuts HJfix -- Date : 11/16/2011 00:27:33

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 9 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 1640 / Fail 0
My documents: Success 31 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 318 / Fail 0
Backup: [FOUND] Success 17 / Fail 1

Drives:
[C:] \Device\HarddiskVolume1 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped
[E:] \Device\CdRom1 -- 0x5 --> Skipped
[K:] \Device\CdRom2 -- 0x5 --> Skipped

¤¤¤ Infection : Fake HDD ¤¤¤

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

OTL logfile created on: 11/16/2011 12:38:13 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.98 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.72% Memory free
3.83 Gb Paging File | 3.22 Gb Available in Paging File | 83.87% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 15.35 Gb Free Space | 27.47% Space Free | Partition Type: NTFS

Computer Name: WHARTON-01 | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/16 00:30:22 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
PRC - [2011/11/08 22:24:14 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/04/28 14:04:50 | 000,506,216 | ---- | M] (Outertech) -- C:\Program Files\ClipboardHistory\ClipboardHistory.exe
PRC - [2008/07/31 09:18:32 | 000,009,216 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/08 22:23:44 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/10/16 19:12:26 | 008,522,400 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2010/12/18 14:14:19 | 000,139,264 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2010/11/22 08:26:14 | 000,047,880 | ---- | M] () -- C:\Program Files\ClipboardHistory\ClipboardHotkey.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/04/19 22:56:47 | 000,083,240 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe -- (CLHNServiceForPowerDVD)
SRV - [2011/04/18 16:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/03/31 08:37:11 | 000,312,616 | ---- | M] (CyberLink) [Disabled | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe -- (CyberLink PowerDVD 11.0 Service)
SRV - [2011/03/31 08:37:06 | 000,070,952 | ---- | M] (CyberLink) [Disabled | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe -- (CyberLink PowerDVD 11.0 Monitor Service)
SRV - [2011/03/18 07:11:02 | 000,947,528 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2011/02/08 04:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2009/11/19 11:26:54 | 000,455,944 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
SRV - [2008/07/31 09:18:32 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2005/07/08 17:24:46 | 000,871,424 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2001/08/09 01:01:00 | 000,090,112 | ---- | M] (SEIKO EPSON CORPORATION) [Disabled | Stopped] -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)


========== Driver Services (SafeList) ==========

DRV - [2011/11/16 00:27:47 | 000,111,872 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TrueSight.sys -- (TrueSight)
DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/04/19 22:56:48 | 000,071,664 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys -- (ntk_PowerDVD)
DRV - [2011/04/14 20:28:42 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/04/12 04:16:53 | 000,077,296 | ---- | M] (CyberLink Corp.) [2011/06/21 01:17:02] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl -- ({329F96B6-DF1E-4328-BFDA-39EA953C1312})
DRV - [2011/04/04 23:59:56 | 000,297,168 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/04/04 00:11:42 | 000,431,672 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2011/03/16 15:03:20 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/03/01 13:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 07:13:02 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/10 06:53:54 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 06:53:52 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/07 05:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2009/05/25 14:43:58 | 000,032,408 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys -- (SMSIVZAM5)
DRV - [2008/07/31 09:18:32 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/02/27 13:49:00 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\BANTExt.sys -- (BANTExt)
DRV - [2008/01/07 07:36:16 | 002,216,064 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2007/04/09 00:25:20 | 000,005,888 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\PWCTLDRV.sys -- (PWCTLDRV)
DRV - [2007/04/06 02:49:26 | 000,039,808 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDWVsp.sys -- (PTDWVsp) Curitel PC Card Diagnostic Serial Port (UDP)
DRV - [2007/04/06 02:49:20 | 000,041,728 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDWMdm.sys -- (PTDWMdm) Curitel PC Card Drivers (UDP)
DRV - [2007/04/06 02:49:16 | 000,027,392 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDWBus.sys -- (PTDWBus) Curitel PC Card Composite Device driver (UDP)
DRV - [2005/10/28 10:38:18 | 000,402,432 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(Hawking)) Hawking Hi-Gain Wireless-G USB Dish Adapter(Hawking)
DRV - [2005/07/08 17:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005/07/08 17:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2005/07/08 10:17:31 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005/06/08 17:44:20 | 000,020,608 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BRGSp50.sys -- (BRGSp50)
DRV - [2004/11/11 07:05:16 | 000,276,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
DRV - [2004/10/25 12:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - [2004/03/23 21:12:34 | 000,017,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\nsndis5.sys -- (NSNDIS5)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]

IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://encrypted.google.com/ [binary data]
IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://encrypted.google.com/
IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.7.0190
FF - prefs.js..keyword.URL: "http://search.avg.co...s&lng=en-US&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Ringz Studio\Storm Codec\Plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Ringz Studio\Storm Codec\Plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\user\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\user\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVG\AVG10\Toolbar\Firefox\[email protected] [2011/05/30 22:45:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/08/09 12:10:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 20:40:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/11 20:40:41 | 000,000,000 | ---D | M]

