Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Possible Virus Infection [Closed]


  • This topic is locked This topic is locked

#1
feetishes

feetishes

    Member

  • Member
  • PipPip
  • 49 posts
Greetings

My computer has been indicating to me that I have some type of virus infection. I currently use AVG and sometime when I reboot my system, the AVG virus prompt appears. It gives me an option to remove the virus (file), which I have tried to do. However, when I select the option to delete the file, the AVG program indicates the file and location can't be found. The name of the virus/trojan horse is Trojan Horse Generic21.BGJY

Any help would be appreciated.


OTL logfile created on: 9/8/2012 8:57:49 PM - Run 1
OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\John\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 68.03% Memory free
4.84 Gb Paging File | 3.83 Gb Available in Paging File | 79.12% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 462.71 Gb Total Space | 13.72 Gb Free Space | 2.96% Space Free | Partition Type: NTFS

Computer Name: RJ-44D11BCAC9F6 | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/29 21:58:46 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/08/26 20:19:41 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John\My Documents\Downloads\OTL.exe
PRC - [2012/08/17 08:35:40 | 000,079,384 | ---- | M] (Google) -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2012/07/20 15:17:14 | 012,218,904 | ---- | M] (Google) -- C:\Program Files\Google\Drive\googledrivesync.exe
PRC - [2012/07/13 12:46:11 | 000,186,832 | ---- | M] (Google Inc.) -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.115\GoogleCrashHandler.exe
PRC - [2012/07/04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exe
PRC - [2012/06/13 03:48:26 | 000,758,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2012/06/13 03:48:24 | 001,255,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2012/04/05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/03/19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2012/02/14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2010/05/17 17:03:14 | 000,105,632 | ---- | M] (Corel) -- C:\Program Files\Common Files\Corel\Standby\Standby.exe
PRC - [2010/05/17 17:02:52 | 000,053,408 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2009/01/08 08:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/07/24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007/07/02 13:29:22 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/06/06 16:44:44 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/05/22 14:18:56 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2007/05/10 01:01:00 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OEM02Mon.exe
PRC - [2007/03/06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2006/09/08 15:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2003/10/25 03:44:20 | 000,724,992 | ---- | M] (Intuit, Inc.) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe


========== Modules (No Company Name) ==========

MOD - [2012/09/08 20:32:10 | 000,571,392 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\pysqlite2._sqlite.pyd
MOD - [2012/09/08 20:32:10 | 000,263,168 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32com.shell.shell.pyd
MOD - [2012/09/08 20:32:10 | 000,096,256 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32api.pyd
MOD - [2012/09/08 20:32:10 | 000,086,016 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\_elementtree.pyd
MOD - [2012/09/08 20:32:10 | 000,070,656 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._html2.pyd
MOD - [2012/09/08 20:32:10 | 000,040,448 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\_socket.pyd
MOD - [2012/09/08 20:32:09 | 001,018,368 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\windows._cacheinvalidation.pyd
MOD - [2012/09/08 20:32:09 | 000,792,576 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._gdi_.pyd
MOD - [2012/09/08 20:32:09 | 000,731,136 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._misc_.pyd
MOD - [2012/09/08 20:32:09 | 000,354,304 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\pythoncom26.dll
MOD - [2012/09/08 20:32:09 | 000,153,088 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\pyexpat.pyd
MOD - [2012/09/08 20:32:09 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\_ctypes.pyd
MOD - [2012/09/08 20:32:09 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32crypt.pyd
MOD - [2012/09/08 20:32:08 | 000,645,120 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\_ssl.pyd
MOD - [2012/09/08 20:32:08 | 000,110,592 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\PyWinTypes26.dll
MOD - [2012/09/08 20:32:07 | 001,169,408 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._core_.pyd
MOD - [2012/09/08 20:32:07 | 000,311,808 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\_hashlib.pyd
MOD - [2012/09/08 20:32:07 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32process.pyd
MOD - [2012/09/08 20:32:07 | 000,022,528 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32pdh.pyd
MOD - [2012/09/08 20:32:06 | 000,807,424 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._windows_.pyd
MOD - [2012/09/08 20:32:06 | 000,121,856 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._wizard.pyd
MOD - [2012/09/08 20:32:06 | 000,111,104 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32file.pyd
MOD - [2012/09/08 20:32:05 | 001,056,256 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\wx._controls_.pyd
MOD - [2012/09/08 20:32:05 | 000,039,424 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32inet.pyd
MOD - [2012/09/08 20:32:03 | 000,585,728 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\unicodedata.pyd
MOD - [2012/09/08 20:32:03 | 000,017,920 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\win32event.pyd
MOD - [2012/09/08 20:32:02 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI4242\select.pyd
MOD - [2012/08/29 21:58:45 | 000,442,392 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppgooglenaclpluginchrome.dll
MOD - [2012/08/29 21:58:44 | 012,237,336 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
MOD - [2012/08/29 21:58:42 | 003,997,720 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
MOD - [2012/08/29 21:57:15 | 000,144,424 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\avutil-51.dll
MOD - [2012/08/29 21:57:13 | 000,266,792 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\avformat-54.dll
MOD - [2012/08/29 21:57:12 | 002,480,680 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\avcodec-54.dll
MOD - [2012/08/17 05:02:47 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\2516a49d10f4418f72e1c25f691815a8\System.ServiceProcess.ni.dll
MOD - [2012/08/17 04:59:25 | 000,762,368 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\0f9d7198d2c0a3953fb59b1aca0d35f7\System.Runtime.Remoting.ni.dll
MOD - [2012/08/17 04:59:22 | 000,786,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\26ee061618887d629a9f7072970ffb85\System.EnterpriseServices.ni.dll
MOD - [2012/08/17 04:59:21 | 000,646,656 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\ce2aa3a5e89c326055ac8e2a309232f7\System.Transactions.ni.dll
MOD - [2012/08/17 04:57:04 | 013,197,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\54d61af44b1dedee6aea0d1bbc46b13a\System.Windows.Forms.ni.dll
MOD - [2012/08/17 04:51:19 | 001,666,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4a668799513e369a54fdab8b3f74de92\System.Drawing.ni.dll
MOD - [2012/08/17 04:48:27 | 006,798,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\9f5111b0b58258c3a4bbcfb8bf27374c\System.Data.ni.dll
MOD - [2012/08/17 04:48:17 | 007,052,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\14ba6251d6ec84c9579ed3d3e10b30c1\System.Core.ni.dll
MOD - [2012/08/17 04:48:13 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5ee8bf77e7b3e25cdbff6e1c299574fe\System.Xml.ni.dll
MOD - [2012/08/17 04:48:08 | 000,980,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\0c8e950df17a0abec10888e8ad966cbe\System.Configuration.ni.dll
MOD - [2012/08/17 04:48:07 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\6f399163bb35597da7141ccdb7f39d16\System.ni.dll
MOD - [2012/08/17 04:47:57 | 014,412,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2011/11/03 10:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2011/11/03 10:28:36 | 000,386,048 | ---- | M] () -- C:\WINDOWS\system32\qdvd.dll
MOD - [2008/10/24 18:00:32 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2008/10/24 18:00:12 | 000,753,664 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2008/04/13 19:12:03 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\qcap.dll
MOD - [2008/04/13 19:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 19:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2003/09/02 18:58:10 | 000,024,621 | ---- | M] () -- C:\Program Files\WS_FTP Pro\nsftpch.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2012/08/15 06:50:34 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2010/05/17 17:02:52 | 000,053,408 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2007/07/24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007/03/06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbmodem.sys -- (USBModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbbus.sys -- (usbbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\FsUsbExDisk.SYS -- (FsUsbExDisk)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/04/19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2012/03/19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012/02/22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2012/01/31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/12/23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/12/23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2011/12/23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)
DRV - [2011/12/23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2011/03/29 20:55:52 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2011/03/18 11:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2010/12/21 00:55:02 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/12/21 00:55:02 | 000,121,576 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2010/12/21 00:55:02 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus)
DRV - [2010/12/21 00:55:02 | 000,096,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2010/12/21 00:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/12/21 00:55:02 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/12/21 00:55:02 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2010/09/02 17:49:06 | 000,013,312 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pneteth.sys -- (pneteth)
DRV - [2010/03/29 15:27:00 | 000,043,944 | ---- | M] (Fuzhou Rockchip Electronics Co,Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rk28usb.sys -- (RK28USB)
DRV - [2008/10/24 18:00:32 | 001,287,552 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007/07/18 01:02:00 | 000,235,520 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2007/06/25 18:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/06/08 01:00:00 | 000,141,376 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OEM02Afx.sys -- (OEM02Afx)
DRV - [2007/05/10 10:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007/03/21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/03/05 18:45:00 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2007/02/24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/21 04:25:44 | 000,045,568 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/11/02 07:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2006/08/04 16:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\XAudio.sys -- (XAudio)
DRV - [2004/12/23 04:47:10 | 000,027,392 | ---- | M] (Ulead Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ULCDRHlp.sys -- (ULCDRHlp)
DRV - [1996/04/03 14:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\John\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/07/17 09:34:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/02 09:11:16 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Logitech Device Detection (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\1.24.0.9_0\npLogitechDeviceDetection.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Documents and Settings\John\Application Data\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Veetle = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\anmkomjokjgdndleofheimembpkhfheg\1.4_0\
CHR - Extension: YouTube = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Search by Image (by Google) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm\1.3.0_0\
CHR - Extension: Logitech Device Detection = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\1.24.0.9_0\
CHR - Extension: We-Care Reminder = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ippkomaaonokjnfjoikaemidanojkfmm\1.0.0.25_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2191_0\
CHR - Extension: Google Voice (by Google) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.3.6.8_0\
CHR - Extension: Hide Facebook SideBar Ticker = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ldfdjdnohanpkljbgeipdoeiefheaefp\1.0_0\
CHR - Extension: AVG Do Not Track = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: Facebook Notifications = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: Gmail = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/02/02 21:23:37 | 000,001,078 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 9 more lines...
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Standby] c:\Program Files\Common Files\Corel\Standby\Standby.exe (Corel)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\John\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.3\IExifMap.htm ()
O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.3\IExifCom.htm ()
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell....lSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D83E334C-8013-4FF0-A774-A64F437820E4}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D9DA1EB3-7549-46B6-8AEB-34BE28894B72}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/19 17:42:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{938747a2-4c03-11e0-9670-001d09def96c}\Shell - "" = AutoRun
O33 - MountPoints2\{938747a2-4c03-11e0-9670-001d09def96c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{938747a2-4c03-11e0-9670-001d09def96c}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{af4f9f1e-bc16-11df-9621-001d09def96c}\Shell - "" = AutoRun
O33 - MountPoints2\{af4f9f1e-bc16-11df-9621-001d09def96c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{af4f9f1e-bc16-11df-9621-001d09def96c}\Shell\AutoRun\command - "" = F:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/08 20:30:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\John\Recent
[2012/09/03 17:16:16 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/08/21 20:19:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\New Folder
[2012/08/21 19:40:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\isabelle
[2012/08/20 07:44:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\kenwood_reunion2012
[2012/08/15 19:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\feetishes qb
[2012/08/15 19:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\Desktop Stuff
[2012/08/15 19:35:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks
[2012/08/15 19:35:13 | 000,636,032 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Graphs32.ocx
[2012/08/15 19:35:13 | 000,634,880 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Gsprop32.dll
[2012/08/15 19:35:13 | 000,423,016 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Gsw32.exe
[2012/08/15 19:35:13 | 000,262,656 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\TX4OLE.OCX
[2012/08/15 19:35:13 | 000,242,816 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Gswag32.dll
[2012/08/15 19:35:13 | 000,152,688 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\gswdll32.dll
[2012/08/15 19:35:13 | 000,090,112 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\Ic32.dll
[2012/08/15 19:35:13 | 000,072,704 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\Txtls32.dll
[2012/08/15 19:35:13 | 000,068,096 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\tx_rtf32.dll
[2012/08/15 19:35:13 | 000,047,104 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\WNDTLS32.dll
[2012/08/15 19:35:13 | 000,033,792 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\tx_tif32.flt
[2012/08/15 19:35:13 | 000,024,064 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\Tx_gif32.flt
[2012/08/15 19:35:13 | 000,022,016 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\tx_bmp32.flt
[2012/08/15 19:35:13 | 000,018,432 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\Tx_wmf32.flt
[2012/08/15 19:35:11 | 002,471,424 | ---- | C] (Steema Software SL) -- C:\WINDOWS\System32\TeeChart5.ocx
[2012/08/15 19:34:52 | 001,699,913 | ---- | C] (Intuit Inc.) -- C:\WINDOWS\System32\InetClnt.dll
[2012/08/15 19:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AnswerWorks 4.0
[2012/08/15 19:34:07 | 000,339,968 | ---- | C] (AMYUNI Consultants
http://www.amyuni.com) -- C:\WINDOWS\System32\cdintf.dll
[2012/08/15 19:34:05 | 000,000,000 | ---D | C] -- C:\Program Files\Intuit
[2012/08/15 19:34:04 | 000,999,424 | ---- | C] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\SPR32X30.ocx
[2012/08/15 19:34:04 | 000,200,704 | ---- | C] (Sheridan Software Systems, Inc.) -- C:\WINDOWS\System32\THREED32.OCX
[2012/08/15 19:34:03 | 000,737,280 | ---- | C] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\spr32d30.dll
[2012/08/15 19:28:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\Intuit
[2012/08/15 18:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\My Documents\TurboTax
[2012/08/15 18:10:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Local Settings\Application Data\Intuit
[2012/08/15 18:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2012/08/15 18:09:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Application Data\Intuit
[2012/08/15 18:08:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax Business 2011
[2012/08/15 18:07:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Local Settings\Application Data\IsolatedStorage
[2012/08/15 18:07:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intuit
[2012/08/15 18:07:30 | 000,000,000 | ---D | C] -- C:\Program Files\TurboTax
[2012/08/15 18:04:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/08/15 18:02:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2012/08/15 17:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2012/08/15 17:48:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Application Data\uTorrent
[2012/08/13 17:15:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\john_personal
[2012/08/10 15:17:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\New Folder (4)
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/08 20:51:01 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003UA.job
[2012/09/08 20:50:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/08 20:42:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/08 20:36:56 | 000,473,482 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/09/08 20:36:56 | 000,076,410 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/09/08 20:33:42 | 000,052,597 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2012/09/08 20:33:39 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/09/08 20:31:45 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/08 20:31:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/09/08 19:43:01 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003UA.job
[2012/09/08 17:27:14 | 094,027,834 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/09/08 17:26:34 | 000,271,972 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/09/08 16:43:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003Core.job
[2012/09/08 12:51:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003Core.job
[2012/09/08 02:00:00 | 000,000,340 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-RJ-44D11BCAC9F6-John.job
[2012/09/04 12:53:21 | 000,002,255 | ---- | M] () -- C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/02 10:48:59 | 000,000,030 | ---- | M] () -- C:\WINDOWS\Iedit.INI
[2012/09/02 10:48:51 | 000,006,517 | ---- | M] () -- C:\Documents and Settings\John\Desktop\426731_10151093963204299_2143498001_a.jpg
[2012/09/01 21:07:18 | 000,067,502 | ---- | M] () -- C:\Documents and Settings\John\Desktop\DSC_0376_2.jpg
[2012/08/31 22:32:19 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/08/24 07:06:03 | 000,020,263 | ---- | M] () -- C:\Documents and Settings\John\Desktop\Untitled - 3.jpg
[2012/08/24 07:02:11 | 000,008,205 | ---- | M] () -- C:\Documents and Settings\John\Desktop\Untitled - 2.jpg
[2012/08/23 21:06:53 | 001,795,664 | ---- | M] () -- C:\Documents and Settings\John\Desktop\DSC_0376.jpg
[2012/08/23 21:00:03 | 003,572,394 | ---- | M] () -- C:\Documents and Settings\John\Desktop\buddy_film.jpg
[2012/08/23 04:01:59 | 000,172,029 | ---- | M] () -- C:\Documents and Settings\John\Desktop\427298_10151038511363507_674581594_n.jpg
[2012/08/23 04:01:50 | 000,161,561 | ---- | M] () -- C:\Documents and Settings\John\Desktop\418590_10151038511238507_1047055010_n.jpg
[2012/08/23 04:01:42 | 000,143,632 | ---- | M] () -- C:\Documents and Settings\John\Desktop\422179_10151038511178507_1216715432_n.jpg
[2012/08/22 21:11:59 | 000,055,926 | ---- | M] () -- C:\Documents and Settings\John\Desktop\378590_462012213820644_754857536_n.jpg
[2012/08/22 21:11:47 | 000,038,975 | ---- | M] () -- C:\Documents and Settings\John\Desktop\523369_462011930487339_1999836809_n.jpg
[2012/08/22 21:11:41 | 000,034,747 | ---- | M] () -- C:\Documents and Settings\John\Desktop\418605_462011873820678_333907223_n.jpg
[2012/08/22 21:11:30 | 000,183,241 | ---- | M] () -- C:\Documents and Settings\John\Desktop\201884_462011843820681_1679871337_o.jpg
[2012/08/21 00:02:49 | 006,585,155 | ---- | M] () -- C:\Documents and Settings\John\Desktop\ace02.jpg
[2012/08/21 00:02:26 | 006,126,018 | ---- | M] () -- C:\Documents and Settings\John\Desktop\ace01.jpg
[2012/08/20 13:13:28 | 000,000,132 | ---- | M] () -- C:\WINDOWS\picture-shark.INI
[2012/08/15 19:37:07 | 003,467,416 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/15 19:35:40 | 000,001,861 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/08/15 19:35:40 | 000,001,634 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickBooks Premier Edition 2004.lnk
[2012/08/15 18:10:12 | 000,000,590 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/08/15 18:08:42 | 000,001,884 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax Business 2011.lnk
[2012/08/15 17:50:00 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\礣orrent.lnk
[2012/08/15 17:50:00 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\礣orrent.lnk
[2012/08/15 05:39:35 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/10 14:37:52 | 000,027,520 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\dt.dat
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/09/02 10:48:55 | 000,006,517 | ---- | C] () -- C:\Documents and Settings\John\Desktop\426731_10151093963204299_2143498001_a.jpg
[2012/09/01 21:05:55 | 000,067,502 | ---- | C] () -- C:\Documents and Settings\John\Desktop\DSC_0376_2.jpg
[2012/08/31 22:32:18 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/08/24 07:06:03 | 000,020,263 | ---- | C] () -- C:\Documents and Settings\John\Desktop\Untitled - 3.jpg
[2012/08/24 07:02:10 | 000,008,205 | ---- | C] () -- C:\Documents and Settings\John\Desktop\Untitled - 2.jpg
[2012/08/23 21:06:52 | 001,795,664 | ---- | C] () -- C:\Documents and Settings\John\Desktop\DSC_0376.jpg
[2012/08/23 20:59:56 | 003,572,394 | ---- | C] () -- C:\Documents and Settings\John\Desktop\buddy_film.jpg
[2012/08/23 04:02:00 | 000,172,029 | ---- | C] () -- C:\Documents and Settings\John\Desktop\427298_10151038511363507_674581594_n.jpg
[2012/08/23 04:01:51 | 000,161,561 | ---- | C] () -- C:\Documents and Settings\John\Desktop\418590_10151038511238507_1047055010_n.jpg
[2012/08/23 04:01:45 | 000,143,632 | ---- | C] () -- C:\Documents and Settings\John\Desktop\422179_10151038511178507_1216715432_n.jpg
[2012/08/22 21:12:00 | 000,055,926 | ---- | C] () -- C:\Documents and Settings\John\Desktop\378590_462012213820644_754857536_n.jpg
[2012/08/22 21:11:48 | 000,038,975 | ---- | C] () -- C:\Documents and Settings\John\Desktop\523369_462011930487339_1999836809_n.jpg
[2012/08/22 21:11:43 | 000,034,747 | ---- | C] () -- C:\Documents and Settings\John\Desktop\418605_462011873820678_333907223_n.jpg
[2012/08/22 21:11:35 | 000,183,241 | ---- | C] () -- C:\Documents and Settings\John\Desktop\201884_462011843820681_1679871337_o.jpg
[2012/08/21 00:02:47 | 006,585,155 | ---- | C] () -- C:\Documents and Settings\John\Desktop\ace02.jpg
[2012/08/21 00:02:23 | 006,126,018 | ---- | C] () -- C:\Documents and Settings\John\Desktop\ace01.jpg
[2012/08/15 19:35:40 | 000,001,861 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/08/15 19:35:40 | 000,001,634 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickBooks Premier Edition 2004.lnk
[2012/08/15 19:35:13 | 000,375,296 | ---- | C] () -- C:\WINDOWS\System32\tx32.dll
[2012/08/15 19:35:13 | 000,000,202 | ---- | C] () -- C:\WINDOWS\System32\Ic32.ini
[2012/08/15 19:29:00 | 000,227,134 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-602162358-920026266-1801674531-1003-0.dat
[2012/08/15 19:28:59 | 000,227,134 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/08/15 18:08:48 | 000,000,590 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/08/15 18:08:42 | 000,001,884 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TurboTax Business 2011.lnk
[2012/08/15 17:50:00 | 000,000,648 | ---- | C] () -- C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\礣orrent.lnk
[2012/08/15 17:50:00 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\礣orrent.lnk
[2012/08/15 05:39:35 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/10 14:37:52 | 000,027,520 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\dt.dat
[2012/02/15 21:30:05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/11/17 09:09:59 | 000,000,132 | ---- | C] () -- C:\WINDOWS\picture-shark.INI
[2011/06/15 17:34:03 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Images
[2011/06/15 17:34:03 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Icons
[2011/06/15 17:34:03 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Jingles
[2011/06/15 17:32:04 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdy.DAT
[2011/06/05 20:47:11 | 000,024,084 | ---- | C] () -- C:\Documents and Settings\John\bitpim.csv
[2011/03/31 17:38:15 | 000,019,517 | ---- | C] () -- C:\WINDOWS\hpqins13.dat
[2011/03/31 17:13:28 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\John\񀿉
[2011/02/21 09:51:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2011/02/21 09:20:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Internet Plug-Ins
[2011/02/21 09:20:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Importer
[2011/02/21 09:20:43 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2011/02/21 09:20:43 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Limiter
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Instrument Library
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Installer Plugin
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Images
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Image Units
[2011/02/21 09:20:42 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2011/02/21 09:20:42 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2011/02/21 09:20:42 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Licenses
[2011/02/21 09:20:42 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Legacy
[2011/01/23 09:08:04 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\John\Application Data\$_hpcst$.hpc
[2011/01/04 17:10:56 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2011/01/04 17:10:56 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/04 17:10:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/04 17:10:56 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/30 12:11:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbx.DAT
[2010/10/11 08:00:38 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010/09/28 18:16:24 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/09/28 18:16:23 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/09/28 18:16:22 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/09/28 18:16:22 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/09/28 18:16:22 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/09/10 20:42:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\John\Application Data\downloads.m3u
[2010/09/10 20:06:24 | 000,000,196 | ---- | C] () -- C:\Documents and Settings\John\Application Data\default.rss
[2010/08/28 10:11:25 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\281857412B.sys
[2010/08/28 10:11:23 | 000,005,642 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/08/24 12:25:22 | 000,098,816 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/24 09:09:31 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\PUTTY.RND

========== LOP Check ==========

[2010/10/18 19:48:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\360SD
[2012/01/13 09:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/04/30 20:14:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 08:16:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/06/15 17:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/07/13 17:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iCoolsoft Studio
[2010/08/28 10:07:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/10/18 19:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Jlcm
[2012/09/08 17:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/25 01:24:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2010/10/18 19:59:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PPLive
[2012/02/02 21:40:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/05/02 17:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2010/08/28 11:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/09/01 07:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/06/15 17:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2012/01/20 19:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2010/12/21 08:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Amazon
[2012/01/13 09:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\AVG2012
[2012/05/11 09:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Dropbox
[2011/07/11 08:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Easeware
[2011/05/11 20:08:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\HDRsoft
[2011/12/19 23:54:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\LegalsoundsDownloadManager
[2011/07/15 13:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\MPEG Streamclip
[2012/01/21 08:31:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\MyPublisher
[2011/06/15 17:34:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Nikon
[2011/06/09 14:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Octoshape
[2012/01/20 19:03:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\OpenCandy
[2011/01/23 09:51:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Samsung
[2010/10/18 19:50:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\SE_logs
[2010/10/19 19:45:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\StreamTorrent
[2011/07/13 18:18:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Ulead Systems
[2012/09/05 08:46:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\uTorrent
[2010/08/24 17:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\VirtualStore
[2012/09/08 16:43:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003Core.job
[2012/09/08 19:43:01 | 000,000,994 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003UA.job

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi what is the name of the file that AVG reports ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image

    :OTL
    O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
  • 0

#3
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Greetings

I was not able to get the name of the file AVG was reporting as a possible virus file.


OTL logfile created on: 9/9/2012 8:41:51 AM - Run 2
OTL by OldTimer - Version 3.2.59.1 Folder = C:\Documents and Settings\John\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 73.62% Memory free
4.84 Gb Paging File | 3.96 Gb Available in Paging File | 81.77% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 462.71 Gb Total Space | 14.05 Gb Free Space | 3.04% Space Free | Partition Type: NTFS

Computer Name: RJ-44D11BCAC9F6 | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/29 21:58:46 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/08/26 20:19:41 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John\Desktop\OTL.exe
PRC - [2012/08/17 08:35:40 | 000,079,384 | ---- | M] (Google) -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2012/07/20 15:17:14 | 012,218,904 | ---- | M] (Google) -- C:\Program Files\Google\Drive\googledrivesync.exe
PRC - [2012/07/13 12:46:11 | 000,186,832 | ---- | M] (Google Inc.) -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.115\GoogleCrashHandler.exe
PRC - [2012/07/04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgidsagent.exe
PRC - [2012/06/13 03:48:26 | 000,758,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2012/06/13 03:48:24 | 001,255,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2012/04/05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/03/19 05:18:12 | 000,979,840 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2012/02/14 04:52:38 | 000,338,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2011/01/07 13:12:22 | 000,505,576 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/05/17 17:03:14 | 000,105,632 | ---- | M] (Corel) -- C:\Program Files\Common Files\Corel\Standby\Standby.exe
PRC - [2010/05/17 17:02:52 | 000,053,408 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2009/01/08 08:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/07/24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2007/07/02 13:29:22 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/06/06 16:44:44 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/05/22 14:18:56 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2007/05/10 01:01:00 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OEM02Mon.exe
PRC - [2007/03/06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2006/09/08 15:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2003/10/25 03:44:20 | 000,724,992 | ---- | M] (Intuit, Inc.) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe


========== Modules (No Company Name) ==========

MOD - [2012/09/09 08:22:45 | 000,792,576 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._gdi_.pyd
MOD - [2012/09/09 08:22:45 | 000,571,392 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\pysqlite2._sqlite.pyd
MOD - [2012/09/09 08:22:45 | 000,263,168 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32com.shell.shell.pyd
MOD - [2012/09/09 08:22:45 | 000,153,088 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\pyexpat.pyd
MOD - [2012/09/09 08:22:45 | 000,096,256 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32api.pyd
MOD - [2012/09/09 08:22:45 | 000,086,016 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\_elementtree.pyd
MOD - [2012/09/09 08:22:45 | 000,070,656 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._html2.pyd
MOD - [2012/09/09 08:22:45 | 000,040,448 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\_socket.pyd
MOD - [2012/09/09 08:22:45 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32crypt.pyd
MOD - [2012/09/09 08:22:44 | 001,018,368 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\windows._cacheinvalidation.pyd
MOD - [2012/09/09 08:22:44 | 000,731,136 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._misc_.pyd
MOD - [2012/09/09 08:22:44 | 000,354,304 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\pythoncom26.dll
MOD - [2012/09/09 08:22:44 | 000,110,592 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\PyWinTypes26.dll
MOD - [2012/09/09 08:22:44 | 000,073,728 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\_ctypes.pyd
MOD - [2012/09/09 08:22:43 | 000,645,120 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\_ssl.pyd
MOD - [2012/09/09 08:22:43 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32process.pyd
MOD - [2012/09/09 08:22:43 | 000,022,528 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32pdh.pyd
MOD - [2012/09/09 08:22:42 | 001,169,408 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._core_.pyd
MOD - [2012/09/09 08:22:42 | 000,807,424 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._windows_.pyd
MOD - [2012/09/09 08:22:42 | 000,311,808 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\_hashlib.pyd
MOD - [2012/09/09 08:22:41 | 000,121,856 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._wizard.pyd
MOD - [2012/09/09 08:22:41 | 000,111,104 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32file.pyd
MOD - [2012/09/09 08:22:40 | 001,056,256 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\wx._controls_.pyd
MOD - [2012/09/09 08:22:40 | 000,039,424 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32inet.pyd
MOD - [2012/09/09 08:22:39 | 000,585,728 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\unicodedata.pyd
MOD - [2012/09/09 08:22:39 | 000,017,920 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\win32event.pyd
MOD - [2012/09/09 08:22:38 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Temp\_MEI1442\select.pyd
MOD - [2012/08/29 21:58:45 | 000,442,392 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppgooglenaclpluginchrome.dll
MOD - [2012/08/29 21:58:44 | 012,237,336 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
MOD - [2012/08/29 21:58:42 | 003,997,720 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
MOD - [2012/08/29 21:57:15 | 000,144,424 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\avutil-51.dll
MOD - [2012/08/29 21:57:13 | 000,266,792 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\avformat-54.dll
MOD - [2012/08/29 21:57:12 | 002,480,680 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\avcodec-54.dll
MOD - [2012/08/17 05:02:47 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\2516a49d10f4418f72e1c25f691815a8\System.ServiceProcess.ni.dll
MOD - [2012/08/17 04:59:25 | 000,762,368 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\0f9d7198d2c0a3953fb59b1aca0d35f7\System.Runtime.Remoting.ni.dll
MOD - [2012/08/17 04:59:22 | 000,786,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\26ee061618887d629a9f7072970ffb85\System.EnterpriseServices.ni.dll
MOD - [2012/08/17 04:59:21 | 000,646,656 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\ce2aa3a5e89c326055ac8e2a309232f7\System.Transactions.ni.dll
MOD - [2012/08/17 04:57:04 | 013,197,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\54d61af44b1dedee6aea0d1bbc46b13a\System.Windows.Forms.ni.dll
MOD - [2012/08/17 04:51:19 | 001,666,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\4a668799513e369a54fdab8b3f74de92\System.Drawing.ni.dll
MOD - [2012/08/17 04:48:27 | 006,798,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\9f5111b0b58258c3a4bbcfb8bf27374c\System.Data.ni.dll
MOD - [2012/08/17 04:48:17 | 007,052,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\14ba6251d6ec84c9579ed3d3e10b30c1\System.Core.ni.dll
MOD - [2012/08/17 04:48:13 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\5ee8bf77e7b3e25cdbff6e1c299574fe\System.Xml.ni.dll
MOD - [2012/08/17 04:48:08 | 000,980,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\0c8e950df17a0abec10888e8ad966cbe\System.Configuration.ni.dll
MOD - [2012/08/17 04:48:07 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\6f399163bb35597da7141ccdb7f39d16\System.ni.dll
MOD - [2012/08/17 04:47:57 | 014,412,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2011/11/03 10:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2011/11/03 10:28:36 | 000,386,048 | ---- | M] () -- C:\WINDOWS\system32\qdvd.dll
MOD - [2010/06/29 11:31:12 | 000,652,800 | ---- | M] () -- C:\Program Files\IZArc\IZArcCM.dll
MOD - [2008/10/24 18:00:32 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2008/10/24 18:00:12 | 000,753,664 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2008/04/13 19:12:03 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\qcap.dll
MOD - [2008/04/13 19:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 19:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2003/09/02 18:44:52 | 000,069,678 | ---- | M] () -- C:\Program Files\WS_FTP Pro\wsfirscr.dll
MOD - [2003/09/02 18:44:42 | 000,135,214 | ---- | M] () -- C:\Program Files\WS_FTP Pro\wsftplib.dll
MOD - [2003/09/02 18:43:50 | 000,049,197 | ---- | M] () -- C:\Program Files\WS_FTP Pro\wshosts.dll
MOD - [2003/03/20 10:01:32 | 000,839,680 | ---- | M] () -- C:\Program Files\WS_FTP Pro\libeay32.dll
MOD - [2003/03/20 10:01:32 | 000,159,744 | ---- | M] () -- C:\Program Files\WS_FTP Pro\ssleay32.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2012/08/15 06:50:34 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/04 17:25:54 | 005,160,568 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2010/05/17 17:02:52 | 000,053,408 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2007/07/24 11:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2007/03/06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbmodem.sys -- (USBModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbbus.sys -- (usbbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\FsUsbExDisk.SYS -- (FsUsbExDisk)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/04/19 04:50:26 | 000,024,896 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2012/03/19 05:17:28 | 000,301,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012/02/22 05:25:32 | 000,235,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2012/01/31 04:46:50 | 000,031,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/12/23 13:32:14 | 000,041,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/12/23 13:32:08 | 000,017,232 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2011/12/23 13:32:06 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsfilterx.sys -- (AVGIDSFilter)
DRV - [2011/12/23 13:32:00 | 000,139,856 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2011/03/29 20:55:52 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2011/03/18 11:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2010/12/21 00:55:02 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/12/21 00:55:02 | 000,121,576 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2010/12/21 00:55:02 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus)
DRV - [2010/12/21 00:55:02 | 000,096,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2010/12/21 00:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/12/21 00:55:02 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/12/21 00:55:02 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2010/09/02 17:49:06 | 000,013,312 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pneteth.sys -- (pneteth)
DRV - [2010/03/29 15:27:00 | 000,043,944 | ---- | M] (Fuzhou Rockchip Electronics Co,Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rk28usb.sys -- (RK28USB)
DRV - [2008/10/24 18:00:32 | 001,287,552 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007/07/18 01:02:00 | 000,235,520 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2007/06/25 18:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/06/08 01:00:00 | 000,141,376 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OEM02Afx.sys -- (OEM02Afx)
DRV - [2007/05/10 10:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007/03/21 22:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/03/05 18:45:00 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2007/02/24 14:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/23 16:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/21 04:25:44 | 000,045,568 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/11/02 07:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2006/08/04 16:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\XAudio.sys -- (XAudio)
DRV - [2004/12/23 04:47:10 | 000,027,392 | ---- | M] (Ulead Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ULCDRHlp.sys -- (ULCDRHlp)
DRV - [1996/04/03 14:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\John\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017300.dll (Amazon.com, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/07/17 09:34:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/02 09:11:16 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Logitech Device Detection (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\1.24.0.9_0\npLogitechDeviceDetection.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\plugins/avgnpss.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\John\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Documents and Settings\John\Application Data\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Veetle = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\anmkomjokjgdndleofheimembpkhfheg\1.4_0\
CHR - Extension: YouTube = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Search by Image (by Google) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm\1.3.0_0\
CHR - Extension: Logitech Device Detection = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\elncikmfipkphghakkmemnlnahadedno\1.24.0.9_0\
CHR - Extension: We-Care Reminder = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ippkomaaonokjnfjoikaemidanojkfmm\1.0.0.25_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2191_0\
CHR - Extension: Google Voice (by Google) = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.3.6.8_0\
CHR - Extension: Hide Facebook SideBar Ticker = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ldfdjdnohanpkljbgeipdoeiefheaefp\1.0_0\
CHR - Extension: AVG Do Not Track = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: Facebook Notifications = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: Gmail = C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/09 08:19:43 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Standby] c:\Program Files\Common Files\Corel\Standby\Standby.exe (Corel)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\John\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\John\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.3\IExifMap.htm ()
O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.3\IExifCom.htm ()
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell....lSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D83E334C-8013-4FF0-A774-A64F437820E4}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D9DA1EB3-7549-46B6-8AEB-34BE28894B72}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/19 17:42:13 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{938747a2-4c03-11e0-9670-001d09def96c}\Shell - "" = AutoRun
O33 - MountPoints2\{938747a2-4c03-11e0-9670-001d09def96c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{938747a2-4c03-11e0-9670-001d09def96c}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{af4f9f1e-bc16-11df-9621-001d09def96c}\Shell - "" = AutoRun
O33 - MountPoints2\{af4f9f1e-bc16-11df-9621-001d09def96c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{af4f9f1e-bc16-11df-9621-001d09def96c}\Shell\AutoRun\command - "" = F:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/09 08:19:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/08 20:30:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\John\Recent
[2012/09/03 17:16:16 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/08/26 20:19:40 | 000,598,528 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\John\Desktop\OTL.exe
[2012/08/21 20:19:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\New Folder
[2012/08/21 19:40:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\isabelle
[2012/08/20 07:44:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\kenwood_reunion2012
[2012/08/15 19:54:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\feetishes qb
[2012/08/15 19:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\Desktop Stuff
[2012/08/15 19:35:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickBooks
[2012/08/15 19:35:13 | 000,636,032 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Graphs32.ocx
[2012/08/15 19:35:13 | 000,634,880 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Gsprop32.dll
[2012/08/15 19:35:13 | 000,423,016 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Gsw32.exe
[2012/08/15 19:35:13 | 000,262,656 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\TX4OLE.OCX
[2012/08/15 19:35:13 | 000,242,816 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\Gswag32.dll
[2012/08/15 19:35:13 | 000,152,688 | ---- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\gswdll32.dll
[2012/08/15 19:35:13 | 000,090,112 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\Ic32.dll
[2012/08/15 19:35:13 | 000,072,704 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\Txtls32.dll
[2012/08/15 19:35:13 | 000,068,096 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\tx_rtf32.dll
[2012/08/15 19:35:13 | 000,047,104 | ---- | C] (DBS GmbH, Bremen-Germany) -- C:\WINDOWS\System32\WNDTLS32.dll
[2012/08/15 19:35:13 | 000,033,792 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\tx_tif32.flt
[2012/08/15 19:35:13 | 000,024,064 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\Tx_gif32.flt
[2012/08/15 19:35:13 | 000,022,016 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\tx_bmp32.flt
[2012/08/15 19:35:13 | 000,018,432 | ---- | C] (DBS GmbH) -- C:\WINDOWS\System32\Tx_wmf32.flt
[2012/08/15 19:35:11 | 002,471,424 | ---- | C] (Steema Software SL) -- C:\WINDOWS\System32\TeeChart5.ocx
[2012/08/15 19:34:52 | 001,699,913 | ---- | C] (Intuit Inc.) -- C:\WINDOWS\System32\InetClnt.dll
[2012/08/15 19:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AnswerWorks 4.0
[2012/08/15 19:34:07 | 000,339,968 | ---- | C] (AMYUNI Consultants
http://www.amyuni.com) -- C:\WINDOWS\System32\cdintf.dll
[2012/08/15 19:34:05 | 000,000,000 | ---D | C] -- C:\Program Files\Intuit
[2012/08/15 19:34:04 | 000,999,424 | ---- | C] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\SPR32X30.ocx
[2012/08/15 19:34:04 | 000,200,704 | ---- | C] (Sheridan Software Systems, Inc.) -- C:\WINDOWS\System32\THREED32.OCX
[2012/08/15 19:34:03 | 000,737,280 | ---- | C] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\spr32d30.dll
[2012/08/15 19:28:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\Intuit
[2012/08/15 18:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\My Documents\TurboTax
[2012/08/15 18:10:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Local Settings\Application Data\Intuit
[2012/08/15 18:09:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2012/08/15 18:09:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Application Data\Intuit
[2012/08/15 18:08:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax Business 2011
[2012/08/15 18:07:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Local Settings\Application Data\IsolatedStorage
[2012/08/15 18:07:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intuit
[2012/08/15 18:07:30 | 000,000,000 | ---D | C] -- C:\Program Files\TurboTax
[2012/08/15 18:04:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/08/15 18:02:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2012/08/15 17:49:58 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2012/08/15 17:48:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Application Data\uTorrent
[2012/08/13 17:15:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\john_personal
[2012/08/10 15:17:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John\Desktop\New Folder (4)

========== Files - Modified Within 30 Days ==========

[2012/09/09 08:51:01 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003UA.job
[2012/09/09 08:50:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/09/09 08:42:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/09 08:28:16 | 000,473,482 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/09/09 08:28:16 | 000,076,410 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/09/09 08:22:34 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/09/09 08:22:31 | 000,052,597 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2012/09/09 08:21:25 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/09 08:21:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/09/09 08:19:43 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012/09/09 08:16:02 | 094,077,353 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/09/09 04:43:01 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003UA.job
[2012/09/09 02:00:00 | 000,000,340 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-RJ-44D11BCAC9F6-John.job
[2012/09/08 17:26:34 | 000,271,972 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/09/08 16:43:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003Core.job
[2012/09/08 12:51:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003Core.job
[2012/09/04 12:53:21 | 000,002,255 | ---- | M] () -- C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/02 10:48:59 | 000,000,030 | ---- | M] () -- C:\WINDOWS\Iedit.INI
[2012/09/02 10:48:51 | 000,006,517 | ---- | M] () -- C:\Documents and Settings\John\Desktop\426731_10151093963204299_2143498001_a.jpg
[2012/09/01 21:07:18 | 000,067,502 | ---- | M] () -- C:\Documents and Settings\John\Desktop\DSC_0376_2.jpg
[2012/08/31 22:32:19 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/08/26 20:19:41 | 000,598,528 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John\Desktop\OTL.exe
[2012/08/24 07:06:03 | 000,020,263 | ---- | M] () -- C:\Documents and Settings\John\Desktop\Untitled - 3.jpg
[2012/08/24 07:02:11 | 000,008,205 | ---- | M] () -- C:\Documents and Settings\John\Desktop\Untitled - 2.jpg
[2012/08/23 21:06:53 | 001,795,664 | ---- | M] () -- C:\Documents and Settings\John\Desktop\DSC_0376.jpg
[2012/08/23 21:00:03 | 003,572,394 | ---- | M] () -- C:\Documents and Settings\John\Desktop\buddy_film.jpg
[2012/08/23 04:01:59 | 000,172,029 | ---- | M] () -- C:\Documents and Settings\John\Desktop\427298_10151038511363507_674581594_n.jpg
[2012/08/23 04:01:50 | 000,161,561 | ---- | M] () -- C:\Documents and Settings\John\Desktop\418590_10151038511238507_1047055010_n.jpg
[2012/08/23 04:01:42 | 000,143,632 | ---- | M] () -- C:\Documents and Settings\John\Desktop\422179_10151038511178507_1216715432_n.jpg
[2012/08/22 21:11:59 | 000,055,926 | ---- | M] () -- C:\Documents and Settings\John\Desktop\378590_462012213820644_754857536_n.jpg
[2012/08/22 21:11:47 | 000,038,975 | ---- | M] () -- C:\Documents and Settings\John\Desktop\523369_462011930487339_1999836809_n.jpg
[2012/08/22 21:11:41 | 000,034,747 | ---- | M] () -- C:\Documents and Settings\John\Desktop\418605_462011873820678_333907223_n.jpg
[2012/08/22 21:11:30 | 000,183,241 | ---- | M] () -- C:\Documents and Settings\John\Desktop\201884_462011843820681_1679871337_o.jpg
[2012/08/21 00:02:49 | 006,585,155 | ---- | M] () -- C:\Documents and Settings\John\Desktop\ace02.jpg
[2012/08/21 00:02:26 | 006,126,018 | ---- | M] () -- C:\Documents and Settings\John\Desktop\ace01.jpg
[2012/08/20 13:13:28 | 000,000,132 | ---- | M] () -- C:\WINDOWS\picture-shark.INI
[2012/08/15 19:37:07 | 003,467,416 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/15 19:35:40 | 000,001,861 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/08/15 19:35:40 | 000,001,634 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickBooks Premier Edition 2004.lnk
[2012/08/15 18:10:12 | 000,000,590 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/08/15 18:08:42 | 000,001,884 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax Business 2011.lnk
[2012/08/15 17:50:00 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\礣orrent.lnk
[2012/08/15 17:50:00 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\礣orrent.lnk
[2012/08/15 05:39:35 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/10 14:37:52 | 000,027,520 | ---- | M] () -- C:\Documents and Settings\John\Local Settings\Application Data\dt.dat

========== Files Created - No Company Name ==========

[2012/09/02 10:48:55 | 000,006,517 | ---- | C] () -- C:\Documents and Settings\John\Desktop\426731_10151093963204299_2143498001_a.jpg
[2012/09/01 21:05:55 | 000,067,502 | ---- | C] () -- C:\Documents and Settings\John\Desktop\DSC_0376_2.jpg
[2012/08/31 22:32:18 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Amazon Cloud Player.lnk
[2012/08/24 07:06:03 | 000,020,263 | ---- | C] () -- C:\Documents and Settings\John\Desktop\Untitled - 3.jpg
[2012/08/24 07:02:10 | 000,008,205 | ---- | C] () -- C:\Documents and Settings\John\Desktop\Untitled - 2.jpg
[2012/08/23 21:06:52 | 001,795,664 | ---- | C] () -- C:\Documents and Settings\John\Desktop\DSC_0376.jpg
[2012/08/23 20:59:56 | 003,572,394 | ---- | C] () -- C:\Documents and Settings\John\Desktop\buddy_film.jpg
[2012/08/23 04:02:00 | 000,172,029 | ---- | C] () -- C:\Documents and Settings\John\Desktop\427298_10151038511363507_674581594_n.jpg
[2012/08/23 04:01:51 | 000,161,561 | ---- | C] () -- C:\Documents and Settings\John\Desktop\418590_10151038511238507_1047055010_n.jpg
[2012/08/23 04:01:45 | 000,143,632 | ---- | C] () -- C:\Documents and Settings\John\Desktop\422179_10151038511178507_1216715432_n.jpg
[2012/08/22 21:12:00 | 000,055,926 | ---- | C] () -- C:\Documents and Settings\John\Desktop\378590_462012213820644_754857536_n.jpg
[2012/08/22 21:11:48 | 000,038,975 | ---- | C] () -- C:\Documents and Settings\John\Desktop\523369_462011930487339_1999836809_n.jpg
[2012/08/22 21:11:43 | 000,034,747 | ---- | C] () -- C:\Documents and Settings\John\Desktop\418605_462011873820678_333907223_n.jpg
[2012/08/22 21:11:35 | 000,183,241 | ---- | C] () -- C:\Documents and Settings\John\Desktop\201884_462011843820681_1679871337_o.jpg
[2012/08/21 00:02:47 | 006,585,155 | ---- | C] () -- C:\Documents and Settings\John\Desktop\ace02.jpg
[2012/08/21 00:02:23 | 006,126,018 | ---- | C] () -- C:\Documents and Settings\John\Desktop\ace01.jpg
[2012/08/15 19:35:40 | 000,001,861 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/08/15 19:35:40 | 000,001,634 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickBooks Premier Edition 2004.lnk
[2012/08/15 19:35:13 | 000,375,296 | ---- | C] () -- C:\WINDOWS\System32\tx32.dll
[2012/08/15 19:35:13 | 000,000,202 | ---- | C] () -- C:\WINDOWS\System32\Ic32.ini
[2012/08/15 19:29:00 | 000,227,134 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-602162358-920026266-1801674531-1003-0.dat
[2012/08/15 19:28:59 | 000,227,134 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/08/15 18:08:48 | 000,000,590 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/08/15 18:08:42 | 000,001,884 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TurboTax Business 2011.lnk
[2012/08/15 17:50:00 | 000,000,648 | ---- | C] () -- C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Quick Launch\礣orrent.lnk
[2012/08/15 17:50:00 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\礣orrent.lnk
[2012/08/15 05:39:35 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/10 14:37:52 | 000,027,520 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\dt.dat
[2012/02/15 21:30:05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/11/17 09:09:59 | 000,000,132 | ---- | C] () -- C:\WINDOWS\picture-shark.INI
[2011/06/15 17:34:03 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Images
[2011/06/15 17:34:03 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Icons
[2011/06/15 17:34:03 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Jingles
[2011/06/15 17:32:04 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdy.DAT
[2011/06/05 20:47:11 | 000,024,084 | ---- | C] () -- C:\Documents and Settings\John\bitpim.csv
[2011/03/31 17:38:15 | 000,019,517 | ---- | C] () -- C:\WINDOWS\hpqins13.dat
[2011/03/31 17:13:28 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\John\񀿉
[2011/02/21 09:51:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2011/02/21 09:20:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Internet Plug-Ins
[2011/02/21 09:20:43 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Importer
[2011/02/21 09:20:43 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2011/02/21 09:20:43 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Limiter
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Instrument Library
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Installer Plugin
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Images
[2011/02/21 09:20:42 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\John\Application Data\Image Units
[2011/02/21 09:20:42 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2011/02/21 09:20:42 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2011/02/21 09:20:42 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Licenses
[2011/02/21 09:20:42 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Legacy
[2011/01/23 09:08:04 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\John\Application Data\$_hpcst$.hpc
[2011/01/04 17:10:56 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2011/01/04 17:10:56 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2011/01/04 17:10:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2011/01/04 17:10:56 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2010/12/30 12:11:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLbx.DAT
[2010/10/11 08:00:38 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010/09/28 18:16:24 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/09/28 18:16:23 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010/09/28 18:16:22 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/09/28 18:16:22 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/09/28 18:16:22 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/09/10 20:42:07 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\John\Application Data\downloads.m3u
[2010/09/10 20:06:24 | 000,000,196 | ---- | C] () -- C:\Documents and Settings\John\Application Data\default.rss
[2010/08/28 10:11:25 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\281857412B.sys
[2010/08/28 10:11:23 | 000,005,642 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/08/24 12:25:22 | 000,098,816 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/24 09:09:31 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\John\Local Settings\Application Data\PUTTY.RND

========== LOP Check ==========

[2010/10/18 19:48:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\360SD
[2012/01/13 09:41:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/04/30 20:14:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 08:16:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/06/15 17:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/07/13 17:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iCoolsoft Studio
[2010/08/28 10:07:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/10/18 19:59:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Jlcm
[2012/09/09 08:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/25 01:24:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2010/10/18 19:59:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PPLive
[2012/02/02 21:40:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/05/02 17:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2010/08/28 11:58:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/09/01 07:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/06/15 17:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2012/01/20 19:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2010/12/21 08:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Amazon
[2012/01/13 09:28:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\AVG2012
[2012/05/11 09:30:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Dropbox
[2011/07/11 08:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Easeware
[2011/05/11 20:08:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\HDRsoft
[2011/12/19 23:54:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\LegalsoundsDownloadManager
[2011/07/15 13:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\MPEG Streamclip
[2012/01/21 08:31:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\MyPublisher
[2011/06/15 17:34:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Nikon
[2011/06/09 14:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Octoshape
[2012/01/20 19:03:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\OpenCandy
[2011/01/23 09:51:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Samsung
[2010/10/18 19:50:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\SE_logs
[2010/10/19 19:45:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\StreamTorrent
[2011/07/13 18:18:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\Ulead Systems
[2012/09/05 08:46:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\uTorrent
[2010/08/24 17:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John\Application Data\VirtualStore
[2012/09/08 16:43:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003Core.job
[2012/09/09 04:43:01 | 000,000,994 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-602162358-920026266-1801674531-1003UA.job

========== Purity Check ==========



< End of report >
  • 0

#4
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.09.09.03

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
John :: RJ-44D11BCAC9F6 [administrator]

9/9/2012 9:09:13 AM
mbam-log-2012-09-09 (09-09-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216563
Time elapsed: 5 minute(s), 42 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I am not seeing anythig visible, what problems are you experiencing ?
  • 0

#6
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
I'm not experiencing any problems, but it's the AVG prompt which just keeps popping up. It does it whenever I reboot my computer, or whenever I'm online. It just pops up every 2 hours or so.

When it does pop up again, would you like me to attach a screenshot of it?!

Regards
  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yes please as I would like to know what it is alerting on

  • Download RogueKiller and save it on your desktop.
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan
Posted Image
  • Wait for the end of the scan.
  • The report has been created on the desktop.
  • Click on the Delete button.
Posted Image
  • The report has been created on the desktop.

  • Next click on the ShortcutsFix
    Posted Image
  • The report has been created on the desktop.

Please post: All RKreport.txt text files located on your desktop.
  • 0

#8
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
RogueKiller V8.0.2 [08/31/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : John [Admin rights]
Mode : Scan -- Date : 09/09/2012 10:41:05

い Bad processes : 0 い

い Registry Entries : 3 い
[Services][ROGUE ST] HKLM\[...]\ControlSet001\Services\61883 (system32\DRIVERS\61883.sys) -> FOUND
[Services][ROGUE ST] HKLM\[...]\ControlSet003\Services\61883 (system32\DRIVERS\61883.sys) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

い Particular Files / Folders: い

い Driver : [LOADED] い

い Infection : い

い HOSTS File: い
--> C:\WINDOWS\system32\drivers\etc\hosts

1

い MBR Check: い

+++++ PhysicalDrive0: ST9500420AS +++++
--- User ---
[MBR] 99ba313593db55bfce1f65f9f8adebe7
[BSP] 924c3ccc7cf16975da73c299d9d5d6d2 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 47 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 473815 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 970470585 | Size: 3074 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt
  • 0

#9
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
RogueKiller V8.0.2 [08/31/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : John [Admin rights]
Mode : Remove -- Date : 09/09/2012 10:42:36

い Bad processes : 0 い

い Registry Entries : 3 い
[Services][ROGUE ST] HKLM\[...]\ControlSet001\Services\61883 (system32\DRIVERS\61883.sys) -> DELETED
[Services][ROGUE ST] HKLM\[...]\ControlSet003\Services\61883 (system32\DRIVERS\61883.sys) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

い Particular Files / Folders: い

い Driver : [LOADED] い

い Infection : い

い HOSTS File: い
--> C:\WINDOWS\system32\drivers\etc\hosts

1

い MBR Check: い

+++++ PhysicalDrive0: ST9500420AS +++++
--- User ---
[MBR] 99ba313593db55bfce1f65f9f8adebe7
[BSP] 924c3ccc7cf16975da73c299d9d5d6d2 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 47 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 473815 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 970470585 | Size: 3074 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
  • 0

#10
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
RogueKiller V8.0.2 [08/31/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : John [Admin rights]
Mode : Shortcuts HJfix -- Date : 09/09/2012 10:52:00

い Bad processes : 0 い

い Driver : [LOADED] い

い File attributes restored: い
Desktop: Success 16 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 7 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 83 / Fail 0
My documents: Success 142 / Fail 142
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 116 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped

い Infection : い

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
  • 0

Advertisements


#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Rogue killer found a service to delete

I will wait for a screenshot from AVG before I proceed
  • 0

#12
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Greetings

Here is a screen capture which occurred just moments ago when the AVG alert popped up.

Attached Thumbnails

  • screencap.jpg

  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
That is a temporary file .. Lets empty them

Clear Cache/Temp Files
Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

  • 0

#14
feetishes

feetishes

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Greetings

I did everything as instructed and AVG issued another prompt upon reboot. It appears to be in a different location, but I am attaching the screen capture for it.

Attached Thumbnails

  • screencap2.jpg

  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets take a look at the drivers and services

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP