help! cant get rid of google rediredt virus! [Solved]
Started by
kingbear
, Sep 18 2012 05:15 AM
#1
Posted 18 September 2012 - 05:15 AM
#2
Posted 18 September 2012 - 09:10 AM
Hi I have moved you to the malware forum
Download OTL to your Desktop
THEN
Download aswMBR.exe ( 4.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan
On completion of the scan click save log, save it to your desktop and post in your next reply
Download OTL to your Desktop
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Select All Users
- Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
qmgr.dll
/md5stop
%systemdrive%\$Recycle.Bin|@;true;true;true
CREATERESTOREPOINT - Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Post both logs
THEN
Download aswMBR.exe ( 4.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan
On completion of the scan click save log, save it to your desktop and post in your next reply
#3
Posted 18 September 2012 - 11:48 AM
OTL logfile created on: 9/18/2012 12:38:02 PM - Run 1
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Owner\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.25% Memory free
3.98 Gb Paging File | 2.76 Gb Available in Paging File | 69.31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.87 Gb Total Space | 162.92 Gb Free Space | 74.78% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/09/11 07:04:14 | 001,595,056 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxetray.exe
PRC - [2012/08/14 15:53:19 | 000,686,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccsvchst.exe
PRC - [2012/06/11 16:22:16 | 000,267,856 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BingApp.exe
PRC - [2012/06/11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012/05/12 02:02:46 | 001,403,640 | ---- | M] (CleanMyPC Software) -- C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
PRC - [2012/04/11 02:35:48 | 000,742,816 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\PCDoctor\KSafeTray.exe
PRC - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\PCDoctor\KSafeSvc.exe
PRC - [2011/10/11 13:49:14 | 001,179,648 | ---- | M] (W3i, LLC) -- C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
PRC - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/12/07 13:20:02 | 000,101,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\Asus\HotkeyService\HotKeyMon.exe
PRC - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () -- C:\Windows\System32\AsusService.exe
PRC - [2010/12/07 13:19:52 | 001,248,176 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\Asus\HotkeyService\HotkeyService.exe
PRC - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/22 15:12:34 | 001,086,888 | ---- | M] (AsusTek Computer Inc.) -- C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
PRC - [2010/06/09 18:26:34 | 000,412,600 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
PRC - [2010/05/28 20:41:36 | 000,445,344 | ---- | M] (ASUS) -- C:\Program Files\EeePC\CapsHook\CapsHook.exe
PRC - [2009/11/19 09:44:14 | 000,083,240 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/21 05:01:48 | 000,140,664 | ---- | M] () -- C:\Program Files\Kingsoft\PCDoctor\zlib1.dll
MOD - [2011/10/21 05:01:40 | 000,075,160 | ---- | M] () -- C:\Program Files\Kingsoft\PCDoctor\json.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\uTorrent\uTorent.exe -- (uTorrentService)
SRV - [2012/08/14 16:53:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe -- (kxescore)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccSvcHst.exe -- (NAV)
SRV - [2012/06/11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program Files\Kingsoft\PCDoctor\KSafeSvc.exe -- (KSafeSvc)
SRV - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe -- (MCLIENT)
SRV - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () [On_Demand | Running] -- C:\Windows\System32\AsusService.exe -- (AsusService)
SRV - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe -- (NSL)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/03/15 14:48:26 | 000,535,807 | ---- | M] (Aladdin Knowledge Systems Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\hasplms.exe -- (hasplms)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Unknown] -- system32\drivers\Partizan.sys -- (Partizan)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\mcdbus.sys -- (mcdbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Owner\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwrchid.sys -- (btwrchid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwavdt.sys -- (btwavdt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1t8w3fv)
DRV - [2012/09/17 16:53:03 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120917.016\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/09/17 16:53:03 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120917.016\NAVENG.SYS -- (NAVENG)
DRV - [2012/09/14 08:41:34 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\IPSDefs\20120917.001\IDSvix86.sys -- (IDSVix86)
DRV - [2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) [Kernel | Disabled | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kusbquery.sys -- (KUsbGuard)
DRV - [2012/08/31 18:09:14 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\BASHDefs\20120905.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\kisknl.sys -- (kisknl)
DRV - [2012/08/17 09:09:53 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/09 07:37:55 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/10 19:09:06 | 000,125,784 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- c:\Program Files\Kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys -- (KDHacker)
DRV - [2012/07/10 19:09:06 | 000,027,240 | ---- | M] (Kingsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kavbootc.sys -- (kavbootc)
DRV - [2012/07/10 19:09:04 | 000,082,264 | ---- | M] (Kingsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ksapi.sys -- (ksapi)
DRV - [2012/07/05 22:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtspx.sys -- (SRTSPX)
DRV - [2012/06/30 20:05:29 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/06/07 00:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ccsetx86.sys -- (ccSet_NAV)
DRV - [2012/05/21 21:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symefa.sys -- (SymEFA)
DRV - [2012/04/30 10:43:27 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012/04/17 22:13:32 | 000,318,584 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symnets.sys -- (SymNetS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ironx86.sys -- (SymIRON)
DRV - [2012/03/23 10:19:42 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/12/19 21:58:08 | 000,111,008 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- C:\Program Files\Kingsoft\PCDoctor\kmodurl.sys -- (kmodurl)
DRV - [2011/10/01 09:30:42 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2011/10/01 09:30:40 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2011/10/01 09:30:38 | 000,194,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2011/10/01 09:30:36 | 000,579,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2011/08/08 11:38:12 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\MCLIENT\0101010.003\ccSetx86.sys -- (ccSet_MCLIENT)
DRV - [2011/07/25 22:18:36 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symds.sys -- (SymDS)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2010/08/24 05:55:51 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/07/01 21:14:00 | 001,015,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192se.sys -- (rtl8192se)
DRV - [2010/03/30 21:40:20 | 000,011,520 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2009/10/05 13:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/20 05:29:40 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/01 00:46:20 | 000,043,944 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2007/03/12 20:48:56 | 000,351,744 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aksfridge.sys -- (aksfridge)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKLM\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://home.myplayci...s={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...0001c4bd6e04197
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...&ver=4.0.0.1606
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...n=&geo=US&ver=1
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{EED02185-CF0A-4895-B284-53562CE2A44E}: "URL" = http://websearch.ask...1-26BFE1EB43D2
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{EED10D7A-B1C4-498D-8E37-F9327FD2358E}: "URL" = http://search.yahoo....01,17118,0,18,0
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\IPSFFPlgn\ [2012/09/17 16:48:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/05/15 19:11:54 | 000,000,000 | ---D | M]
[2012/06/18 01:07:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/06/17 18:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
[2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
O1 HOSTS File: ([2012/09/17 15:56:01 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\Windows\System32\BOOTTVID.DLL ()
O2 - BHO: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [KSafeTray] C:\Program files\Kingsoft\PCDoctor\KSafeTray.exe (Kingsoft Corporation)
O4 - HKLM..\Run: [kxesc] c:\program files\kingsoft\kingsoft antivirus\kxetray.exe (Kingsoft Corporation)
O4 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..Trusted Domains: moove.com ([]* in Trusted sites)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.syste...ent_4.5.1.0.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...yri_4.5.1.0.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00491AA3-92D1-4157-B062-7163FE4BA717}: DhcpNameServer = 168.94.0.15 168.94.0.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{110D093A-1A15-48F9-A930-65F7B997C492}: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\...com [@ = comfile] -- Reg Error: Value error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2030/01/01 15:03:33 | 000,000,000 | ---D | C] -- C:\Boot
[2012/09/18 12:26:41 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 12:03:50 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\gun guy_files
[2012/09/18 09:27:26 | 000,000,000 | ---D | C] -- C:\windows\$regcmp$
[2012/09/17 19:43:45 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/09/17 18:45:59 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/17 16:07:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\temp
[2012/09/17 14:44:33 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2012/09/16 08:35:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/09/15 15:50:02 | 000,000,000 | ---D | C] -- C:\ProgramData\KRSHistory
[2012/09/15 11:47:34 | 000,203,120 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTSD.sys
[2012/09/15 11:47:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012/09/14 21:23:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Apps
[2012/09/14 10:56:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2012/09/14 10:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\Games for Windows
[2012/09/13 07:00:31 | 000,000,000 | ---D | C] -- C:\windows\System32\1018
[2012/09/13 06:53:21 | 000,000,000 | ---D | C] -- C:\windows\System32\1017
[2012/09/11 07:04:18 | 000,018,296 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:18 | 000,014,200 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/06 08:04:40 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\sims
[2012/09/05 20:27:34 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2012/09/05 17:40:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Electronic Arts
[2012/09/05 15:41:21 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/05 15:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2012/09/05 15:39:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Origin
[2012/09/05 15:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2012/09/05 15:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2012/09/05 15:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2012/08/21 09:55:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\EA
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/18 12:39:01 | 000,000,884 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 12:03:53 | 000,074,838 | ---- | M] () -- C:\Users\Owner\Documents\gun guy.htm
[2012/09/18 11:53:05 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/09/18 10:12:17 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 10:12:17 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 10:03:42 | 000,000,880 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/18 10:03:27 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2012/09/18 10:03:11 | 1602,887,680 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/18 06:50:14 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt
[2012/09/18 06:50:14 | 000,001,688 | ---- | M] () -- C:\windows\System32\autoexec.nt
[2012/09/18 06:50:14 | 000,000,002 | RHS- | M] () -- C:\windows\winstart.bat
[2012/09/17 19:26:36 | 000,278,928 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/17 15:56:01 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\tasks\At1.job
[2012/09/15 11:52:55 | 001,487,627 | ---- | M] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | M] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/14 06:46:32 | 000,660,762 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/09/14 06:46:32 | 000,121,400 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/09/13 10:24:31 | 000,002,154 | ---- | M] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/11 07:04:09 | 000,018,296 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/05 15:36:23 | 000,000,901 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | M] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | M] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:23:08 | 000,000,748 | ---- | M] () -- C:\windows\eReg.dat
[2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kisknl.sys
[2012/08/21 09:29:41 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | M] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | M] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | M] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2030/01/01 15:03:34 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012/09/18 12:03:49 | 000,074,838 | ---- | C] () -- C:\Users\Owner\Documents\gun guy.htm
[2012/09/18 06:50:14 | 000,000,002 | RHS- | C] () -- C:\windows\winstart.bat
[2012/09/17 19:26:12 | 000,278,928 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/15 11:48:09 | 001,487,627 | ---- | C] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | C] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/13 10:24:31 | 000,002,154 | ---- | C] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/05 15:36:22 | 000,000,901 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | C] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | C] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:35:51 | 000,024,576 | ---- | C] () -- C:\windows\UniFISH.exe
[2012/08/21 09:29:41 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | C] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | C] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | C] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2012/08/16 22:41:22 | 000,000,017 | ---- | C] () -- C:\windows\System32\shortcut_ex.dat
[2012/08/10 22:10:44 | 000,091,072 | ---- | C] () -- C:\windows\System32\RoseCo2.dll
[2012/07/30 07:23:18 | 000,000,233 | ---- | C] () -- C:\windows\SIERRA.INI
[2012/04/23 12:51:28 | 000,004,096 | ---- | C] () -- C:\windows\d3dx.dat
[2012/01/30 16:52:55 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx11_442.dll
[2012/01/30 16:51:51 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx9_2225.dll
[2012/01/24 15:50:07 | 000,043,520 | ---- | C] () -- C:\windows\System32\CmdLineExt03.dll
[2012/01/17 21:43:29 | 000,000,748 | ---- | C] () -- C:\windows\eReg.dat
[2011/11/28 19:26:09 | 000,000,064 | ---- | C] () -- C:\windows\GPlrLanc.dat
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibilllitycpl.dll
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibillitycpl.dll
[2011/05/06 08:19:38 | 000,005,576 | ---- | C] () -- C:\windows\Language.ini
[2011/05/06 08:14:30 | 000,004,692 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2011/05/06 08:14:30 | 000,000,008 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
[2011/03/03 20:14:28 | 000,224,680 | ---- | C] () -- C:\windows\System32\AsusService.exe
[2011/03/03 20:14:28 | 000,025,616 | ---- | C] () -- C:\windows\AsAcpiSvrLang.ini
[2011/03/03 20:11:46 | 000,011,520 | ---- | C] () -- C:\windows\System32\drivers\AsUpIO.sys
[2011/03/03 20:11:25 | 000,000,831 | ---- | C] () -- C:\windows\Reboot.ini
[2011/03/03 20:07:01 | 000,451,072 | ---- | C] () -- C:\windows\System32\ISSRemoveSP.exe
[2011/03/03 20:06:35 | 000,014,051 | ---- | C] () -- C:\windows\System32\RaCoInst.dat
[2011/03/02 12:39:08 | 000,000,485 | ---- | C] () -- C:\windows\WinRAR.dll
========== ZeroAccess Check ==========
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
========== LOP Check ==========
[2012/06/08 10:09:17 | 000,000,000 | -HSD | M] -- C:\Users\Owner\AppData\Roaming\.#
[2012/05/17 11:40:41 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CleanMyPC Software
[2012/01/21 16:10:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Clickteam
[2012/07/16 21:23:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
[2011/05/06 08:18:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\E-Cam
[2012/08/21 09:55:52 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\EA
[2012/01/20 07:55:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\flashInstall
[2012/05/23 15:11:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\kingsoft
[2012/05/23 15:12:05 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\KSafe
[2012/01/24 15:37:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Leadertech
[2012/05/08 10:56:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Oberon Media
[2012/09/05 15:41:46 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/16 08:35:47 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/05/30 08:04:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Rovio
[2012/08/21 09:30:32 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SoftGrid Client
[2012/04/22 12:03:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Thinstall
[2012/01/21 10:27:30 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Trio
[2012/09/17 16:48:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2011/07/20 21:56:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\Tasks\At1.job
[2012/07/19 12:54:04 | 000,000,282 | ---- | M] () -- C:\windows\Tasks\KsafeDelay.job
[2012/06/03 08:59:40 | 000,032,618 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU(42).TXT
[2012/09/13 11:12:30 | 000,032,586 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
========== Base Services ==========
SRV - [2009/07/13 21:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2010/11/20 08:18:03 | 000,047,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2009/07/13 21:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2010/11/20 08:18:06 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011/11/17 01:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009/07/13 21:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2012/07/04 17:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2012/04/24 00:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2010/11/20 08:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2010/11/20 08:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2011/03/03 01:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2009/07/13 21:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009/07/13 21:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2009/07/13 21:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2010/11/20 08:19:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/07/13 21:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009/07/13 21:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2009/07/13 21:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2009/07/13 21:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2010/11/20 08:20:30 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2009/07/13 21:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2011/05/24 06:44:59 | 000,293,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2012/02/11 01:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011/11/17 01:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009/07/13 21:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2010/11/20 08:21:00 | 000,286,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2010/11/20 08:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2009/07/13 21:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011/11/17 01:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009/07/13 21:16:20 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010/11/20 08:21:26 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2010/11/20 08:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010/11/20 08:21:05 | 000,750,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2010/11/20 08:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/13 21:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2012/05/01 00:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2010/11/20 08:17:51 | 001,025,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2010/11/20 08:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2010/11/20 08:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2010/11/20 08:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010/11/20 08:21:35 | 001,086,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (eventlog)
SRV - [2010/11/20 08:19:40 | 000,566,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2010/11/20 08:21:35 | 000,463,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (StiSvc)
SRV - [2010/11/20 08:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\System32\msiexec.exe -- (msiserver)
SRV - [2009/07/13 21:16:19 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012/06/02 18:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2010/11/20 08:18:34 | 000,214,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009/07/13 21:16:19 | 000,829,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2010/11/20 08:21:36 | 000,084,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
< MD5 for: QMGR.DLL >
[2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) MD5=E585445D5021971FAE10393F0F1C3961 -- C:\Windows\erdnt\cache\qmgr.dll
[2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) MD5=E585445D5021971FAE10393F0F1C3961 -- C:\Windows\System32\qmgr.dll
[2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) MD5=E585445D5021971FAE10393F0F1C3961 -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7601.17514_none_25982ed857b42497\qmgr.dll
< MD5 for: SERVICES >
[2012/07/01 10:57:21 | 000,017,589 | ---- | M] () MD5=8949DD322EDF0FD9056657A8E270DC09 -- C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.CFG >
[2012/07/27 16:51:34 | 000,586,083 | ---- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\erdnt\cache\services.exe
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
< %systemdrive%\$Recycle.Bin|@;true;true;true >
========== Alternate Data Streams ==========
@Alternate Data Stream - 177 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:85AA7074
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:5D90B241
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7D288858
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:09867A8B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:92DB4653
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6387AA6C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:73C78BAA
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:02A78DF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:0F6AC518
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:72C99D4E
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A1460B2A
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 9/18/2012 12:38:02 PM - Run 1
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Owner\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.25% Memory free
3.98 Gb Paging File | 2.76 Gb Available in Paging File | 69.31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.87 Gb Total Space | 162.92 Gb Free Space | 74.78% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Value error. File not found
.cmd [@ = cmdfile] -- Reg Error: Value error. File not found
.com [@ = comfile] -- Reg Error: Value error. File not found
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
.pif [@ = piffile] -- Reg Error: Value error. File not found
.vbs [@ = VBSFile] -- Reg Error: Value error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{007521E6-61EB-4D09-B763-7831A2A9BA41}" = rport=445 | protocol=6 | dir=out | app=system |
"{0910E0BE-BD98-4D25-A044-9B97D5750BC9}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{15A3C0E5-0458-4ADF-A5CE-4BEF5221A323}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{24245C8C-817B-42CB-9EC4-E2E43E7248FA}" = lport=445 | protocol=6 | dir=in | app=system |
"{2BCB9E7F-00A6-4C6A-9381-9B62E52CF393}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{323751EE-19DC-4780-96A3-41147D8105C8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3C2DBA90-6640-48C5-994D-EAA0A7721468}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{3E0AD95A-8B32-452B-B1F1-3303DF4E67BD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4636BF4A-F612-48C7-BABD-DC7578F58678}" = lport=137 | protocol=17 | dir=in | app=system |
"{676A8D68-2D56-46E5-9287-6423115603D0}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{68CA31BD-FC2C-4EF3-9320-02DC7B3AB1F4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6F205684-AB09-413C-861A-372FA22582DB}" = rport=139 | protocol=6 | dir=out | app=system |
"{8463A4BF-7B15-453A-ABD9-1A96F8C8E91C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8BF9142C-5132-4DFA-AD1D-35B403C3C378}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8E0860C5-D6B2-4B9C-B9EB-8850CF34F7DF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9FE5318C-F528-4225-B083-C002973166C2}" = lport=138 | protocol=17 | dir=in | app=system |
"{B327744F-90A7-48DD-A40D-645D8F930751}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CB20ED17-AC4D-42AC-BBFD-7915DE39561D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DA178E83-916E-4CD7-B737-CBC4942B666E}" = rport=137 | protocol=17 | dir=out | app=system |
"{DD629F44-B71B-41FC-8536-1B16D368AA69}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E0FD4CD2-3046-4DD5-A45B-3AA680F4F61B}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{E2892C30-EF8D-43D2-AC5A-EE57C70DEE88}" = rport=138 | protocol=17 | dir=out | app=system |
"{ECDD1A07-4BDD-4977-9C9F-EC026F753198}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FEC1C1BF-9B03-4727-857A-52715DC4D970}" = lport=139 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{345BB574-1F36-4501-96E3-8E9F748DF270}" = protocol=1 | dir=out | [email protected],-28544 |
"{34CE7F7D-E771-429E-8E61-B34536AB7A0F}" = protocol=1 | dir=in | [email protected],-28543 |
"{48EFC471-AFAB-4FB8-BD6C-3187267C4141}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{4B9E5841-1456-4BD9-B1C8-210ACC591C1D}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{5E5EE982-80D4-422A-A561-54AD118A8A68}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{BCCBF055-36FF-4E4E-83A4-89A83D7FFD31}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{C39D9F14-5754-460A-9E65-FCF8D0F6761C}" = protocol=58 | dir=in | [email protected],-28545 |
"{DE9CD1EF-5A8D-47FA-9E06-A0FC2B76727B}" = protocol=58 | dir=out | [email protected],-28546 |
"{E8C6A4E2-9F45-4A86-9936-E5B120AE7B54}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{C941F8AF-27ED-4F39-8FBF-8D83C43FD6A2}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{88B7AB50-5924-4176-AB8D-CE8128E09B1B}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07A6B206-3F11-4D92-92A1-90E116ADD660}" = Angry Birds
"{08A25478-C5DD-4EA7-B168-3D687CA987FF}" = The Sims™ 3 Master Suite Stuff
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"{185AFA7A-F63E-450B-94AA-011CAC18090E}" = E-Cam
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java 6 Update 31
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38E5A3B1-ADF1-47E0-8024-76310A30EB36}" = LiveUpdate
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = The Sims™ 3 Late Night
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4B5092B6-F231-4D18-83BC-2618B729CA45}" = CapsHook
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6333FC29-BFE5-4024-AC78-958A1A7555D1}" = EeeSplendid
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{71C0E38E-09F2-4386-9977-404D4F6640CD}" = Hotkey Service
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7D5F8291-24FE-11E1-BCE5-F04DA23A5C58}" = MSVCRT Redists
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D40CF-8491-44AD-8FA8-7389CB418C64}" = 32 Bit HP CIO Components Installer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3D8C60-A55F-4fed-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F58C1D44-4AC9-48E8-9049-7A6CDFCB415C}" = LocaleMe
"{F9657EF6-C156-4CE9-A0A2-562CD3E94842}" = Beach Life
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Alchemy Deluxe [PopCap]" = Alchemy Deluxe [PopCap]
"Amazing Adventures 5 (Riddle of the Two Knights) [PopCap]" = Amazing Adventures 5 (Riddle of the Two Knights) [PopCap]
"B41C7C96D83162A676DA7365ADEFD6C1AF62A4EE" = Windows Driver Package - Broadcom Bluetooth (07/17/2009 6.2.0.9403)
"B5C82F3814F82FB37F1513B3185399BD88892B08" = Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0)
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"Casino Island To Go" = GameHouse Games Collection: Casino Island To Go
"chartertoolbar" = Charter Toolbar
"CleanMyPC - Registry Cleaner_is1" = CleanMyPC - Registry Cleaner
"DAEMON Tools Lite" = DAEMON Tools Lite
"Escape Rosecliff Island [PopCap]" = Escape Rosecliff Island [PopCap]
"Escape Whisper Valley [PopCap]" = Escape Whisper Valley [PopCap]
"Game Booster_is1" = Game Booster 3
"HDMI" = Intel® Graphics Media Accelerator Driver
"Hidden Identity (Chicago Blackout) [PopCap]" = Hidden Identity (Chicago Blackout) [PopCap]
"InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"Intel AppUp(SM) center 11779" = Intel AppUp(SM) center
"Kingsoft Internet Security" = Kingsoft Antivirus 2012
"Kingsoft PC Doctor" = Kingsoft PC Doctor 3.7.0.47
"Magic Inlay" = GameHouse Games Collection: Magic Inlay
"MCLIENT" = Norton Management
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mystery Case Files (Huntsville) [PopCap]" = Mystery Case Files (Huntsville) [PopCap]
"Mystery P.I. 6 (Stolen in San Francisco) [PopCap]" = Mystery P.I. 6 (Stolen in San Francisco) [PopCap]
"Mystery P.I. 7 (The Curious Case of Counterfeit Cove) [PopCap]" = Mystery P.I. 7 (The Curious Case of Counterfeit Cove) [PopCap]
"NAV" = Norton AntiVirus
"NST" = Norton Safe Web Lite
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Origin" = Origin
"Poker Superstars" = GameHouse Games Collection: Poker Superstars
"Puzzle Inlay" = GameHouse Games Collection: Puzzle Inlay
"RocketBowl Plus [PopCap]" = RocketBowl Plus [PopCap]
"Super TextTwist" = GameHouse Games Collection: Super TextTwist
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The Wizard's Pen [PopCap]" = The Wizard's Pen [PopCap]
"Typer Shark! Deluxe [PopCap]" = Typer Shark! Deluxe [PopCap]
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"Word Slinger" = GameHouse Games Collection: Word Slinger
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2/21/2012 9:48:03 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.2.0.148, time stamp:
0x4d84016e Faulting module name: TS3W.exe, version: 0.2.0.148, time stamp: 0x4d84016e
Exception
code: 0x80000003 Fault offset: 0x0017f196 Faulting process id: 0x1a58 Faulting application
start time: 0x01ccf09f524051c4 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: ac4008f7-5c92-11e1-9974-f46d040a3b01
Error - 2/21/2012 9:50:17 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.2.0.148, time stamp:
0x4d84016e Faulting module name: TS3W.exe, version: 0.2.0.148, time stamp: 0x4d84016e
Exception
code: 0x80000003 Fault offset: 0x0017f196 Faulting process id: 0x1ff8 Faulting application
start time: 0x01ccf09fb07878ce Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: fc3d3f91-5c92-11e1-9974-f46d040a3b01
Error - 2/21/2012 9:52:18 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.2.0.148, time stamp:
0x4d84016e Faulting module name: TS3W.exe, version: 0.2.0.148, time stamp: 0x4d84016e
Exception
code: 0x80000003 Fault offset: 0x0017f196 Faulting process id: 0xae0 Faulting application
start time: 0x01ccf09ff9ed0586 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 441e70d3-5c93-11e1-9974-f46d040a3b01
Error - 2/21/2012 9:55:52 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x17a0 Faulting application
start time: 0x01ccf0a079b0ceef Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: c3b13085-5c93-11e1-9974-f46d040a3b01
Error - 2/21/2012 10:00:27 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x1f50 Faulting application
start time: 0x01ccf0a11c0d9a47 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 680ba6c1-5c94-11e1-9974-f46d040a3b01
Error - 2/21/2012 10:03:17 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x1bd4 Faulting application
start time: 0x01ccf0a183f7ab72 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: cd6427e4-5c94-11e1-9974-f46d040a3b01
Error - 2/21/2012 10:48:58 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x1688 Faulting application
start time: 0x01ccf0a7d78fe878 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 2ece7b84-5c9b-11e1-afaf-f46d040a3b01
Error - 2/21/2012 11:01:14 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x10e8 Faulting application
start time: 0x01ccf0a99b671662 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: e5b3ff2c-5c9c-11e1-9a51-f46d040a3b01
Error - 2/21/2012 11:04:08 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x95c Faulting application
start time: 0x01ccf0aa01f901e5 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 4d9ef439-5c9d-11e1-9a51-f46d040a3b01
Error - 2/21/2012 11:12:45 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0xa3c Faulting application
start time: 0x01ccf0ab35d871c1 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 81bb3d03-5c9e-11e1-8efe-f46d040a3b01
[ System Events ]
Error - 9/18/2012 9:58:24 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 9/18/2012 9:59:08 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 9/18/2012 9:59:23 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 9/18/2012 10:02:06 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =
Error - 9/18/2012 10:03:46 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The uTorrent service failed to start due to the following error: %%2
Error - 9/18/2012 10:04:57 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the HASP
License Manager service to connect.
Error - 9/18/2012 10:05:01 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%1053
Error - 9/18/2012 10:09:44 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The catchme service failed to start due to the following error: %%2
Error - 9/18/2012 12:02:10 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10016
Description =
Error - 9/18/2012 12:02:10 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10016
Description =
< End of report >
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-09-18 13:40:56
-----------------------------
13:40:56.225 OS Version: Windows 6.1.7601 Service Pack 1
13:40:56.225 Number of processors: 2 586 0x1C0A
13:40:56.240 ComputerName: OWNER-PC UserName: Owner
13:41:00.203 Initialize success
13:41:12.761 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
13:41:12.776 Disk 0 Vendor: Hitachi_ ESBO Size: 238475MB BusType: 3
13:41:12.792 Disk 0 MBR read successfully
13:41:12.807 Disk 0 MBR scan
13:41:12.823 Disk 0 Windows 7 default MBR code
13:41:12.839 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 223097 MB offset 2048
13:41:12.870 Disk 0 Partition 2 00 1B Hidd FAT32 MSDOS5.0 15360 MB offset 456904704
13:41:12.901 Disk 0 Partition 3 00 EF EFI FAT 16 MB offset 488361984
13:41:12.917 Disk 0 scanning sectors +488394752
13:41:13.010 Disk 0 scanning C:\windows\system32\drivers
13:41:22.557 Service scanning
13:41:34.538 Service KDHacker c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys **LOCKED** 5
13:41:35.131 Service KUsbGuard C:\Program Files\Kingsoft\kingsoft antivirus\kusbquery.sys **LOCKED** 5
13:41:53.352 Modules scanning
13:42:19.919 Disk 0 trace - called modules:
13:42:20.043 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys sptd.sys
13:42:20.075 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86817030]
13:42:20.106 3 CLASSPNP.SYS[8898a59e] -> nt!IofCallDriver -> [0x8407f680]
13:42:20.137 5 ACPI.sys[823b23d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84982028]
13:42:20.168 Scan finished successfully
13:42:30.932 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
13:42:30.964 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Owner\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.25% Memory free
3.98 Gb Paging File | 2.76 Gb Available in Paging File | 69.31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.87 Gb Total Space | 162.92 Gb Free Space | 74.78% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/09/11 07:04:14 | 001,595,056 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxetray.exe
PRC - [2012/08/14 15:53:19 | 000,686,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccsvchst.exe
PRC - [2012/06/11 16:22:16 | 000,267,856 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BingApp.exe
PRC - [2012/06/11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012/05/12 02:02:46 | 001,403,640 | ---- | M] (CleanMyPC Software) -- C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
PRC - [2012/04/11 02:35:48 | 000,742,816 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\PCDoctor\KSafeTray.exe
PRC - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\PCDoctor\KSafeSvc.exe
PRC - [2011/10/11 13:49:14 | 001,179,648 | ---- | M] (W3i, LLC) -- C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
PRC - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/12/07 13:20:02 | 000,101,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\Asus\HotkeyService\HotKeyMon.exe
PRC - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () -- C:\Windows\System32\AsusService.exe
PRC - [2010/12/07 13:19:52 | 001,248,176 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\Asus\HotkeyService\HotkeyService.exe
PRC - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/22 15:12:34 | 001,086,888 | ---- | M] (AsusTek Computer Inc.) -- C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
PRC - [2010/06/09 18:26:34 | 000,412,600 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
PRC - [2010/05/28 20:41:36 | 000,445,344 | ---- | M] (ASUS) -- C:\Program Files\EeePC\CapsHook\CapsHook.exe
PRC - [2009/11/19 09:44:14 | 000,083,240 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/21 05:01:48 | 000,140,664 | ---- | M] () -- C:\Program Files\Kingsoft\PCDoctor\zlib1.dll
MOD - [2011/10/21 05:01:40 | 000,075,160 | ---- | M] () -- C:\Program Files\Kingsoft\PCDoctor\json.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\uTorrent\uTorent.exe -- (uTorrentService)
SRV - [2012/08/14 16:53:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe -- (kxescore)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccSvcHst.exe -- (NAV)
SRV - [2012/06/11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program Files\Kingsoft\PCDoctor\KSafeSvc.exe -- (KSafeSvc)
SRV - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe -- (MCLIENT)
SRV - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () [On_Demand | Running] -- C:\Windows\System32\AsusService.exe -- (AsusService)
SRV - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe -- (NSL)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/03/15 14:48:26 | 000,535,807 | ---- | M] (Aladdin Knowledge Systems Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\hasplms.exe -- (hasplms)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Unknown] -- system32\drivers\Partizan.sys -- (Partizan)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\mcdbus.sys -- (mcdbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Owner\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwrchid.sys -- (btwrchid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwavdt.sys -- (btwavdt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1t8w3fv)
DRV - [2012/09/17 16:53:03 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120917.016\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/09/17 16:53:03 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120917.016\NAVENG.SYS -- (NAVENG)
DRV - [2012/09/14 08:41:34 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\IPSDefs\20120917.001\IDSvix86.sys -- (IDSVix86)
DRV - [2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) [Kernel | Disabled | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kusbquery.sys -- (KUsbGuard)
DRV - [2012/08/31 18:09:14 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\BASHDefs\20120905.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\kisknl.sys -- (kisknl)
DRV - [2012/08/17 09:09:53 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/09 07:37:55 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/10 19:09:06 | 000,125,784 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- c:\Program Files\Kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys -- (KDHacker)
DRV - [2012/07/10 19:09:06 | 000,027,240 | ---- | M] (Kingsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kavbootc.sys -- (kavbootc)
DRV - [2012/07/10 19:09:04 | 000,082,264 | ---- | M] (Kingsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ksapi.sys -- (ksapi)
DRV - [2012/07/05 22:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtspx.sys -- (SRTSPX)
DRV - [2012/06/30 20:05:29 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/06/07 00:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ccsetx86.sys -- (ccSet_NAV)
DRV - [2012/05/21 21:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symefa.sys -- (SymEFA)
DRV - [2012/04/30 10:43:27 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012/04/17 22:13:32 | 000,318,584 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symnets.sys -- (SymNetS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ironx86.sys -- (SymIRON)
DRV - [2012/03/23 10:19:42 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/12/19 21:58:08 | 000,111,008 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- C:\Program Files\Kingsoft\PCDoctor\kmodurl.sys -- (kmodurl)
DRV - [2011/10/01 09:30:42 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2011/10/01 09:30:40 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2011/10/01 09:30:38 | 000,194,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2011/10/01 09:30:36 | 000,579,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2011/08/08 11:38:12 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\MCLIENT\0101010.003\ccSetx86.sys -- (ccSet_MCLIENT)
DRV - [2011/07/25 22:18:36 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symds.sys -- (SymDS)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2010/08/24 05:55:51 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/07/01 21:14:00 | 001,015,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192se.sys -- (rtl8192se)
DRV - [2010/03/30 21:40:20 | 000,011,520 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2009/10/05 13:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/20 05:29:40 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/01 00:46:20 | 000,043,944 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2007/03/12 20:48:56 | 000,351,744 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aksfridge.sys -- (aksfridge)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKLM\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://home.myplayci...s={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...0001c4bd6e04197
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...&ver=4.0.0.1606
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...n=&geo=US&ver=1
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{EED02185-CF0A-4895-B284-53562CE2A44E}: "URL" = http://websearch.ask...1-26BFE1EB43D2
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{EED10D7A-B1C4-498D-8E37-F9327FD2358E}: "URL" = http://search.yahoo....01,17118,0,18,0
IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\IPSFFPlgn\ [2012/09/17 16:48:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/05/15 19:11:54 | 000,000,000 | ---D | M]
[2012/06/18 01:07:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/06/17 18:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
[2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
O1 HOSTS File: ([2012/09/17 15:56:01 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\Windows\System32\BOOTTVID.DLL ()
O2 - BHO: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\Program Files\chartertoolbar\chartertoolbar.dll (Charter Communications)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [KSafeTray] C:\Program files\Kingsoft\PCDoctor\KSafeTray.exe (Kingsoft Corporation)
O4 - HKLM..\Run: [kxesc] c:\program files\kingsoft\kingsoft antivirus\kxetray.exe (Kingsoft Corporation)
O4 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..Trusted Domains: moove.com ([]* in Trusted sites)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.syste...ent_4.5.1.0.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...yri_4.5.1.0.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00491AA3-92D1-4157-B062-7163FE4BA717}: DhcpNameServer = 168.94.0.15 168.94.0.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{110D093A-1A15-48F9-A930-65F7B997C492}: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\...com [@ = comfile] -- Reg Error: Value error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2030/01/01 15:03:33 | 000,000,000 | ---D | C] -- C:\Boot
[2012/09/18 12:26:41 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 12:03:50 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\gun guy_files
[2012/09/18 09:27:26 | 000,000,000 | ---D | C] -- C:\windows\$regcmp$
[2012/09/17 19:43:45 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/09/17 18:45:59 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/17 16:07:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\temp
[2012/09/17 14:44:33 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2012/09/16 08:35:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/09/15 15:50:02 | 000,000,000 | ---D | C] -- C:\ProgramData\KRSHistory
[2012/09/15 11:47:34 | 000,203,120 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTSD.sys
[2012/09/15 11:47:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012/09/14 21:23:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Apps
[2012/09/14 10:56:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2012/09/14 10:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\Games for Windows
[2012/09/13 07:00:31 | 000,000,000 | ---D | C] -- C:\windows\System32\1018
[2012/09/13 06:53:21 | 000,000,000 | ---D | C] -- C:\windows\System32\1017
[2012/09/11 07:04:18 | 000,018,296 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:18 | 000,014,200 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/06 08:04:40 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\sims
[2012/09/05 20:27:34 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2012/09/05 17:40:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Electronic Arts
[2012/09/05 15:41:21 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/05 15:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2012/09/05 15:39:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Origin
[2012/09/05 15:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2012/09/05 15:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2012/09/05 15:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2012/08/21 09:55:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\EA
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/18 12:39:01 | 000,000,884 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 12:03:53 | 000,074,838 | ---- | M] () -- C:\Users\Owner\Documents\gun guy.htm
[2012/09/18 11:53:05 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/09/18 10:12:17 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 10:12:17 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 10:03:42 | 000,000,880 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/18 10:03:27 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2012/09/18 10:03:11 | 1602,887,680 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/18 06:50:14 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt
[2012/09/18 06:50:14 | 000,001,688 | ---- | M] () -- C:\windows\System32\autoexec.nt
[2012/09/18 06:50:14 | 000,000,002 | RHS- | M] () -- C:\windows\winstart.bat
[2012/09/17 19:26:36 | 000,278,928 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/17 15:56:01 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\tasks\At1.job
[2012/09/15 11:52:55 | 001,487,627 | ---- | M] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | M] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/14 06:46:32 | 000,660,762 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/09/14 06:46:32 | 000,121,400 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/09/13 10:24:31 | 000,002,154 | ---- | M] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/11 07:04:09 | 000,018,296 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/05 15:36:23 | 000,000,901 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | M] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | M] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:23:08 | 000,000,748 | ---- | M] () -- C:\windows\eReg.dat
[2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kisknl.sys
[2012/08/21 09:29:41 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | M] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | M] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | M] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2030/01/01 15:03:34 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012/09/18 12:03:49 | 000,074,838 | ---- | C] () -- C:\Users\Owner\Documents\gun guy.htm
[2012/09/18 06:50:14 | 000,000,002 | RHS- | C] () -- C:\windows\winstart.bat
[2012/09/17 19:26:12 | 000,278,928 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/15 11:48:09 | 001,487,627 | ---- | C] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | C] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/13 10:24:31 | 000,002,154 | ---- | C] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/05 15:36:22 | 000,000,901 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | C] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | C] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:35:51 | 000,024,576 | ---- | C] () -- C:\windows\UniFISH.exe
[2012/08/21 09:29:41 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | C] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | C] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | C] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2012/08/16 22:41:22 | 000,000,017 | ---- | C] () -- C:\windows\System32\shortcut_ex.dat
[2012/08/10 22:10:44 | 000,091,072 | ---- | C] () -- C:\windows\System32\RoseCo2.dll
[2012/07/30 07:23:18 | 000,000,233 | ---- | C] () -- C:\windows\SIERRA.INI
[2012/04/23 12:51:28 | 000,004,096 | ---- | C] () -- C:\windows\d3dx.dat
[2012/01/30 16:52:55 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx11_442.dll
[2012/01/30 16:51:51 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx9_2225.dll
[2012/01/24 15:50:07 | 000,043,520 | ---- | C] () -- C:\windows\System32\CmdLineExt03.dll
[2012/01/17 21:43:29 | 000,000,748 | ---- | C] () -- C:\windows\eReg.dat
[2011/11/28 19:26:09 | 000,000,064 | ---- | C] () -- C:\windows\GPlrLanc.dat
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibilllitycpl.dll
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibillitycpl.dll
[2011/05/06 08:19:38 | 000,005,576 | ---- | C] () -- C:\windows\Language.ini
[2011/05/06 08:14:30 | 000,004,692 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2011/05/06 08:14:30 | 000,000,008 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
[2011/03/03 20:14:28 | 000,224,680 | ---- | C] () -- C:\windows\System32\AsusService.exe
[2011/03/03 20:14:28 | 000,025,616 | ---- | C] () -- C:\windows\AsAcpiSvrLang.ini
[2011/03/03 20:11:46 | 000,011,520 | ---- | C] () -- C:\windows\System32\drivers\AsUpIO.sys
[2011/03/03 20:11:25 | 000,000,831 | ---- | C] () -- C:\windows\Reboot.ini
[2011/03/03 20:07:01 | 000,451,072 | ---- | C] () -- C:\windows\System32\ISSRemoveSP.exe
[2011/03/03 20:06:35 | 000,014,051 | ---- | C] () -- C:\windows\System32\RaCoInst.dat
[2011/03/02 12:39:08 | 000,000,485 | ---- | C] () -- C:\windows\WinRAR.dll
========== ZeroAccess Check ==========
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
========== LOP Check ==========
[2012/06/08 10:09:17 | 000,000,000 | -HSD | M] -- C:\Users\Owner\AppData\Roaming\.#
[2012/05/17 11:40:41 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CleanMyPC Software
[2012/01/21 16:10:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Clickteam
[2012/07/16 21:23:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
[2011/05/06 08:18:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\E-Cam
[2012/08/21 09:55:52 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\EA
[2012/01/20 07:55:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\flashInstall
[2012/05/23 15:11:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\kingsoft
[2012/05/23 15:12:05 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\KSafe
[2012/01/24 15:37:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Leadertech
[2012/05/08 10:56:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Oberon Media
[2012/09/05 15:41:46 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/16 08:35:47 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/05/30 08:04:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Rovio
[2012/08/21 09:30:32 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SoftGrid Client
[2012/04/22 12:03:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Thinstall
[2012/01/21 10:27:30 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Trio
[2012/09/17 16:48:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2011/07/20 21:56:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\Tasks\At1.job
[2012/07/19 12:54:04 | 000,000,282 | ---- | M] () -- C:\windows\Tasks\KsafeDelay.job
[2012/06/03 08:59:40 | 000,032,618 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU(42).TXT
[2012/09/13 11:12:30 | 000,032,586 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< >
< >
========== Base Services ==========
SRV - [2009/07/13 21:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2010/11/20 08:18:03 | 000,047,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2009/07/13 21:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2010/11/20 08:18:06 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011/11/17 01:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009/07/13 21:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2012/07/04 17:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2012/04/24 00:36:42 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2010/11/20 08:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2010/11/20 08:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2011/03/03 01:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2009/07/13 21:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009/07/13 21:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2009/07/13 21:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2010/11/20 08:19:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/07/13 21:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009/07/13 21:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2009/07/13 21:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2009/07/13 21:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2010/11/20 08:20:30 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2009/07/13 21:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2011/05/24 06:44:59 | 000,293,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2012/02/11 01:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011/11/17 01:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009/07/13 21:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2010/11/20 08:21:00 | 000,286,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2010/11/20 08:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2009/07/13 21:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011/11/17 01:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009/07/13 21:16:20 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010/11/20 08:21:26 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2010/11/20 08:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010/11/20 08:21:05 | 000,750,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2010/11/20 08:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/13 21:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2012/05/01 00:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2010/11/20 08:17:51 | 001,025,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2010/11/20 08:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2010/11/20 08:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2010/11/20 08:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010/11/20 08:21:35 | 001,086,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (eventlog)
SRV - [2010/11/20 08:19:40 | 000,566,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2010/11/20 08:21:35 | 000,463,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (StiSvc)
SRV - [2010/11/20 08:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\System32\msiexec.exe -- (msiserver)
SRV - [2009/07/13 21:16:19 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012/06/02 18:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2010/11/20 08:18:34 | 000,214,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009/07/13 21:16:19 | 000,829,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2010/11/20 08:21:36 | 000,084,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
< MD5 for: QMGR.DLL >
[2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) MD5=E585445D5021971FAE10393F0F1C3961 -- C:\Windows\erdnt\cache\qmgr.dll
[2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) MD5=E585445D5021971FAE10393F0F1C3961 -- C:\Windows\System32\qmgr.dll
[2010/11/20 08:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) MD5=E585445D5021971FAE10393F0F1C3961 -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7601.17514_none_25982ed857b42497\qmgr.dll
< MD5 for: SERVICES >
[2012/07/01 10:57:21 | 000,017,589 | ---- | M] () MD5=8949DD322EDF0FD9056657A8E270DC09 -- C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services
< MD5 for: SERVICES.CFG >
[2012/07/27 16:51:34 | 000,586,083 | ---- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\erdnt\cache\services.exe
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml
< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
< %systemdrive%\$Recycle.Bin|@;true;true;true >
========== Alternate Data Streams ==========
@Alternate Data Stream - 177 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:85AA7074
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:5D90B241
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7D288858
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:09867A8B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:92DB4653
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6387AA6C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:73C78BAA
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:02A78DF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:0F6AC518
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:72C99D4E
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A1460B2A
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 9/18/2012 12:38:02 PM - Run 1
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Owner\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.25% Memory free
3.98 Gb Paging File | 2.76 Gb Available in Paging File | 69.31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.87 Gb Total Space | 162.92 Gb Free Space | 74.78% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- Reg Error: Value error. File not found
.cmd [@ = cmdfile] -- Reg Error: Value error. File not found
.com [@ = comfile] -- Reg Error: Value error. File not found
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
.pif [@ = piffile] -- Reg Error: Value error. File not found
.vbs [@ = VBSFile] -- Reg Error: Value error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{007521E6-61EB-4D09-B763-7831A2A9BA41}" = rport=445 | protocol=6 | dir=out | app=system |
"{0910E0BE-BD98-4D25-A044-9B97D5750BC9}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{15A3C0E5-0458-4ADF-A5CE-4BEF5221A323}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{24245C8C-817B-42CB-9EC4-E2E43E7248FA}" = lport=445 | protocol=6 | dir=in | app=system |
"{2BCB9E7F-00A6-4C6A-9381-9B62E52CF393}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{323751EE-19DC-4780-96A3-41147D8105C8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3C2DBA90-6640-48C5-994D-EAA0A7721468}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{3E0AD95A-8B32-452B-B1F1-3303DF4E67BD}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{4636BF4A-F612-48C7-BABD-DC7578F58678}" = lport=137 | protocol=17 | dir=in | app=system |
"{676A8D68-2D56-46E5-9287-6423115603D0}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{68CA31BD-FC2C-4EF3-9320-02DC7B3AB1F4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6F205684-AB09-413C-861A-372FA22582DB}" = rport=139 | protocol=6 | dir=out | app=system |
"{8463A4BF-7B15-453A-ABD9-1A96F8C8E91C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8BF9142C-5132-4DFA-AD1D-35B403C3C378}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8E0860C5-D6B2-4B9C-B9EB-8850CF34F7DF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9FE5318C-F528-4225-B083-C002973166C2}" = lport=138 | protocol=17 | dir=in | app=system |
"{B327744F-90A7-48DD-A40D-645D8F930751}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CB20ED17-AC4D-42AC-BBFD-7915DE39561D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DA178E83-916E-4CD7-B737-CBC4942B666E}" = rport=137 | protocol=17 | dir=out | app=system |
"{DD629F44-B71B-41FC-8536-1B16D368AA69}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E0FD4CD2-3046-4DD5-A45B-3AA680F4F61B}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{E2892C30-EF8D-43D2-AC5A-EE57C70DEE88}" = rport=138 | protocol=17 | dir=out | app=system |
"{ECDD1A07-4BDD-4977-9C9F-EC026F753198}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FEC1C1BF-9B03-4727-857A-52715DC4D970}" = lport=139 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{345BB574-1F36-4501-96E3-8E9F748DF270}" = protocol=1 | dir=out | [email protected],-28544 |
"{34CE7F7D-E771-429E-8E61-B34536AB7A0F}" = protocol=1 | dir=in | [email protected],-28543 |
"{48EFC471-AFAB-4FB8-BD6C-3187267C4141}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{4B9E5841-1456-4BD9-B1C8-210ACC591C1D}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{5E5EE982-80D4-422A-A561-54AD118A8A68}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{BCCBF055-36FF-4E4E-83A4-89A83D7FFD31}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{C39D9F14-5754-460A-9E65-FCF8D0F6761C}" = protocol=58 | dir=in | [email protected],-28545 |
"{DE9CD1EF-5A8D-47FA-9E06-A0FC2B76727B}" = protocol=58 | dir=out | [email protected],-28546 |
"{E8C6A4E2-9F45-4A86-9936-E5B120AE7B54}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"TCP Query User{C941F8AF-27ED-4F39-8FBF-8D83C43FD6A2}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{88B7AB50-5924-4176-AB8D-CE8128E09B1B}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07A6B206-3F11-4D92-92A1-90E116ADD660}" = Angry Birds
"{08A25478-C5DD-4EA7-B168-3D687CA987FF}" = The Sims™ 3 Master Suite Stuff
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"{185AFA7A-F63E-450B-94AA-011CAC18090E}" = E-Cam
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java 6 Update 31
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38E5A3B1-ADF1-47E0-8024-76310A30EB36}" = LiveUpdate
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = The Sims™ 3 Late Night
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4B5092B6-F231-4D18-83BC-2618B729CA45}" = CapsHook
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate for Eee PC
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6333FC29-BFE5-4024-AC78-958A1A7555D1}" = EeeSplendid
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{71C0E38E-09F2-4386-9977-404D4F6640CD}" = Hotkey Service
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7D5F8291-24FE-11E1-BCE5-F04DA23A5C58}" = MSVCRT Redists
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D40CF-8491-44AD-8FA8-7389CB418C64}" = 32 Bit HP CIO Components Installer
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88F08F98-12BC-4613-81A2-8F9B88CFC73E}" = Super Hybrid Engine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3D8C60-A55F-4fed-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F58C1D44-4AC9-48E8-9049-7A6CDFCB415C}" = LocaleMe
"{F9657EF6-C156-4CE9-A0A2-562CD3E94842}" = Beach Life
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Alchemy Deluxe [PopCap]" = Alchemy Deluxe [PopCap]
"Amazing Adventures 5 (Riddle of the Two Knights) [PopCap]" = Amazing Adventures 5 (Riddle of the Two Knights) [PopCap]
"B41C7C96D83162A676DA7365ADEFD6C1AF62A4EE" = Windows Driver Package - Broadcom Bluetooth (07/17/2009 6.2.0.9403)
"B5C82F3814F82FB37F1513B3185399BD88892B08" = Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0)
"BF20603967CFDCB2BBF91950E8A56DFBC5C833FE" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"Casino Island To Go" = GameHouse Games Collection: Casino Island To Go
"chartertoolbar" = Charter Toolbar
"CleanMyPC - Registry Cleaner_is1" = CleanMyPC - Registry Cleaner
"DAEMON Tools Lite" = DAEMON Tools Lite
"Escape Rosecliff Island [PopCap]" = Escape Rosecliff Island [PopCap]
"Escape Whisper Valley [PopCap]" = Escape Whisper Valley [PopCap]
"Game Booster_is1" = Game Booster 3
"HDMI" = Intel® Graphics Media Accelerator Driver
"Hidden Identity (Chicago Blackout) [PopCap]" = Hidden Identity (Chicago Blackout) [PopCap]
"InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}" = FontResizer
"Intel AppUp(SM) center 11779" = Intel AppUp(SM) center
"Kingsoft Internet Security" = Kingsoft Antivirus 2012
"Kingsoft PC Doctor" = Kingsoft PC Doctor 3.7.0.47
"Magic Inlay" = GameHouse Games Collection: Magic Inlay
"MCLIENT" = Norton Management
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mystery Case Files (Huntsville) [PopCap]" = Mystery Case Files (Huntsville) [PopCap]
"Mystery P.I. 6 (Stolen in San Francisco) [PopCap]" = Mystery P.I. 6 (Stolen in San Francisco) [PopCap]
"Mystery P.I. 7 (The Curious Case of Counterfeit Cove) [PopCap]" = Mystery P.I. 7 (The Curious Case of Counterfeit Cove) [PopCap]
"NAV" = Norton AntiVirus
"NST" = Norton Safe Web Lite
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Origin" = Origin
"Poker Superstars" = GameHouse Games Collection: Poker Superstars
"Puzzle Inlay" = GameHouse Games Collection: Puzzle Inlay
"RocketBowl Plus [PopCap]" = RocketBowl Plus [PopCap]
"Super TextTwist" = GameHouse Games Collection: Super TextTwist
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The Wizard's Pen [PopCap]" = The Wizard's Pen [PopCap]
"Typer Shark! Deluxe [PopCap]" = Typer Shark! Deluxe [PopCap]
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"Word Slinger" = GameHouse Games Collection: Word Slinger
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 2/21/2012 9:48:03 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.2.0.148, time stamp:
0x4d84016e Faulting module name: TS3W.exe, version: 0.2.0.148, time stamp: 0x4d84016e
Exception
code: 0x80000003 Fault offset: 0x0017f196 Faulting process id: 0x1a58 Faulting application
start time: 0x01ccf09f524051c4 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: ac4008f7-5c92-11e1-9974-f46d040a3b01
Error - 2/21/2012 9:50:17 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.2.0.148, time stamp:
0x4d84016e Faulting module name: TS3W.exe, version: 0.2.0.148, time stamp: 0x4d84016e
Exception
code: 0x80000003 Fault offset: 0x0017f196 Faulting process id: 0x1ff8 Faulting application
start time: 0x01ccf09fb07878ce Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: fc3d3f91-5c92-11e1-9974-f46d040a3b01
Error - 2/21/2012 9:52:18 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.2.0.148, time stamp:
0x4d84016e Faulting module name: TS3W.exe, version: 0.2.0.148, time stamp: 0x4d84016e
Exception
code: 0x80000003 Fault offset: 0x0017f196 Faulting process id: 0xae0 Faulting application
start time: 0x01ccf09ff9ed0586 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 441e70d3-5c93-11e1-9974-f46d040a3b01
Error - 2/21/2012 9:55:52 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x17a0 Faulting application
start time: 0x01ccf0a079b0ceef Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: c3b13085-5c93-11e1-9974-f46d040a3b01
Error - 2/21/2012 10:00:27 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x1f50 Faulting application
start time: 0x01ccf0a11c0d9a47 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 680ba6c1-5c94-11e1-9974-f46d040a3b01
Error - 2/21/2012 10:03:17 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x1bd4 Faulting application
start time: 0x01ccf0a183f7ab72 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: cd6427e4-5c94-11e1-9974-f46d040a3b01
Error - 2/21/2012 10:48:58 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x1688 Faulting application
start time: 0x01ccf0a7d78fe878 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 2ece7b84-5c9b-11e1-afaf-f46d040a3b01
Error - 2/21/2012 11:01:14 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x10e8 Faulting application
start time: 0x01ccf0a99b671662 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: e5b3ff2c-5c9c-11e1-9a51-f46d040a3b01
Error - 2/21/2012 11:04:08 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0x95c Faulting application
start time: 0x01ccf0aa01f901e5 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 4d9ef439-5c9d-11e1-9a51-f46d040a3b01
Error - 2/21/2012 11:12:45 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: TS3W.exe, version: 0.430.0.521, time stamp:
0x4e03d26d Faulting module name: TS3W.exe, version: 0.430.0.521, time stamp: 0x4e03d26d
Exception
code: 0x80000003 Fault offset: 0x0017fa66 Faulting process id: 0xa3c Faulting application
start time: 0x01ccf0ab35d871c1 Faulting application path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Faulting module path: C:\Program Files\Electronic
Arts\The Sims 3\Game\Bin\TS3W.exe Report Id: 81bb3d03-5c9e-11e1-8efe-f46d040a3b01
[ System Events ]
Error - 9/18/2012 9:58:24 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 9/18/2012 9:59:08 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 9/18/2012 9:59:23 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 9/18/2012 10:02:06 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =
Error - 9/18/2012 10:03:46 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The uTorrent service failed to start due to the following error: %%2
Error - 9/18/2012 10:04:57 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the HASP
License Manager service to connect.
Error - 9/18/2012 10:05:01 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%1053
Error - 9/18/2012 10:09:44 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description = The catchme service failed to start due to the following error: %%2
Error - 9/18/2012 12:02:10 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10016
Description =
Error - 9/18/2012 12:02:10 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10016
Description =
< End of report >
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-09-18 13:40:56
-----------------------------
13:40:56.225 OS Version: Windows 6.1.7601 Service Pack 1
13:40:56.225 Number of processors: 2 586 0x1C0A
13:40:56.240 ComputerName: OWNER-PC UserName: Owner
13:41:00.203 Initialize success
13:41:12.761 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
13:41:12.776 Disk 0 Vendor: Hitachi_ ESBO Size: 238475MB BusType: 3
13:41:12.792 Disk 0 MBR read successfully
13:41:12.807 Disk 0 MBR scan
13:41:12.823 Disk 0 Windows 7 default MBR code
13:41:12.839 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 223097 MB offset 2048
13:41:12.870 Disk 0 Partition 2 00 1B Hidd FAT32 MSDOS5.0 15360 MB offset 456904704
13:41:12.901 Disk 0 Partition 3 00 EF EFI FAT 16 MB offset 488361984
13:41:12.917 Disk 0 scanning sectors +488394752
13:41:13.010 Disk 0 scanning C:\windows\system32\drivers
13:41:22.557 Service scanning
13:41:34.538 Service KDHacker c:\program files\kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys **LOCKED** 5
13:41:35.131 Service KUsbGuard C:\Program Files\Kingsoft\kingsoft antivirus\kusbquery.sys **LOCKED** 5
13:41:53.352 Modules scanning
13:42:19.919 Disk 0 trace - called modules:
13:42:20.043 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys sptd.sys
13:42:20.075 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86817030]
13:42:20.106 3 CLASSPNP.SYS[8898a59e] -> nt!IofCallDriver -> [0x8407f680]
13:42:20.137 5 ACPI.sys[823b23d4] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84982028]
13:42:20.168 Scan finished successfully
13:42:30.932 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
13:42:30.964 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
#4
Posted 18 September 2012 - 01:02 PM
Could you let me know if the redirects still occur after this run
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1t8w3fv) IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms} IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...0001c4bd6e04197 IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...&ver=4.0.0.1606 IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms} FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found [2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] [2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\Windows\System32\BOOTTVID.DLL () O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found. O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found :Files C:\windows\Tasks\At*.job :Commands [purity] [resethosts] [emptytemp] [CREATERESTOREPOINT] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
#5
Posted 18 September 2012 - 01:56 PM
OTL logfile created on: 9/18/2012 3:40:00 PM - Run 2
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Owner\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 59.05% Memory free
3.98 Gb Paging File | 3.06 Gb Available in Paging File | 76.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.87 Gb Total Space | 162.92 Gb Free Space | 74.78% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/09/11 07:04:14 | 001,595,056 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxetray.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccSvcHst.exe
PRC - [2012/06/11 16:22:16 | 000,267,856 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BingApp.exe
PRC - [2012/06/11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
PRC - [2012/05/12 02:02:46 | 001,403,640 | ---- | M] (CleanMyPC Software) -- C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
PRC - [2012/04/11 02:35:48 | 000,742,816 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\PCDoctor\KSafeTray.exe
PRC - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) -- C:\Program files\Kingsoft\PCDoctor\KSafeSvc.exe
PRC - [2011/10/11 13:49:14 | 001,179,648 | ---- | M] (W3i, LLC) -- C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
PRC - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\windows\Explorer.EXE
PRC - [2010/12/07 13:20:02 | 000,101,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe
PRC - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () -- C:\windows\System32\AsusService.exe
PRC - [2010/12/07 13:19:52 | 001,248,176 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\HotkeyService\HotkeyService.exe
PRC - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/22 15:12:34 | 001,086,888 | ---- | M] (AsusTek Computer Inc.) -- C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
PRC - [2010/06/09 18:26:34 | 000,412,600 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
PRC - [2010/05/28 20:41:36 | 000,445,344 | ---- | M] (ASUS) -- C:\Program Files\EeePC\CapsHook\CapsHook.exe
PRC - [2009/11/19 09:44:14 | 000,083,240 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/21 05:01:48 | 000,140,664 | ---- | M] () -- C:\Program files\Kingsoft\PCDoctor\zlib1.dll
MOD - [2011/10/21 05:01:40 | 000,075,160 | ---- | M] () -- C:\Program Files\Kingsoft\PCDoctor\json.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Running] -- -- (WdiSystemHost)
SRV - File not found [On_Demand | Running] -- -- (WdiServiceHost)
SRV - File not found [Auto | Stopped] -- C:\Program Files\uTorrent\uTorent.exe -- (uTorrentService)
SRV - File not found [On_Demand | Stopped] -- -- (MSDTC)
SRV - [2012/08/14 16:53:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe -- (kxescore)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccSvcHst.exe -- (NAV)
SRV - [2012/06/11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe -- (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe -- (BBSvc)
SRV - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program files\Kingsoft\PCDoctor\KSafeSvc.exe -- (KSafeSvc)
SRV - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe -- (MCLIENT)
SRV - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () [On_Demand | Running] -- C:\windows\System32\AsusService.exe -- (AsusService)
SRV - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe -- (NSL)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2007/03/15 14:48:26 | 000,535,807 | ---- | M] (Aladdin Knowledge Systems Ltd.) [On_Demand | Stopped] -- C:\windows\System32\hasplms.exe -- (hasplms)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Unknown] -- system32\drivers\Partizan.sys -- (Partizan)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\mcdbus.sys -- (mcdbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Owner\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwrchid.sys -- (btwrchid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwavdt.sys -- (btwavdt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a0gr1onw)
DRV - [2012/09/17 16:53:03 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120918.001\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/09/17 16:53:03 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120918.001\NAVENG.SYS -- (NAVENG)
DRV - [2012/09/14 08:41:34 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\IPSDefs\20120917.001\IDSvix86.sys -- (IDSVix86)
DRV - [2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) [Kernel | Disabled | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kusbquery.sys -- (KUsbGuard)
DRV - [2012/08/31 18:09:14 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\BASHDefs\20120905.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\kisknl.sys -- (kisknl)
DRV - [2012/08/17 09:09:53 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/09 07:37:55 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/10 19:09:06 | 000,125,784 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- c:\Program Files\Kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys -- (KDHacker)
DRV - [2012/07/10 19:09:06 | 000,027,240 | ---- | M] (Kingsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kavbootc.sys -- (kavbootc)
DRV - [2012/07/10 19:09:04 | 000,082,264 | ---- | M] (Kingsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ksapi.sys -- (ksapi)
DRV - [2012/07/05 22:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtspx.sys -- (SRTSPX)
DRV - [2012/06/30 20:05:29 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/06/07 00:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ccsetx86.sys -- (ccSet_NAV)
DRV - [2012/05/21 21:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symefa.sys -- (SymEFA)
DRV - [2012/04/30 10:43:27 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012/04/17 22:13:32 | 000,318,584 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symnets.sys -- (SymNetS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ironx86.sys -- (SymIRON)
DRV - [2012/03/23 10:19:42 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/12/19 21:58:08 | 000,111,008 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- C:\Program Files\Kingsoft\PCDoctor\kmodurl.sys -- (kmodurl)
DRV - [2011/10/01 09:30:42 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2011/10/01 09:30:40 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2011/10/01 09:30:38 | 000,194,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2011/10/01 09:30:36 | 000,579,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2011/08/08 11:38:12 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\MCLIENT\0101010.003\ccSetx86.sys -- (ccSet_MCLIENT)
DRV - [2011/07/25 22:18:36 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symds.sys -- (SymDS)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2010/08/24 05:55:51 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/07/01 21:14:00 | 001,015,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192se.sys -- (rtl8192se)
DRV - [2010/03/30 21:40:20 | 000,011,520 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2009/10/05 13:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/20 05:29:40 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/01 00:46:20 | 000,043,944 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2007/03/12 20:48:56 | 000,351,744 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aksfridge.sys -- (aksfridge)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKLM\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://home.myplayci...s={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...0001c4bd6e04197
IE - HKCU\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...&ver=4.0.0.1606
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...n=&geo=US&ver=1
IE - HKCU\..\SearchScopes\{EED02185-CF0A-4895-B284-53562CE2A44E}: "URL" = http://websearch.ask...1-26BFE1EB43D2
IE - HKCU\..\SearchScopes\{EED10D7A-B1C4-498D-8E37-F9327FD2358E}: "URL" = http://search.yahoo....01,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\IPSFFPlgn\ [2012/09/17 16:48:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/05/15 19:11:54 | 000,000,000 | ---D | M]
[2012/06/18 01:07:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/06/17 18:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
[2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
O1 HOSTS File: ([2012/09/17 15:56:01 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\windows\System32\BOOTTVID.DLL ()
O2 - BHO: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL (Charter Communications)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\IPS\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL (Charter Communications)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [KSafeTray] C:\Program files\Kingsoft\PCDoctor\KSafeTray.exe (Kingsoft Corporation)
O4 - HKLM..\Run: [kxesc] c:\program files\kingsoft\kingsoft antivirus\kxetray.exe (Kingsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: moove.com ([]* in Trusted sites)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.syste...ent_4.5.1.0.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...yri_4.5.1.0.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00491AA3-92D1-4157-B062-7163FE4BA717}: DhcpNameServer = 168.94.0.15 168.94.0.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{110D093A-1A15-48F9-A930-65F7B997C492}: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = comfile] -- Reg Error: Value error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2030/01/01 15:03:33 | 000,000,000 | ---D | C] -- C:\Boot
[2012/09/18 15:28:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/18 13:39:39 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Owner\Desktop\aswMBR.exe
[2012/09/18 12:26:41 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 09:27:26 | 000,000,000 | ---D | C] -- C:\windows\$regcmp$
[2012/09/17 19:43:45 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/09/17 18:45:59 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/17 16:07:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\temp
[2012/09/17 14:44:33 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2012/09/16 08:35:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/09/15 15:50:02 | 000,000,000 | ---D | C] -- C:\ProgramData\KRSHistory
[2012/09/15 11:47:34 | 000,203,120 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTSD.sys
[2012/09/15 11:47:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012/09/14 21:23:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Apps
[2012/09/14 10:56:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2012/09/14 10:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\Games for Windows
[2012/09/13 07:00:31 | 000,000,000 | ---D | C] -- C:\windows\System32\1018
[2012/09/13 06:53:21 | 000,000,000 | ---D | C] -- C:\windows\System32\1017
[2012/09/11 07:04:18 | 000,018,296 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:18 | 000,014,200 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/06 08:04:40 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\sims
[2012/09/05 20:27:34 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2012/09/05 17:40:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Electronic Arts
[2012/09/05 15:41:21 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/05 15:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2012/09/05 15:39:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Origin
[2012/09/05 15:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2012/09/05 15:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2012/09/05 15:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2012/08/21 09:55:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\EA
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/18 15:39:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/18 15:38:43 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 15:38:43 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 15:31:13 | 000,000,880 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/18 15:30:50 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2012/09/18 15:30:29 | 1602,887,680 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/18 14:53:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/09/18 13:42:30 | 000,000,512 | ---- | M] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/09/18 13:39:54 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Owner\Desktop\aswMBR.exe
[2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 06:50:14 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt
[2012/09/18 06:50:14 | 000,001,688 | ---- | M] () -- C:\windows\System32\autoexec.nt
[2012/09/18 06:50:14 | 000,000,002 | RHS- | M] () -- C:\windows\winstart.bat
[2012/09/17 19:26:36 | 000,278,928 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/17 15:56:01 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\tasks\At1.job
[2012/09/15 11:52:55 | 001,487,627 | ---- | M] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | M] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/14 06:46:32 | 000,660,762 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/09/14 06:46:32 | 000,121,400 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/09/13 10:24:31 | 000,002,154 | ---- | M] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/11 07:04:09 | 000,018,296 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/05 15:36:23 | 000,000,901 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | M] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | M] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:23:08 | 000,000,748 | ---- | M] () -- C:\windows\eReg.dat
[2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kisknl.sys
[2012/08/21 09:29:41 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | M] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | M] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | M] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2030/01/01 15:03:34 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012/09/18 13:42:30 | 000,000,512 | ---- | C] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/09/18 06:50:14 | 000,000,002 | RHS- | C] () -- C:\windows\winstart.bat
[2012/09/17 19:26:12 | 000,278,928 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/15 11:48:09 | 001,487,627 | ---- | C] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | C] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/13 10:24:31 | 000,002,154 | ---- | C] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/05 15:36:22 | 000,000,901 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | C] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | C] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:35:51 | 000,024,576 | ---- | C] () -- C:\windows\UniFISH.exe
[2012/08/21 09:29:41 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | C] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | C] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | C] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2012/08/16 22:41:22 | 000,000,017 | ---- | C] () -- C:\windows\System32\shortcut_ex.dat
[2012/08/10 22:10:44 | 000,091,072 | ---- | C] () -- C:\windows\System32\RoseCo2.dll
[2012/07/30 07:23:18 | 000,000,233 | ---- | C] () -- C:\windows\SIERRA.INI
[2012/04/23 12:51:28 | 000,004,096 | ---- | C] () -- C:\windows\d3dx.dat
[2012/01/30 16:52:55 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx11_442.dll
[2012/01/30 16:51:51 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx9_2225.dll
[2012/01/24 15:50:07 | 000,043,520 | ---- | C] () -- C:\windows\System32\CmdLineExt03.dll
[2012/01/17 21:43:29 | 000,000,748 | ---- | C] () -- C:\windows\eReg.dat
[2011/11/28 19:26:09 | 000,000,064 | ---- | C] () -- C:\windows\GPlrLanc.dat
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibilllitycpl.dll
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibillitycpl.dll
[2011/05/06 08:19:38 | 000,005,576 | ---- | C] () -- C:\windows\Language.ini
[2011/05/06 08:14:30 | 000,004,692 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2011/05/06 08:14:30 | 000,000,008 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
[2011/03/03 20:14:28 | 000,224,680 | ---- | C] () -- C:\windows\System32\AsusService.exe
[2011/03/03 20:14:28 | 000,025,616 | ---- | C] () -- C:\windows\AsAcpiSvrLang.ini
[2011/03/03 20:11:46 | 000,011,520 | ---- | C] () -- C:\windows\System32\drivers\AsUpIO.sys
[2011/03/03 20:11:25 | 000,000,831 | ---- | C] () -- C:\windows\Reboot.ini
[2011/03/03 20:07:01 | 000,451,072 | ---- | C] () -- C:\windows\System32\ISSRemoveSP.exe
[2011/03/03 20:06:35 | 000,014,051 | ---- | C] () -- C:\windows\System32\RaCoInst.dat
[2011/03/02 12:39:08 | 000,000,485 | ---- | C] () -- C:\windows\WinRAR.dll
========== ZeroAccess Check ==========
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
========== LOP Check ==========
[2012/06/08 10:09:17 | 000,000,000 | -HSD | M] -- C:\Users\Owner\AppData\Roaming\.#
[2012/05/17 11:40:41 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CleanMyPC Software
[2012/01/21 16:10:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Clickteam
[2012/07/16 21:23:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
[2011/05/06 08:18:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\E-Cam
[2012/08/21 09:55:52 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\EA
[2012/01/20 07:55:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\flashInstall
[2012/05/23 15:11:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\kingsoft
[2012/05/23 15:12:05 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\KSafe
[2012/01/24 15:37:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Leadertech
[2012/05/08 10:56:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Oberon Media
[2012/09/05 15:41:46 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/16 08:35:47 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/05/30 08:04:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Rovio
[2012/08/21 09:30:32 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SoftGrid Client
[2012/04/22 12:03:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Thinstall
[2012/01/21 10:27:30 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Trio
[2012/09/17 16:48:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2011/07/20 21:56:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\Tasks\At1.job
[2012/07/19 12:54:04 | 000,000,282 | ---- | M] () -- C:\windows\Tasks\KsafeDelay.job
[2012/06/03 08:59:40 | 000,032,618 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU(42).TXT
[2012/09/13 11:12:30 | 000,032,586 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 177 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:85AA7074
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:5D90B241
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7D288858
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:09867A8B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:92DB4653
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6387AA6C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:73C78BAA
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:02A78DF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:0F6AC518
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:72C99D4E
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A1460B2A
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
All processes killed
Error: Unable to interpret <:OTLDRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1t8w3fv)IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...{searchTerms}IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...01c4bd6e04197IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...er=4.0.0.1606IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...{searchTerms}FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found[2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roa> in the current context!
Error: Unable to interpret <ming\Mozilla\Firefox\Profiles\0\extensions\[email protected][2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\Windows\System32\BOOTTVID.DLL ()O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not foundO4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found:FilesC:\windows\Tasks\At*.job:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]> in the current context!
OTL by OldTimer - Version 3.2.63.0 log created on 09182012_152857
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
OTL by OldTimer - Version 3.2.63.0 Folder = C:\Users\Owner\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 59.05% Memory free
3.98 Gb Paging File | 3.06 Gb Available in Paging File | 76.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 217.87 Gb Total Space | 162.92 Gb Free Space | 74.78% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/09/11 07:04:14 | 001,595,056 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxetray.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccSvcHst.exe
PRC - [2012/06/11 16:22:16 | 000,267,856 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BingApp.exe
PRC - [2012/06/11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
PRC - [2012/05/12 02:02:46 | 001,403,640 | ---- | M] (CleanMyPC Software) -- C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
PRC - [2012/04/11 02:35:48 | 000,742,816 | ---- | M] (Kingsoft Corporation) -- C:\Program Files\Kingsoft\PCDoctor\KSafeTray.exe
PRC - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) -- C:\Program files\Kingsoft\PCDoctor\KSafeSvc.exe
PRC - [2011/10/11 13:49:14 | 001,179,648 | ---- | M] (W3i, LLC) -- C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
PRC - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\windows\Explorer.EXE
PRC - [2010/12/07 13:20:02 | 000,101,288 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe
PRC - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () -- C:\windows\System32\AsusService.exe
PRC - [2010/12/07 13:19:52 | 001,248,176 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\HotkeyService\HotkeyService.exe
PRC - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/22 15:12:34 | 001,086,888 | ---- | M] (AsusTek Computer Inc.) -- C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
PRC - [2010/06/09 18:26:34 | 000,412,600 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
PRC - [2010/05/28 20:41:36 | 000,445,344 | ---- | M] (ASUS) -- C:\Program Files\EeePC\CapsHook\CapsHook.exe
PRC - [2009/11/19 09:44:14 | 000,083,240 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/21 05:01:48 | 000,140,664 | ---- | M] () -- C:\Program files\Kingsoft\PCDoctor\zlib1.dll
MOD - [2011/10/21 05:01:40 | 000,075,160 | ---- | M] () -- C:\Program Files\Kingsoft\PCDoctor\json.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Running] -- -- (WdiSystemHost)
SRV - File not found [On_Demand | Running] -- -- (WdiServiceHost)
SRV - File not found [Auto | Stopped] -- C:\Program Files\uTorrent\uTorent.exe -- (uTorrentService)
SRV - File not found [On_Demand | Stopped] -- -- (MSDTC)
SRV - [2012/08/14 16:53:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/10 19:09:04 | 000,123,992 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kxescore.exe -- (kxescore)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\ccSvcHst.exe -- (NAV)
SRV - [2012/06/11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe -- (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe -- (BBSvc)
SRV - [2012/04/10 13:07:58 | 000,290,720 | ---- | M] (Kingsoft Corporation) [Auto | Running] -- C:\Program files\Kingsoft\PCDoctor\KSafeSvc.exe -- (KSafeSvc)
SRV - [2011/10/01 09:30:42 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:36 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Management\Engine\1.1.1.3\ccSvcHst.exe -- (MCLIENT)
SRV - [2010/12/07 13:19:54 | 000,224,680 | ---- | M] () [On_Demand | Running] -- C:\windows\System32\AsusService.exe -- (AsusService)
SRV - [2010/11/23 22:21:18 | 000,130,000 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe -- (NSL)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2007/03/15 14:48:26 | 000,535,807 | ---- | M] (Aladdin Knowledge Systems Ltd.) [On_Demand | Stopped] -- C:\windows\System32\hasplms.exe -- (hasplms)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Unknown] -- system32\drivers\Partizan.sys -- (Partizan)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\mcdbus.sys -- (mcdbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Owner\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwrchid.sys -- (btwrchid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwl2cap.sys -- (btwl2cap)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\DRIVERS\btwavdt.sys -- (btwavdt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btwaudio.sys -- (btwaudio)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a0gr1onw)
DRV - [2012/09/17 16:53:03 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120918.001\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/09/17 16:53:03 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\VirusDefs\20120918.001\NAVENG.SYS -- (NAVENG)
DRV - [2012/09/14 08:41:34 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\IPSDefs\20120917.001\IDSvix86.sys -- (IDSVix86)
DRV - [2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) [Kernel | Disabled | Running] -- C:\Program Files\Kingsoft\kingsoft antivirus\kusbquery.sys -- (KUsbGuard)
DRV - [2012/08/31 18:09:14 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\Definitions\BASHDefs\20120905.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\kisknl.sys -- (kisknl)
DRV - [2012/08/17 09:09:53 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/09 07:37:55 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/10 19:09:06 | 000,125,784 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- c:\Program Files\Kingsoft\kingsoft antivirus\security\kxescan\kdhacker.sys -- (KDHacker)
DRV - [2012/07/10 19:09:06 | 000,027,240 | ---- | M] (Kingsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kavbootc.sys -- (kavbootc)
DRV - [2012/07/10 19:09:04 | 000,082,264 | ---- | M] (Kingsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ksapi.sys -- (ksapi)
DRV - [2012/07/05 22:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 22:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\srtspx.sys -- (SRTSPX)
DRV - [2012/06/30 20:05:29 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/06/07 00:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ccsetx86.sys -- (ccSet_NAV)
DRV - [2012/05/21 21:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symefa.sys -- (SymEFA)
DRV - [2012/04/30 10:43:27 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012/04/17 22:13:32 | 000,318,584 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symnets.sys -- (SymNetS)
DRV - [2012/04/17 21:42:14 | 000,149,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\ironx86.sys -- (SymIRON)
DRV - [2012/03/23 10:19:42 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/12/19 21:58:08 | 000,111,008 | ---- | M] (Kingsoft Corporation) [Kernel | System | Running] -- C:\Program Files\Kingsoft\PCDoctor\kmodurl.sys -- (kmodurl)
DRV - [2011/10/01 09:30:42 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2011/10/01 09:30:40 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2011/10/01 09:30:38 | 000,194,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2011/10/01 09:30:36 | 000,579,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2011/08/08 11:38:12 | 000,132,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\MCLIENT\0101010.003\ccSetx86.sys -- (ccSet_MCLIENT)
DRV - [2011/07/25 22:18:36 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NAV\1308000.00E\symds.sys -- (SymDS)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2010/08/24 05:55:51 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/07/01 21:14:00 | 001,015,912 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rtl8192se.sys -- (rtl8192se)
DRV - [2010/03/30 21:40:20 | 000,011,520 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsUpIO.sys -- (AsUpIO)
DRV - [2009/10/05 13:31:50 | 001,221,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/20 05:29:40 | 000,013,880 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/01 00:46:20 | 000,043,944 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2007/03/12 20:48:56 | 000,351,744 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\aksfridge.sys -- (aksfridge)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKLM\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://home.myplayci...s={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://eeepc.asus.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = charter.net
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...0001c4bd6e04197
IE - HKCU\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...&ver=4.0.0.1606
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...n=&geo=US&ver=1
IE - HKCU\..\SearchScopes\{EED02185-CF0A-4895-B284-53562CE2A44E}: "URL" = http://websearch.ask...1-26BFE1EB43D2
IE - HKCU\..\SearchScopes\{EED10D7A-B1C4-498D-8E37-F9327FD2358E}: "URL" = http://search.yahoo....01,17118,0,18,0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files\Common Files\Oberon Media\NCAdapter\1.0.0.8\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\IPSFFPlgn\ [2012/09/17 16:48:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/05/15 19:11:54 | 000,000,000 | ---D | M]
[2012/06/18 01:07:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/06/17 18:33:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
[2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
[2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
O1 HOSTS File: ([2012/09/17 15:56:01 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\windows\System32\BOOTTVID.DLL ()
O2 - BHO: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL (Charter Communications)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.8.0.14\IPS\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Charter Toolbar) - {4E7BD74F-2B8D-469E-85AB-AF21F3D9AE2F} - C:\PROGRA~1\CHARTE~1\CHARTE~1.DLL (Charter Communications)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [KSafeTray] C:\Program files\Kingsoft\PCDoctor\KSafeTray.exe (Kingsoft Corporation)
O4 - HKLM..\Run: [kxesc] c:\program files\kingsoft\kingsoft antivirus\kxetray.exe (Kingsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: moove.com ([]* in Trusted sites)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.syste...ent_4.5.1.0.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...yri_4.5.1.0.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00491AA3-92D1-4157-B062-7163FE4BA717}: DhcpNameServer = 168.94.0.15 168.94.0.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{110D093A-1A15-48F9-A930-65F7B997C492}: DhcpNameServer = 24.247.15.53 66.189.0.100 24.178.162.3
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = comfile] -- Reg Error: Value error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2030/01/01 15:03:33 | 000,000,000 | ---D | C] -- C:\Boot
[2012/09/18 15:28:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/18 13:39:39 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Owner\Desktop\aswMBR.exe
[2012/09/18 12:26:41 | 000,600,576 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 09:27:26 | 000,000,000 | ---D | C] -- C:\windows\$regcmp$
[2012/09/17 19:43:45 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Malwarebytes
[2012/09/17 18:45:59 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/17 16:07:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\temp
[2012/09/17 14:44:33 | 000,000,000 | ---D | C] -- C:\windows\erdnt
[2012/09/16 08:35:47 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/09/15 15:50:02 | 000,000,000 | ---D | C] -- C:\ProgramData\KRSHistory
[2012/09/15 11:47:34 | 000,203,120 | ---- | C] (PC Tools) -- C:\windows\System32\drivers\PCTSD.sys
[2012/09/15 11:47:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2012/09/14 21:23:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Apps
[2012/09/14 10:56:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2012/09/14 10:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games for Windows
[2012/09/13 10:24:00 | 000,000,000 | ---D | C] -- C:\Program Files\Games for Windows
[2012/09/13 07:00:31 | 000,000,000 | ---D | C] -- C:\windows\System32\1018
[2012/09/13 06:53:21 | 000,000,000 | ---D | C] -- C:\windows\System32\1017
[2012/09/11 07:04:18 | 000,018,296 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:18 | 000,014,200 | ---- | C] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/06 08:04:40 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\sims
[2012/09/05 20:27:34 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2012/09/05 17:40:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Electronic Arts
[2012/09/05 15:41:21 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/05 15:41:20 | 000,000,000 | ---D | C] -- C:\Program Files\Origin Games
[2012/09/05 15:39:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Origin
[2012/09/05 15:36:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2012/09/05 15:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2012/09/05 15:36:12 | 000,000,000 | ---D | C] -- C:\Program Files\Origin
[2012/08/21 09:55:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\EA
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/18 15:39:00 | 000,000,884 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/18 15:38:43 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 15:38:43 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 15:31:13 | 000,000,880 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/18 15:30:50 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2012/09/18 15:30:29 | 1602,887,680 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/18 14:53:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/09/18 13:42:30 | 000,000,512 | ---- | M] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/09/18 13:39:54 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Owner\Desktop\aswMBR.exe
[2012/09/18 12:27:12 | 000,600,576 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/18 06:50:14 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt
[2012/09/18 06:50:14 | 000,001,688 | ---- | M] () -- C:\windows\System32\autoexec.nt
[2012/09/18 06:50:14 | 000,000,002 | RHS- | M] () -- C:\windows\winstart.bat
[2012/09/17 19:26:36 | 000,278,928 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/17 15:56:01 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\tasks\At1.job
[2012/09/15 11:52:55 | 001,487,627 | ---- | M] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | M] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/14 06:46:32 | 000,660,762 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/09/14 06:46:32 | 000,121,400 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/09/13 10:24:31 | 000,002,154 | ---- | M] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/11 07:04:09 | 000,018,296 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery64.sys
[2012/09/11 07:04:05 | 000,014,200 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kusbquery.sys
[2012/09/05 15:36:23 | 000,000,901 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | M] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | M] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:23:08 | 000,000,748 | ---- | M] () -- C:\windows\eReg.dat
[2012/08/22 16:54:41 | 000,164,728 | ---- | M] (Kingsoft Corporation) -- C:\windows\System32\drivers\kisknl.sys
[2012/08/21 09:29:41 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | M] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | M] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | M] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | M] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2030/01/01 15:03:34 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012/09/18 13:42:30 | 000,000,512 | ---- | C] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/09/18 06:50:14 | 000,000,002 | RHS- | C] () -- C:\windows\winstart.bat
[2012/09/17 19:26:12 | 000,278,928 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2012/09/15 11:48:09 | 001,487,627 | ---- | C] () -- C:\windows\System32\drivers\Cat.DB
[2012/09/14 14:03:55 | 000,002,227 | ---- | C] () -- C:\Users\Owner\Desktop\RocketBowl Plus.lnk
[2012/09/13 10:24:31 | 000,002,154 | ---- | C] () -- C:\Users\Owner\Desktop\PopCap Game Pack.lnk
[2012/09/05 15:36:22 | 000,000,901 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/08/23 11:07:16 | 000,000,000 | ---- | C] () -- C:\windows\PowerReg.dat
[2012/08/22 22:36:49 | 000,002,696 | ---- | C] () -- C:\{5D06E9C4-1A1B-4BFF-BF1D-0A7205E88FD6}
[2012/08/22 21:35:51 | 000,024,576 | ---- | C] () -- C:\windows\UniFISH.exe
[2012/08/21 09:29:41 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Word Slinger.lnk
[2012/08/21 09:29:37 | 000,001,258 | ---- | C] () -- C:\Users\Owner\Desktop\Super TextTwist.lnk
[2012/08/21 09:29:33 | 000,001,247 | ---- | C] () -- C:\Users\Owner\Desktop\Puzzle Inlay.lnk
[2012/08/21 09:29:29 | 000,001,235 | ---- | C] () -- C:\Users\Owner\Desktop\Magic Inlay.lnk
[2012/08/21 09:29:24 | 000,001,301 | ---- | C] () -- C:\Users\Owner\Desktop\Casino Island To Go.lnk
[2012/08/16 22:41:22 | 000,000,017 | ---- | C] () -- C:\windows\System32\shortcut_ex.dat
[2012/08/10 22:10:44 | 000,091,072 | ---- | C] () -- C:\windows\System32\RoseCo2.dll
[2012/07/30 07:23:18 | 000,000,233 | ---- | C] () -- C:\windows\SIERRA.INI
[2012/04/23 12:51:28 | 000,004,096 | ---- | C] () -- C:\windows\d3dx.dat
[2012/01/30 16:52:55 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx11_442.dll
[2012/01/30 16:51:51 | 000,077,824 | ---- | C] () -- C:\windows\System32\d3dx9_2225.dll
[2012/01/24 15:50:07 | 000,043,520 | ---- | C] () -- C:\windows\System32\CmdLineExt03.dll
[2012/01/17 21:43:29 | 000,000,748 | ---- | C] () -- C:\windows\eReg.dat
[2011/11/28 19:26:09 | 000,000,064 | ---- | C] () -- C:\windows\GPlrLanc.dat
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibilllitycpl.dll
[2011/05/06 10:08:19 | 000,208,896 | ---- | C] () -- C:\windows\System32\accessibillitycpl.dll
[2011/05/06 08:19:38 | 000,005,576 | ---- | C] () -- C:\windows\Language.ini
[2011/05/06 08:14:30 | 000,004,692 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2011/05/06 08:14:30 | 000,000,008 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
[2011/03/03 20:14:28 | 000,224,680 | ---- | C] () -- C:\windows\System32\AsusService.exe
[2011/03/03 20:14:28 | 000,025,616 | ---- | C] () -- C:\windows\AsAcpiSvrLang.ini
[2011/03/03 20:11:46 | 000,011,520 | ---- | C] () -- C:\windows\System32\drivers\AsUpIO.sys
[2011/03/03 20:11:25 | 000,000,831 | ---- | C] () -- C:\windows\Reboot.ini
[2011/03/03 20:07:01 | 000,451,072 | ---- | C] () -- C:\windows\System32\ISSRemoveSP.exe
[2011/03/03 20:06:35 | 000,014,051 | ---- | C] () -- C:\windows\System32\RaCoInst.dat
[2011/03/02 12:39:08 | 000,000,485 | ---- | C] () -- C:\windows\WinRAR.dll
========== ZeroAccess Check ==========
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
========== LOP Check ==========
[2012/06/08 10:09:17 | 000,000,000 | -HSD | M] -- C:\Users\Owner\AppData\Roaming\.#
[2012/05/17 11:40:41 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CleanMyPC Software
[2012/01/21 16:10:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Clickteam
[2012/07/16 21:23:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DAEMON Tools Lite
[2011/05/06 08:18:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\E-Cam
[2012/08/21 09:55:52 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\EA
[2012/01/20 07:55:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\flashInstall
[2012/05/23 15:11:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\kingsoft
[2012/05/23 15:12:05 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\KSafe
[2012/01/24 15:37:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Leadertech
[2012/05/08 10:56:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Oberon Media
[2012/09/05 15:41:46 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Origin
[2012/09/16 08:35:47 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2012/05/30 08:04:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Rovio
[2012/08/21 09:30:32 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SoftGrid Client
[2012/04/22 12:03:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Thinstall
[2012/01/21 10:27:30 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Trio
[2012/09/17 16:48:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2011/07/20 21:56:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2012/09/16 13:12:00 | 000,000,350 | ---- | M] () -- C:\windows\Tasks\At1.job
[2012/07/19 12:54:04 | 000,000,282 | ---- | M] () -- C:\windows\Tasks\KsafeDelay.job
[2012/06/03 08:59:40 | 000,032,618 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU(42).TXT
[2012/09/13 11:12:30 | 000,032,586 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 177 bytes -> C:\ProgramData\TEMP:ECF54A0E
@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:85AA7074
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:5D90B241
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7D288858
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:09867A8B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:92DB4653
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6387AA6C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:73C78BAA
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:02A78DF6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:0F6AC518
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:72C99D4E
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A1460B2A
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
All processes killed
Error: Unable to interpret <:OTLDRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1t8w3fv)IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...{searchTerms}IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...01c4bd6e04197IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}: "URL" = http://www.search-re...er=4.0.0.1606IE - HKU\S-1-5-21-1893933335-3957457206-1101798082-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...{searchTerms}FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found[2012/06/22 21:52:44 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Owner\AppData\Roa> in the current context!
Error: Unable to interpret <ming\Mozilla\Firefox\Profiles\0\extensions\[email protected][2012/05/20 22:47:40 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.O2 - BHO: (Adobe PDF Link Helper) - {491C440D-305E-0124-0099-0F3E390C7E87} - C:\Windows\System32\BOOTTVID.DLL ()O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not foundO4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = File not found:FilesC:\windows\Tasks\At*.job:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][Reboot]> in the current context!
OTL by OldTimer - Version 3.2.63.0 log created on 09182012_152857
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
#6
Posted 18 September 2012 - 02:04 PM
Could you rerun the fix please
Download the attached text file to your desktop
[attachment=60597:fix.txt]
Run OTL
Press run fix
A dialogue will open asking for the location of fix.txt
Navigate to the file you just downloaded and select it
Press run fix again
Download the attached text file to your desktop
[attachment=60597:fix.txt]
Run OTL
Press run fix
A dialogue will open asking for the location of fix.txt
Navigate to the file you just downloaded and select it
Press run fix again
#7
Posted 18 September 2012 - 03:31 PM
All processes killed
========== OTL ==========
Error: No service named a1t8w3fv was found to stop!
Service\Driver key a1t8w3fv not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}\ not found.
Registry key HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0\ not found.
Folder C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\ not found.
File C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{491C440D-305E-0124-0099-0F3E390C7E87}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{491C440D-305E-0124-0099-0F3E390C7E87}\ not found.
File C:\Windows\System32\BOOTTVID.DLL not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ not found.
File move failed. C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk scheduled to be moved on reboot.
========== FILES ==========
File\Folder C:\windows\Tasks\At*.job not found.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Owner
->Temp folder emptied: 9894 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.63.0 log created on 09182012_172102
Files\Folders moved on Reboot...
File\Folder C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk not found!
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk not found!
C:\windows\temp\HS.log moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
========== OTL ==========
Error: No service named a1t8w3fv was found to stop!
Service\Driver key a1t8w3fv not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88FB16D2-04EA-4ffe-8079-CFF68F1B9CE6}\ not found.
Registry key HKEY_USERS\S-1-5-21-1893933335-3957457206-1101798082-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0\ not found.
Folder C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\ not found.
File C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{491C440D-305E-0124-0099-0F3E390C7E87}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{491C440D-305E-0124-0099-0F3E390C7E87}\ not found.
File C:\Windows\System32\BOOTTVID.DLL not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ not found.
File move failed. C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk scheduled to be moved on reboot.
========== FILES ==========
File\Folder C:\windows\Tasks\At*.job not found.
========== COMMANDS ==========
C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Owner
->Temp folder emptied: 9894 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.63.0 log created on 09182012_172102
Files\Folders moved on Reboot...
File\Folder C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk not found!
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk not found!
C:\windows\temp\HS.log moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
#8
Posted 19 September 2012 - 05:21 AM
Not quite sure what you did, but everthing seems to be working again!!!! Thank you sooooo much!!!!! Very much appreciated!!!!!!! Can I delete the files on my desk top that were from the scans or do I need to keep them? Thanks again!!!!
#9
Posted 19 September 2012 - 06:31 AM
Let me do itCan I delete the files on my desk top that were from the scans or do I need to keep them
Subject to no further problems
I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems
Now the best part of the day ----- Your log now appears clean
A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:Commands
[resethosts]
[emptytemp]
[Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.
We will now confirm that your hidden files are set to that, as some of the tools I use will change that
- Go to control panel
- Select folder options (Appearance > Folder options in category view)
- Select the View Tab.
- Under the Hidden files and folders heading select Do not show hidden files and folders.
- Click Yes to confirm.
- Click OK.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.
Upgrading Java:
- Go to this site and click Do I have Java
- It will check your current version and then offer to update to the latest version
SPRING CLEAN
To manually create a new Restore Point
- Go to Control Panel and select System
- Select System
- On the left select System Protection and accept the warning if you get one
- Select System Protection Tab
- Select Create at the bottom
- Type in a name i.e. Clean
- Select Create
Now we can purge the infected ones
- GoStart > All programs > Accessories > system tools
- Right click Disc cleanup and select run as administrator
- Select Your main drive and accept the warning if you get one
- For a few moments the system will make some calculations
- Select the More Options tab
- In the System Restore and Shadow Backups select Clean up
- Select Delete on the pop up
- Select OK
- Select Delete
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
Malwarebytes. Update and run weekly to keep your system clean
Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link
It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe
#10
Posted 21 September 2012 - 07:15 AM
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users