[2010/12/29 21:23:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2011/11/11 19:05:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions
[2011/02/04 20:08:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/25 09:13:03 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/11/11 19:05:21 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/05 16:08:43 | 000,001,919 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\searchplugins\bing-zugo.xml
[2011/04/03 16:45:10 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\searchplugins\daemon-search.xml
[2011/11/08 22:25:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/12 00:00:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/11/08 22:24:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/07/19 04:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/06/30 13:30:14 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011/10/05 10:45:34 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/08 22:24:18 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2001/08/23 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\Ringz Studio\Storm Codec\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [UpdatePPShortCut] C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003..\Run: [ClipboardHistory] C:\Program Files\ClipboardHistory\ClipboardHistory.exe (Outertech)
O4 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} http://www.convergys...om/AppHardT.CAB (WNICheck2 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB07F66D-4F7B-4864-ACCB-EF35002DFD3D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBB8FAC4-20FC-4C37-BB83-5944FD24BFA7}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/28 14:27:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/11/16 00:30:21 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
[2011/11/16 00:20:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\RK_Quarantine
[2011/11/15 23:13:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/11/15 22:32:11 | 000,000,000 | --SD | C] -- C:\2ComboFix12302
[2011/11/15 22:20:27 | 000,000,000 | --SD | C] -- C:\2ComboFix
[2011/11/15 22:19:26 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/15 21:54:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Malwarebytes
[2011/11/15 21:53:10 | 000,000,000 | R--D | C] -- C:\Documents and Settings\user\Recent
[2011/11/15 19:38:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/15 19:38:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/11/15 19:38:33 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/15 19:38:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/15 07:15:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2011/11/13 22:17:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/11/13 22:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2011/11/13 22:16:37 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/11/13 22:08:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\GridinSoft Trojan Killer 2.0.9.7 [vokeon]
[2011/11/13 01:02:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Reimage Repair
[2011/11/13 01:02:11 | 000,000,000 | ---D | C] -- C:\rei
[2011/11/13 01:01:46 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage
[2011/11/13 01:01:06 | 000,261,360 | ---- | C] (Reimage®) -- C:\Documents and Settings\user\Desktop\ReimageRepair.exe
[2011/11/12 23:31:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\PCMichiana YouTube Series Virus Removal Package
[2011/11/12 23:05:18 | 001,564,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\user\Desktop\tdsskiller.exe
[2011/11/12 22:55:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GridinSoft
[2011/11/12 22:54:53 | 000,000,000 | ---D | C] -- C:\Program Files\GridinSoft Trojan Killer
[2011/11/12 22:50:15 | 022,011,960 | ---- | C] (GridinSoft, Inc. ) -- C:\Documents and Settings\user\Desktop\trojankiller2112-setup.exe
[2011/11/12 22:42:41 | 000,141,120 | ---- | C] (GridinSoft) -- C:\Documents and Settings\user\Desktop\unhider.exe
[2011/11/12 19:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Start Menu\Programs\System Restore
[2011/11/11 20:40:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/11/11 20:35:11 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011/11/10 10:20:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Ahead
[2011/10/27 23:01:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Astroburn Pro
[2011/10/27 23:01:40 | 000,000,000 | ---D | C] -- C:\Program Files\Astroburn Pro
[2011/10/27 23:01:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Astroburn Pro
[2011/10/27 23:01:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Astroburn Pro
[2011/10/27 20:41:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Internet Chess Club
[2011/10/27 20:41:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Internet Chess Club
[2011/10/27 20:41:09 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Chess Club
[2010/12/29 21:49:14 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\user\Application Data\pcouffin.sys
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\user\My Documents\*.tmp files -> C:\Documents and Settings\user\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/16 00:48:02 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1935655697-1343024091-1003UA.job
[2011/11/16 00:30:22 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
[2011/11/16 00:27:47 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/11/16 00:19:20 | 000,747,008 | ---- | M] () -- C:\Documents and Settings\user\Desktop\RogueKiller.exe
[2011/11/15 23:52:04 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/15 23:09:29 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/15 23:08:25 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/15 23:08:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/15 22:08:51 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/11/15 20:48:21 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/11/15 19:38:40 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/15 01:13:24 | 000,000,420 | ---- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{90F0C67A-DA24-49F4-8952-F0DE08699A15}.job
[2011/11/14 07:48:05 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1935655697-1343024091-1003Core.job
[2011/11/13 23:29:45 | 000,000,857 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/13 23:27:30 | 000,278,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/13 22:16:42 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\user\Desktop\NTREGOPT.lnk
[2011/11/13 22:16:42 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\user\Desktop\ERUNT.lnk
[2011/11/13 22:06:01 | 000,056,257 | ---- | M] () -- C:\Documents and Settings\user\Desktop\GridinS0ft Tr0jan Killar 2.0.9.7 Patch.rar
[2011/11/13 01:04:34 | 000,000,272 | ---- | M] () -- C:\WINDOWS\reimage.ini
[2011/11/13 01:03:12 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\Reimage Reminder.job
[2011/11/13 01:01:07 | 000,261,360 | ---- | M] (Reimage®) -- C:\Documents and Settings\user\Desktop\ReimageRepair.exe
[2011/11/13 00:31:08 | 000,230,179 | ---- | M] () -- C:\Documents and Settings\user\Desktop\trojankillerresults.jpg
[2011/11/12 23:27:41 | 041,264,744 | ---- | M] () -- C:\Documents and Settings\user\Desktop\PCMichiana-YouTube-Series-Virus-Removal-Package.zip
[2011/11/12 23:05:19 | 001,564,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\user\Desktop\tdsskiller.exe
[2011/11/12 22:51:04 | 022,011,960 | ---- | M] (GridinSoft, Inc. ) -- C:\Documents and Settings\user\Desktop\trojankiller2112-setup.exe
[2011/11/12 22:42:57 | 000,053,568 | ---- | M] () -- C:\Documents and Settings\user\Desktop\restore.exe
[2011/11/12 22:42:43 | 000,141,120 | ---- | M] (GridinSoft) -- C:\Documents and Settings\user\Desktop\unhider.exe
[2011/11/12 19:02:46 | 000,000,456 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\0dMY7gYC8kBLAi
[2011/11/12 19:01:42 | 000,000,296 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAi
[2011/11/12 19:01:42 | 000,000,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAir
[2011/11/12 19:01:31 | 000,000,839 | ---- | M] () -- C:\Documents and Settings\user\Desktop\System Restore.lnk
[2011/11/11 23:10:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/11 19:42:05 | 000,007,077 | ---- | M] () -- C:\WINDOWS\System32\0.6195734122855602.exe
[2011/11/10 21:50:03 | 000,436,186 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/10 21:50:02 | 000,068,916 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/11/10 12:22:51 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/11/09 01:37:17 | 000,001,057 | ---- | M] () -- C:\Documents and Settings\user\Application Data\vso_ts_preview.xml
[2011/11/08 22:37:55 | 000,196,096 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/27 20:00:43 | 000,002,353 | ---- | M] () -- C:\Documents and Settings\user\Desktop\BabasChess.lnk
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\user\My Documents\*.tmp files -> C:\Documents and Settings\user\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/16 00:26:59 | 000,001,766 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2011/11/16 00:26:59 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk
[2011/11/16 00:26:59 | 000,001,257 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2011/11/16 00:26:59 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/11/16 00:26:59 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/11/16 00:26:59 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/11/16 00:26:59 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/11/16 00:26:59 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/16 00:26:59 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2011/11/16 00:26:59 | 000,000,648 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/11/16 00:26:59 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/11/16 00:21:01 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/11/16 00:19:19 | 000,747,008 | ---- | C] () -- C:\Documents and Settings\user\Desktop\RogueKiller.exe
[2011/11/15 19:38:40 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/13 23:29:44 | 000,000,857 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/13 22:16:42 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\user\Desktop\NTREGOPT.lnk
[2011/11/13 22:16:42 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\user\Desktop\ERUNT.lnk
[2011/11/13 22:05:55 | 000,056,257 | ---- | C] () -- C:\Documents and Settings\user\Desktop\GridinS0ft Tr0jan Killar 2.0.9.7 Patch.rar
[2011/11/13 01:03:11 | 000,000,272 | ---- | C] () -- C:\WINDOWS\tasks\Reimage Reminder.job
[2011/11/13 01:03:06 | 000,000,272 | ---- | C] () -- C:\WINDOWS\reimage.ini
[2011/11/13 00:30:54 | 000,230,179 | ---- | C] () -- C:\Documents and Settings\user\Desktop\trojankillerresults.jpg
[2011/11/12 23:26:05 | 041,264,744 | ---- | C] () -- C:\Documents and Settings\user\Desktop\PCMichiana-YouTube-Series-Virus-Removal-Package.zip
[2011/11/12 22:42:56 | 000,053,568 | ---- | C] () -- C:\Documents and Settings\user\Desktop\restore.exe
[2011/11/12 19:01:42 | 000,000,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAir
[2011/11/12 19:01:41 | 000,000,296 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAi
[2011/11/12 19:01:31 | 000,000,839 | ---- | C] () -- C:\Documents and Settings\user\Desktop\System Restore.lnk
[2011/11/12 19:01:25 | 000,000,456 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\0dMY7gYC8kBLAi
[2011/11/11 20:35:17 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/11 19:41:58 | 000,007,077 | ---- | C] () -- C:\WINDOWS\System32\0.6195734122855602.exe
[2011/10/29 18:42:12 | 000,000,420 | ---- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{90F0C67A-DA24-49F4-8952-F0DE08699A15}.job
[2011/09/18 17:09:54 | 000,213,187 | ---- | C] () -- C:\Documents and Settings\user\Application Data\MMUpgrade.jpg
[2011/08/30 23:22:05 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/04/21 18:25:02 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\ZyDelReg.exe
[2011/04/21 18:24:58 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll
[2011/04/21 18:24:58 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL
[2011/03/27 16:37:35 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT
[2011/03/25 18:28:14 | 000,167,704 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/15 22:08:32 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\user\Application Data\vso_ts_preview.xml
[2011/01/03 12:08:39 | 000,058,952 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/12/31 11:58:09 | 000,196,096 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/30 12:48:59 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/12/30 07:46:30 | 000,103,535 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2010/12/30 07:46:30 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2010/12/29 21:49:23 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll
[2010/12/29 21:49:14 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\user\Application Data\ezpinst.exe
[2010/12/29 21:49:14 | 000,007,176 | ---- | C] () -- C:\Documents and Settings\user\Application Data\pcouffin.cat
[2010/12/29 21:49:14 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\user\Application Data\pcouffin.inf
[2010/12/29 21:22:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/12/29 21:13:07 | 000,000,361 | ---- | C] () -- C:\WINDOWS\lgfwup.ini
[2010/12/29 21:02:20 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2010/12/29 12:14:29 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2010/12/28 15:25:39 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2010/12/28 14:30:07 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/12/28 14:23:20 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/12/28 09:11:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/12/28 09:10:20 | 000,278,944 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/14 04:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/12/31 06:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2006/11/01 01:54:30 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/11/01 01:52:38 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/05/26 08:29:14 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2003/05/15 01:39:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002/05/14 23:58:38 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\v2k2_dec.dll
[2001/08/23 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,436,186 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,068,916 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/10/27 23:01:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astroburn Pro
[2011/01/09 20:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/08/09 12:09:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2011/01/29 21:43:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2011/08/02 12:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/08/16 09:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2010/12/29 23:04:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/03 16:44:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/04/03 16:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2011/08/16 09:04:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Boost
[2010/12/29 21:49:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DVDXStudio
[2011/01/02 23:56:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flip Video
[2011/06/21 00:05:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\install_clap
[2010/12/29 23:01:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/01/29 21:44:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/07/17 18:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/06/21 00:17:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PDVD
[2011/03/25 18:02:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/09/07 06:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2011/08/16 09:05:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UAB
[2011/06/28 06:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/04/04 07:20:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WEngineLite
[2011/01/03 06:12:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/01/03 12:01:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/03/23 01:02:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Amazon
[2011/10/27 23:01:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Astroburn Pro
[2011/09/06 21:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\AVG
[2010/12/29 23:08:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\AVG10
[2011/01/18 22:40:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Barnes & Noble
[2011/03/22 05:50:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Blackberry Desktop
[2011/08/16 09:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Canon
[2011/07/24 13:10:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Certblaster
[2011/04/04 06:37:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DAEMON Tools Lite
[2011/04/03 16:20:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DAEMON Tools Pro
[2011/02/05 16:08:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Easy MP3 Recorder
[2011/07/27 06:31:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Elluminate
[2011/08/11 00:00:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Firstload
[2011/10/27 20:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Internet Chess Club
[2011/08/29 21:26:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\OverDrive
[2011/03/25 18:11:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Research In Motion
[2011/01/29 21:38:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\SeriousBit
[2011/03/25 23:13:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Smith Micro
[2011/06/28 21:49:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Softplicity
[2011/07/18 05:35:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\TechWizard
[2011/11/11 18:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\uTorrent
[2011/11/09 01:37:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Vso
[2011/08/04 14:12:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\W Photo Studio Viewer
[2011/11/13 01:03:12 | 000,000,272 | ---- | M] () -- C:\WINDOWS\Tasks\Reimage Reminder.job
[2011/11/15 01:13:24 | 000,000,420 | ---- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{90F0C67A-DA24-49F4-8952-F0DE08699A15}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2011/01/15 15:22:02 | 001,593,856 | ---- | M] () -- C:\Houdini_15a_w32.exe
[2007/11/07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe


< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 04:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 04:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/14 04:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 04:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:0B4227B4

< End of report >

Attached Files


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Have you emptied the temporary files since you were infected ?
If so we may need to restore them manually.

If they do not return after this OTL run then follow the instructions at step 2

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
    IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
    IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
    IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
    IE - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 82 4A DA 16 78 0E 5E 49 BD 30 2E A7 B7 AC 8A F4 [binary data]
    O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
    O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
    O3 - HKU\S-1-5-21-436374069-1935655697-1343024091-1003\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    [2011/11/12 19:02:46 | 000,000,456 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\0dMY7gYC8kBLAi
    [2011/11/12 19:01:42 | 000,000,296 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAi
    [2011/11/12 19:01:42 | 000,000,224 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAir
    [2011/11/12 19:01:31 | 000,000,839 | ---- | M] () -- C:\Documents and Settings\user\Desktop\System Restore.lnk
    [2011/11/11 19:42:05 | 000,007,077 | ---- | M] () -- C:\WINDOWS\System32\0.6195734122855602.exe
    [2011/11/12 22:42:56 | 000,053,568 | ---- | C] () -- C:\Documents and Settings\user\Desktop\restore.exe
    [2011/11/12 19:01:42 | 000,000,224 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAir
    [2011/11/12 19:01:41 | 000,000,296 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~0dMY7gYC8kBLAi
    [2011/11/12 19:01:31 | 000,000,839 | ---- | C] () -- C:\Documents and Settings\user\Desktop\System Restore.lnk
    [2011/11/12 19:01:25 | 000,000,456 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\0dMY7gYC8kBLAi
    [2011/11/11 19:41:58 | 000,007,077 | ---- | C] () -- C:\WINDOWS\System32\0.6195734122855602.exe

    :Reg
    [HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-
    [HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-
    [HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-
    [HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
    XMLHTTP_UUID_Default=-

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

STEP 2

Restore Accessories Program Files Menu

Please download this tool here.

You will need to unzip the tool first.

Once you've unzipped the tool, please double-click on it to run it.

Ensure that the following check boxes are checked (as seen in this image below):

Posted Image


Once they are, click on the Restore button.



Restore Admin Tools Program Files Menu

Please download this tool here.

You will need to unzip the tool first.

Once you've unzipped the tool, please double-click on it to run it.

Click on the Restore Administrative Tools Items button.

As seen in this image below:

Posted Image


This next one will produce the necessary shortcut links which you can cut and paste into the start menu folder
Download the repair.vbs file to your destop
Run the repair.vbs
It will ask for a folder name call it recovery
The tool will let you know when it is finished
On the desktop will be a recovery folder
Open the folder
Cut and Paste the links that you want to C:\documents and settings\your name\start menu

Posted Image


Posted Image
  • 0

#5
cancer0707

cancer0707

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
EssexBoy Thank you for all you guidance. This is something I aspire to do. How did you get started?
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

This is something I aspire to do. How did you get started?

I trained here at GeekU, in my opinion (biased :) ) the best of the bunch... Once we are done here I will give you the link

Do you have all your folders/icons/menus etc back now ?




Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
  • 0

#7
cancer0707

cancer0707

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
How does one enroll in GeekU?
  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
First thing is to have no open malware topics - so how is the computer at the moment ?

GeekU details are here
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
User returned

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS /s
    C:\Windows\assembly\tmp\U\*.* /s
    %Temp%\smtmp\1\*.*
    %Temp%\smtmp\2\*.*
    %Temp%\smtmp\3\*.*
    %Temp%\smtmp\4\*.*
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
User returned
  • 0

#13
cancer0707

cancer0707

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
OTL logfile created on: 12/10/2011 11:23:33 AM - Run 2

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\user\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy



1.98 Gb Total Physical Memory | 1.60 Gb Available Physical Memory | 80.61% Memory free

3.83 Gb Paging File | 3.64 Gb Available in Paging File | 94.80% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]



%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 55.89 Gb Total Space | 6.03 Gb Free Space | 10.78% Space Free | Partition Type: NTFS

Drive F: | 15.69 Gb Total Space | 5.49 Gb Free Space | 35.00% Space Free | Partition Type: FAT32

Drive G: | 465.65 Gb Total Space | 7.10 Gb Free Space | 1.53% Space Free | Partition Type: FAT32

Drive H: | 244.14 Gb Total Space | 244.07 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Drive J: | 111.76 Gb Total Space | 0.13 Gb Free Space | 0.12% Space Free | Partition Type: FAT32



Computer Name: WHARTON-01 | User Name: user | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days



========== Processes (SafeList) ==========



PRC - [2011/11/16 00:30:22 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe

PRC - [2011/04/19 22:56:48 | 000,234,792 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe

PRC - [2010/12/29 21:13:56 | 000,557,056 | ---- | M] (BitLeader) -- C:\Program Files\lg_fwupdate\fwupdate.exe

PRC - [2009/03/10 22:18:14 | 000,934,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WgaTray.exe

PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2006/05/09 09:31:36 | 000,483,328 | ---- | M] () -- C:\Program Files\Hawking\HWU8DD\HWU8DD.exe

PRC - [2005/07/08 17:24:46 | 000,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe

PRC - [2004/11/02 20:24:46 | 000,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe





========== Modules (No Company Name) ==========



MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

MOD - [2010/12/18 14:14:19 | 000,139,264 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll

MOD - [2006/11/30 14:03:46 | 000,434,688 | ---- | M] () -- C:\Program Files\TotalAudioConverter\axTotalConverter.dll

MOD - [2006/05/09 09:31:36 | 000,483,328 | ---- | M] () -- C:\Program Files\Hawking\HWU8DD\HWU8DD.exe

MOD - [2006/05/09 09:31:22 | 000,045,056 | ---- | M] () -- C:\Program Files\Hawking\HWU8DD\ZDWlan.dll

MOD - [2005/09/21 20:39:52 | 000,212,992 | ---- | M] () -- C:\Program Files\Hawking\HWU8DD\dot1x_dll.dll

MOD - [2004/03/05 14:00:58 | 000,155,648 | ---- | M] () -- C:\Program Files\Hawking\HWU8DD\ssleay32.dll

MOD - [2004/03/05 14:00:26 | 000,827,392 | ---- | M] () -- C:\Program Files\Hawking\HWU8DD\libeay32.dll





========== Win32 Services (SafeList) ==========



SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2011/04/19 22:56:47 | 000,083,240 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe -- (CLHNServiceForPowerDVD)

SRV - [2011/03/31 08:37:11 | 000,312,616 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe -- (CyberLink PowerDVD 11.0 Service)

SRV - [2011/03/31 08:37:06 | 000,070,952 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe -- (CyberLink PowerDVD 11.0 Monitor Service)

SRV - [2009/11/19 11:26:54 | 000,455,944 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)

SRV - [2008/07/31 09:18:32 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)

SRV - [2005/07/08 17:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)

SRV - [2001/08/09 01:01:00 | 000,090,112 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe -- (EPSONStatusAgent2)





========== Driver Services (SafeList) ==========



DRV - [2011/11/16 00:27:47 | 000,111,872 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TrueSight.sys -- (TrueSight)

DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)

DRV - [2011/04/19 22:56:48 | 000,071,664 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys -- (ntk_PowerDVD)

DRV - [2011/04/12 04:16:53 | 000,077,296 | ---- | M] (CyberLink Corp.) [2011/06/21 01:17:02] [Kernel | Auto | Running] -- C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl -- ({329F96B6-DF1E-4328-BFDA-39EA953C1312})

DRV - [2011/04/04 00:11:42 | 000,431,672 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)

DRV - [2009/05/25 14:43:58 | 000,032,408 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys -- (SMSIVZAM5)

DRV - [2008/07/31 09:18:32 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)

DRV - [2008/02/27 13:49:00 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\BANTExt.sys -- (BANTExt)

DRV - [2008/01/07 07:36:16 | 002,216,064 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®

DRV - [2007/04/09 00:25:20 | 000,005,888 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\PWCTLDRV.sys -- (PWCTLDRV)

DRV - [2007/04/06 02:49:26 | 000,039,808 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDWVsp.sys -- (PTDWVsp) Curitel PC Card Diagnostic Serial Port (UDP)

DRV - [2007/04/06 02:49:20 | 000,041,728 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDWMdm.sys -- (PTDWMdm) Curitel PC Card Drivers (UDP)

DRV - [2007/04/06 02:49:16 | 000,027,392 | ---- | M] (DEVGURU Co,LTD.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PTDWBus.sys -- (PTDWBus) Curitel PC Card Composite Device driver (UDP)

DRV - [2005/10/28 10:38:18 | 000,402,432 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(Hawking)) Hawking Hi-Gain Wireless-G USB Dish Adapter(Hawking)

DRV - [2005/07/08 17:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)

DRV - [2005/07/08 17:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)

DRV - [2005/07/08 10:17:31 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)

DRV - [2005/06/08 17:44:20 | 000,020,608 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BRGSp50.sys -- (BRGSp50)

DRV - [2004/11/11 07:05:16 | 000,276,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)

DRV - [2004/10/25 12:40:58 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50)

DRV - [2004/03/23 21:12:34 | 000,017,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\nsndis5.sys -- (NSNDIS5)





========== Standard Registry (SafeList) ==========





========== Internet Explorer ==========





IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://encrypted.google.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://encrypted.google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default =

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



========== FireFox ==========



FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"

FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"

FF - prefs.js..browser.search.update: false

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23

FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220

FF - prefs.js..extensions.enabledItems: [email protected]:1.0

FF - prefs.js..extensions.enabledItems: [email protected]:1.1.7.0190

FF - prefs.js..keyword.URL: "http://search.avg.co...s&lng=en-US&q="

FF - prefs.js..network.proxy.type: 0





FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Ringz Studio\Storm Codec\Plugins\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Ringz Studio\Storm Codec\Plugins\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)

FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\user\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)

FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\user\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)



FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVG\AVG10\Toolbar\Firefox\[email protected]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/11/27 23:01:31 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 20:40:42 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/11 20:40:41 | 000,000,000 | ---D | M]



[2010/12/29 21:23:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions

[2011/11/11 19:05:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions

[2011/02/04 20:08:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011/10/25 09:13:03 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

[2011/11/11 19:05:21 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

[2011/11/27 19:03:25 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\extensions\[email protected]

[2011/02/05 16:08:43 | 000,001,919 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\searchplugins\bing-zugo.xml

[2011/04/03 16:45:10 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\5ngncxbx.default\searchplugins\daemon-search.xml

[2011/11/08 22:25:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2011/10/12 00:00:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}

[2011/11/08 22:24:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll

[2011/07/19 04:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll

[2011/06/30 13:30:14 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll

[2011/10/05 10:45:34 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml

[2011/11/08 22:24:18 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml



========== Chrome ==========



CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.121\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll

CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll

CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll

CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll

CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Ringz Studio\Storm Codec\plugins\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Ringz Studio\Storm Codec\plugins\nprpjplug.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll

CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.121\pdf.dll

CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1390_0\plugins/avgnpss.dll

CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\user\Application Data\Mozilla\plugins\npgoogletalk.dll

CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\user\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll

CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll

CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll

CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

CHR - plugin: DocuCom PDF Plus (Enabled) = C:\Program Files\Nuance\PDF Reader\bin\nppdf.dll

CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

CHR - Extension: Classic = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0\

CHR - Extension: avast! WebRep = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1289_0\

CHR - Extension: Play Chess vs. the Computer = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jigmpephianlpnfdadfimdeiebbkoggb\1_0\

CHR - Extension: AVG Safe Search = C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1390_0\



O1 HOSTS File: ([2011/12/02 03:45:57 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.

O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui File not found

O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe File not found

O4 - HKLM..\Run: [LGODDFU] C:\Program Files\lg_fwupdate\fwupdate.exe (BitLeader)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\Ringz Studio\Storm Codec\qttask.exe (Apple Inc.)

O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)

O4 - HKLM..\Run: [RemoteControl11] C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe (CyberLink Corp.)

O4 - HKLM..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti File not found

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe (Research In Motion Limited)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE (SEIKO EPSON CORPORATION)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Hawking Wireless Utility.lnk = C:\Program Files\Hawking\HWU8DD\HWU8DD.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)

O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} http://www.convergys...om/AppHardT.CAB (WNICheck2 Class)

O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB07F66D-4F7B-4864-ACCB-EF35002DFD3D}: DhcpNameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBB8FAC4-20FC-4C37-BB83-5944FD24BFA7}: DhcpNameServer = 192.168.1.1

O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll File not found

O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010/12/28 14:27:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2008/04/01 13:53:24 | 000,000,071 | -H-- | M] () - G:\autorun.inf -- [ FAT32 ]

O32 - AutoRun File - [2008/04/09 19:43:54 | 000,000,000 | -H-D | M] - G:\autorun -- [ FAT32 ]

O32 - AutoRun File - [2006/12/23 20:57:16 | 000,000,000 | ---D | M] - J:\autorun -- [ FAT32 ]

O32 - AutoRun File - [2005/11/15 12:08:04 | 000,000,036 | -H-- | M] () - J:\autorun.inf -- [ FAT32 ]

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*



========== Files/Folders - Created Within 30 Days ==========



[2011/12/02 05:27:22 | 000,000,000 | ---D | C] -- C:\ubuntu

[2011/12/02 05:00:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\DAEMON Tools Images

[2011/12/02 03:55:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\AskToolbar

[2011/11/27 23:31:53 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipnat.sys

[2011/11/27 22:23:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\NetInfo

[2011/11/27 22:23:37 | 000,000,000 | ---D | C] -- C:\Program Files\Tsarfin Computing

[2011/11/27 22:20:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\GetRightToGo

[2011/11/27 20:03:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\New Folder

[2011/11/27 19:03:13 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com

[2011/11/27 18:59:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Glary Utilities

[2011/11/27 18:59:47 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities

[2011/11/26 19:06:40 | 000,000,000 | ---D | C] -- C:\spoolerlogs

[2011/11/26 13:31:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome

[2011/11/26 13:26:15 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software

[2011/11/26 13:26:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software

[2011/11/26 11:07:32 | 000,000,000 | ---D | C] -- C:\Program Files\15D2D

[2011/11/26 11:06:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\EC715

[2011/11/26 11:06:28 | 000,000,000 | ---D | C] -- C:\Program Files\LP

[2011/11/26 11:06:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\QkkWSC6jAXym5m

[2011/11/26 11:06:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\HcYYHaxTGpRBoD

[2011/11/26 11:06:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\VsscH0qTG

[2011/11/26 11:05:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\UDDV7ikWCuQ

[2011/11/24 08:59:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Nuance

[2011/11/23 20:01:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Zeon

[2011/11/23 20:01:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nuance

[2011/11/23 20:01:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Nuance

[2011/11/23 20:00:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ScanSoft

[2011/11/23 20:00:45 | 000,000,000 | ---D | C] -- C:\Program Files\Nuance

[2011/11/23 20:00:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FLEXnet

[2011/11/23 20:00:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Downloaded Installations

[2011/11/23 19:59:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Fighters

[2011/11/23 19:58:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Fighters

[2011/11/23 19:58:23 | 000,000,000 | ---D | C] -- C:\Program Files\Free Offers from Freeze.com

[2011/11/23 07:52:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Auslogics

[2011/11/23 07:52:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics

[2011/11/23 07:52:42 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics

[2011/11/23 00:58:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\user\Recent

[2011/11/23 00:44:19 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner

[2011/11/20 09:02:44 | 004,422,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc100u.dll

[2011/11/20 09:02:44 | 000,773,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr100.dll

[2011/11/20 09:02:44 | 000,081,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfcm100.dll

[2011/11/20 09:02:42 | 000,421,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp100.dll

[2011/11/20 09:02:40 | 004,397,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc100.dll

[2011/11/20 09:02:40 | 000,034,912 | ---- | C] (Tsarfin Computing Ltd) -- C:\WINDOWS\System32\TCBaseAPI.dll

[2011/11/19 16:56:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth

[2011/11/19 13:52:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\recovery

[2011/11/19 11:16:16 | 000,000,000 | ---D | C] -- C:\_OTL

[2011/11/16 00:30:21 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe

[2011/11/16 00:20:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\RK_Quarantine

[2011/11/15 22:32:11 | 000,000,000 | --SD | C] -- C:\2ComboFix12302

[2011/11/15 22:20:27 | 000,000,000 | --SD | C] -- C:\2ComboFix

[2011/11/15 22:19:26 | 000,000,000 | ---D | C] -- C:\Qoobox

[2011/11/15 21:54:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Malwarebytes

[2011/11/15 19:38:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/11/15 19:38:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2011/11/15 19:38:33 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2011/11/15 19:38:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2011/11/15 07:15:28 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC

[2011/11/13 22:17:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2011/11/13 22:16:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT

[2011/11/13 22:16:37 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT

[2011/11/13 22:08:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\GridinSoft Trojan Killer 2.0.9.7 [vokeon]

[2011/11/13 01:02:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Reimage Repair

[2011/11/13 01:02:11 | 000,000,000 | ---D | C] -- C:\rei

[2011/11/13 01:01:46 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage

[2011/11/13 01:01:06 | 000,261,360 | ---- | C] (Reimage®) -- C:\Documents and Settings\user\Desktop\ReimageRepair.exe

[2011/11/12 23:31:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\PCMichiana YouTube Series Virus Removal Package

[2011/11/12 23:05:18 | 001,564,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\user\Desktop\tdsskiller.exe

[2011/11/12 22:55:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GridinSoft

[2011/11/12 22:54:53 | 000,000,000 | ---D | C] -- C:\Program Files\GridinSoft Trojan Killer

[2011/11/12 22:50:15 | 022,011,960 | ---- | C] (GridinSoft, Inc. ) -- C:\Documents and Settings\user\Desktop\trojankiller2112-setup.exe

[2011/11/12 22:42:41 | 000,141,120 | ---- | C] (GridinSoft) -- C:\Documents and Settings\user\Desktop\unhider.exe

[2011/11/12 19:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Start Menu\Programs\System Restore

[2011/11/11 20:40:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime

[2011/11/11 20:35:11 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update

[2010/12/29 21:49:14 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\user\Application Data\pcouffin.sys

[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[2 C:\Documents and Settings\user\My Documents\*.tmp files -> C:\Documents and Settings\user\My Documents\*.tmp -> ]



========== Files - Modified Within 30 Days ==========



[2011/12/10 11:25:34 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{90F0C67A-DA24-49F4-8952-F0DE08699A15}.job

[2011/12/10 11:24:36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/12/10 11:21:58 | 000,000,361 | ---- | M] () -- C:\WINDOWS\lgfwup.ini

[2011/12/10 11:21:33 | 000,000,310 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job

[2011/12/10 11:21:30 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/12/10 11:21:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/12/06 23:01:00 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

[2011/12/06 22:52:10 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/12/06 22:48:11 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1935655697-1343024091-1003UA.job

[2011/12/02 06:06:17 | 000,134,978 | ---- | M] () -- C:\wubildr

[2011/12/02 05:32:20 | 000,000,238 | -HS- | M] () -- C:\boot.ini

[2011/12/02 05:32:14 | 000,008,192 | ---- | M] () -- C:\wubildr.mbr

[2011/12/02 05:26:19 | 000,000,000 | RHS- | M] () -- C:\CONFIG.SYS

[2011/12/02 03:45:57 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2011/12/01 07:48:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1935655697-1343024091-1003Core.job

[2011/11/29 07:43:07 | 000,197,120 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/11/27 22:23:42 | 000,002,122 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\NetInfo.lnk

[2011/11/27 20:06:09 | 000,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak

[2011/11/27 18:59:58 | 000,000,741 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Glary Utilities.lnk

[2011/11/26 22:58:51 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT

[2011/11/26 18:47:38 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/11/26 13:51:23 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2011/11/26 13:31:22 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk

[2011/11/25 23:10:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2011/11/23 20:01:11 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nuance PDF Reader.lnk

[2011/11/23 19:58:24 | 000,001,613 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Free Music Downloads.lnk

[2011/11/23 19:58:24 | 000,001,613 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Free Dolphin Screensaver.lnk

[2011/11/23 19:58:24 | 000,001,603 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Free Games!!.lnk

[2011/11/23 19:55:42 | 000,000,992 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Install 7-Zip.lnk

[2011/11/23 07:52:43 | 000,000,899 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Auslogics Disk Defrag.lnk

[2011/11/23 00:44:22 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk

[2011/11/22 21:32:32 | 000,000,932 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Continue FoxTab PDF Converter Installation.lnk

[2011/11/20 09:02:44 | 004,422,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc100u.dll

[2011/11/20 09:02:44 | 000,773,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr100.dll

[2011/11/20 09:02:44 | 000,081,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mfcm100.dll

[2011/11/20 09:02:42 | 000,421,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp100.dll

[2011/11/20 09:02:40 | 004,397,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc100.dll

[2011/11/20 09:02:40 | 000,034,912 | ---- | M] (Tsarfin Computing Ltd) -- C:\WINDOWS\System32\TCBaseAPI.dll

[2011/11/19 16:56:22 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/11/19 13:51:56 | 000,002,258 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Repair.vbs

[2011/11/19 13:49:42 | 000,000,055 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Windows XP Tips - Ramesh.url

[2011/11/16 03:22:54 | 000,278,944 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2011/11/16 00:30:22 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe

[2011/11/16 00:27:47 | 000,111,872 | ---- | M] () -- C:\WINDOWS\System32\drivers\TrueSight.sys

[2011/11/16 00:19:20 | 000,747,008 | ---- | M] () -- C:\Documents and Settings\user\Desktop\RogueKiller.exe

[2011/11/15 19:38:40 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/11/13 23:29:45 | 000,000,857 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk

[2011/11/13 22:16:42 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\user\Desktop\NTREGOPT.lnk

[2011/11/13 22:16:42 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\user\Desktop\ERUNT.lnk

[2011/11/13 22:06:01 | 000,056,257 | ---- | M] () -- C:\Documents and Settings\user\Desktop\GridinS0ft Tr0jan Killar 2.0.9.7 Patch.rar

[2011/11/13 01:04:34 | 000,000,272 | ---- | M] () -- C:\WINDOWS\reimage.ini

[2011/11/13 01:01:07 | 000,261,360 | ---- | M] (Reimage®) -- C:\Documents and Settings\user\Desktop\ReimageRepair.exe

[2011/11/13 00:31:08 | 000,230,179 | ---- | M] () -- C:\Documents and Settings\user\Desktop\trojankillerresults.jpg

[2011/11/12 23:27:41 | 041,264,744 | ---- | M] () -- C:\Documents and Settings\user\Desktop\PCMichiana-YouTube-Series-Virus-Removal-Package.zip

[2011/11/12 23:05:19 | 001,564,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\user\Desktop\tdsskiller.exe

[2011/11/12 22:51:04 | 022,011,960 | ---- | M] (GridinSoft, Inc. ) -- C:\Documents and Settings\user\Desktop\trojankiller2112-setup.exe

[2011/11/12 22:42:43 | 000,141,120 | ---- | M] (GridinSoft) -- C:\Documents and Settings\user\Desktop\unhider.exe

[2011/11/10 21:50:03 | 000,436,186 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/11/10 21:50:02 | 000,068,916 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/11/10 12:22:51 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[2 C:\Documents and Settings\user\My Documents\*.tmp files -> C:\Documents and Settings\user\My Documents\*.tmp -> ]



========== Files Created - No Company Name ==========



[2011/12/02 06:06:17 | 000,134,978 | ---- | C] () -- C:\wubildr

[2011/12/02 05:32:14 | 000,008,192 | ---- | C] () -- C:\wubildr.mbr

[2011/11/27 22:23:42 | 000,002,122 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\NetInfo.lnk

[2011/11/27 20:03:56 | 000,011,445 | ---- | C] () -- C:\Documents and Settings\user\My Documents\LSPFix-source.zip

[2011/11/27 20:03:43 | 000,011,445 | ---- | C] () -- C:\LSPFix-source.zip

[2011/11/27 19:57:56 | 002,101,817 | ---- | C] () -- C:\Documents and Settings\user\My Documents\ICRTool.exe

[2011/11/27 19:03:22 | 000,000,232 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

[2011/11/27 19:00:03 | 000,000,310 | ---- | C] () -- C:\WINDOWS\tasks\GlaryInitialize.job

[2011/11/27 18:59:58 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Glary Utilities.lnk

[2011/11/26 23:08:37 | 000,001,741 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk

[2011/11/26 23:08:37 | 000,001,576 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Hawking Wireless Utility.lnk

[2011/11/26 23:08:37 | 000,000,947 | ---- | C] () -- C:\Documents and Settings\user\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk

[2011/11/26 23:08:37 | 000,000,893 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk

[2011/11/26 13:31:22 | 000,001,791 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2011/11/26 13:31:21 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk

[2011/11/23 20:01:11 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nuance PDF Reader.lnk

[2011/11/23 19:58:24 | 000,001,613 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Free Dolphin Screensaver.lnk

[2011/11/23 19:58:24 | 000,001,603 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Free Games!!.lnk

[2011/11/23 19:58:23 | 000,001,613 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Free Music Downloads.lnk

[2011/11/23 19:55:42 | 000,000,992 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Install 7-Zip.lnk

[2011/11/23 07:52:43 | 000,000,899 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Auslogics Disk Defrag.lnk

[2011/11/23 00:44:22 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk

[2011/11/22 21:32:32 | 000,000,932 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Continue FoxTab PDF Converter Installation.lnk

[2011/11/19 16:56:22 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/11/19 13:51:55 | 000,002,258 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Repair.vbs

[2011/11/19 13:49:42 | 000,000,055 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Windows XP Tips - Ramesh.url

[2011/11/19 13:49:25 | 000,032,768 | ---- | C] () -- C:\Documents and Settings\user\Desktop\AdminTools.exe

[2011/11/19 13:47:21 | 000,061,440 | ---- | C] () -- C:\Documents and Settings\user\Desktop\AccRestore.exe

[2011/11/16 00:26:59 | 000,001,766 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk

[2011/11/16 00:26:59 | 000,001,653 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Decrypter.lnk

[2011/11/16 00:26:59 | 000,001,257 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk

[2011/11/16 00:26:59 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk

[2011/11/16 00:26:59 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk

[2011/11/16 00:26:59 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2011/11/16 00:26:59 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk

[2011/11/16 00:26:59 | 000,000,648 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk

[2011/11/16 00:26:59 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

[2011/11/16 00:21:01 | 000,111,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\TrueSight.sys

[2011/11/16 00:19:19 | 000,747,008 | ---- | C] () -- C:\Documents and Settings\user\Desktop\RogueKiller.exe

[2011/11/15 19:38:40 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/11/13 23:29:44 | 000,000,857 | ---- | C] () -- C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk

[2011/11/13 22:16:42 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\user\Desktop\NTREGOPT.lnk

[2011/11/13 22:16:42 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\user\Desktop\ERUNT.lnk

[2011/11/13 22:05:55 | 000,056,257 | ---- | C] () -- C:\Documents and Settings\user\Desktop\GridinS0ft Tr0jan Killar 2.0.9.7 Patch.rar

[2011/11/13 01:03:06 | 000,000,272 | ---- | C] () -- C:\WINDOWS\reimage.ini

[2011/11/13 00:30:54 | 000,230,179 | ---- | C] () -- C:\Documents and Settings\user\Desktop\trojankillerresults.jpg

[2011/11/12 23:26:05 | 041,264,744 | ---- | C] () -- C:\Documents and Settings\user\Desktop\PCMichiana-YouTube-Series-Virus-Removal-Package.zip

[2011/11/11 20:35:17 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2011/09/18 17:09:54 | 000,213,187 | ---- | C] () -- C:\Documents and Settings\user\Application Data\MMUpgrade.jpg

[2011/08/30 23:22:05 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/04/21 18:25:02 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\ZyDelReg.exe

[2011/04/21 18:24:58 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD.dll

[2011/04/21 18:24:58 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\InsDrvZD64.DLL

[2011/03/27 16:37:35 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT

[2011/03/25 18:28:14 | 000,167,704 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2011/02/15 22:08:32 | 000,001,057 | ---- | C] () -- C:\Documents and Settings\user\Application Data\vso_ts_preview.xml

[2011/01/03 12:08:39 | 000,058,952 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat

[2010/12/31 11:58:09 | 000,197,120 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/12/30 12:48:59 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2010/12/30 07:46:30 | 000,103,535 | ---- | C] () -- C:\WINDOWS\hpoins04.dat

[2010/12/30 07:46:30 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat

[2010/12/29 21:49:23 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo3.dll

[2010/12/29 21:49:14 | 000,081,920 | ---- | C] () -- C:\Documents and Settings\user\Application Data\ezpinst.exe

[2010/12/29 21:49:14 | 000,007,176 | ---- | C] () -- C:\Documents and Settings\user\Application Data\pcouffin.cat

[2010/12/29 21:49:14 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\user\Application Data\pcouffin.inf

[2010/12/29 21:22:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2010/12/29 21:13:07 | 000,000,361 | ---- | C] () -- C:\WINDOWS\lgfwup.ini

[2010/12/29 21:02:20 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe

[2010/12/29 12:14:29 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys

[2010/12/28 15:25:39 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll

[2010/12/28 14:30:07 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2010/12/28 14:23:20 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2010/12/28 09:11:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2010/12/28 09:10:20 | 000,278,944 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2008/04/14 04:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2008/02/19 01:33:34 | 000,446,352 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll

[2006/12/31 06:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2006/11/01 01:54:30 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2006/11/01 01:52:38 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2006/05/26 08:29:14 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2004/08/04 03:07:00 | 000,001,999 | ---- | C] () -- C:\WINDOWS\System32\netcache32.sys

[2003/05/15 01:39:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2002/05/14 23:58:38 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\v2k2_dec.dll

[2001/08/23 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2001/08/23 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2001/08/23 07:00:00 | 000,436,186 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2001/08/23 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2001/08/23 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2001/08/23 07:00:00 | 000,068,916 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2001/08/23 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2001/08/23 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2001/08/23 07:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2001/08/23 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat



========== Alternate Data Streams ==========



@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:0B4227B4



< End of report >
  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
What are your current problems

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default =
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    [2011/11/26 11:07:32 | 000,000,000 | ---D | C] -- C:\Program Files\15D2D
    [2011/11/26 11:06:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\EC715
    [2011/11/26 11:06:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\QkkWSC6jAXym5m
    [2011/11/26 11:06:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\HcYYHaxTGpRBoD
    [2011/11/26 11:06:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\VsscH0qTG
    [2011/11/26 11:05:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\UDDV7ikWCuQ

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP