Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Frequent system reboot [Solved]

OTL

  • This topic is locked This topic is locked

#1
pissupoosa

pissupoosa

    Member

  • Member
  • PipPip
  • 12 posts

Team,

        I am facing frequent system restarts. And I there is no problem in safe mode. Posting the OTL log for your attension.

 

OTL logfile created on: 7/8/2014 8:55:56 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Rangasamy\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1.98 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 61.13% Memory free
3.83 Gb Paging File | 3.28 Gb Available in Paging File | 85.52% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 78.32 Gb Total Space | 44.23 Gb Free Space | 56.47% Space Free | Partition Type: NTFS
Drive E: | 78.32 Gb Total Space | 58.31 Gb Free Space | 74.45% Space Free | Partition Type: NTFS
Drive F: | 76.24 Gb Total Space | 49.30 Gb Free Space | 64.66% Space Free | Partition Type: NTFS
 
Computer Name: INDIA | User Name: Rangasamy | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/07/08 20:55:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rangasamy\My Documents\Downloads\OTL.exe
PRC - [2014/06/18 10:14:15 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/11/01 08:31:24 | 008,252,744 | ---- | M] (Pokki) -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Pokki\Engine\pokki.exe
PRC - [2013/07/17 10:36:28 | 000,061,024 | ---- | M] (NirSoft) -- C:\bluescreenview\BlueScreenView.exe
PRC - [2008/07/03 14:38:24 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/06/18 10:14:14 | 003,852,912 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014/05/14 07:19:27 | 016,361,136 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll
MOD - [2014/04/27 21:40:07 | 000,489,984 | ---- | M] () -- C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll
MOD - [2013/11/01 08:31:26 | 002,017,608 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Pokki\ocdeskband_1.dll
MOD - [2013/09/07 05:11:12 | 001,400,846 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Pokki\Engine\avcodec-54.dll
MOD - [2013/09/07 05:11:12 | 000,569,856 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Pokki\Engine\ppGoogleNaClPluginChrome.dll
MOD - [2013/09/07 05:11:12 | 000,222,734 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Pokki\Engine\avformat-54.dll
MOD - [2013/09/07 05:11:12 | 000,151,054 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Pokki\Engine\avutil-51.dll
MOD - [2013/09/05 01:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- C:\Program Files\DLCleaner\DLCDefragSrv.exe -- (DLCDiskOptimizer)
SRV - [2014/06/26 12:30:04 | 002,832,704 | ---- | M] (Client Connect LTD) [Auto | Stopped] -- C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe -- (CltMngSvc)
SRV - [2014/06/23 11:47:38 | 001,813,528 | ---- | M] (AVG Secure Search) [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe -- (vToolbarUpdater18.1.7)
SRV - [2014/06/18 10:14:14 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/05/14 07:19:29 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/04/27 21:39:56 | 003,544,064 | ---- | M] (Bandoo Media Inc.) [Auto | Stopped] -- C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe -- (DatamngrCoordinator)
SRV - [2014/02/05 14:34:51 | 000,796,152 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Savevid\SavevidService.exe -- (SavevidService)
SRV - [2013/12/19 01:41:02 | 030,814,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/01/16 09:44:42 | 000,198,136 | ---- | M] (Nitro PDF Software) [Auto | Stopped] -- F:\NitroPDFReaderDriverService2.exe -- (NitroReaderDriverReadSpool2)
SRV - [2011/05/29 10:04:03 | 000,073,600 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ezGOSvc.dll -- (ezGOSvc)
SRV - [2010/03/05 12:50:19 | 000,047,616 | R--- | M] (Mobile Leader Co.,Ltd.) [Auto | Stopped] -- C:\WINDOWS\system32\LGScsiCommandService.exe -- (LGScsiCommandService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbmodem.sys -- (USBModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbdiag.sys -- (UsbDiag)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbbus.sys -- (usbbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgvmodem.sys -- (LGVMODEM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgbtbus.sys -- (lgbusenum)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgbtport.sys -- (LgBttPort)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - [2014/06/23 11:47:45 | 000,042,784 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2014/06/20 16:59:50 | 000,055,224 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}t.sys -- ({1a147621-8c9a-4d6b-a557-6513a40d3207}t)
DRV - [2014/04/27 21:39:56 | 000,031,096 | ---- | M] (Bandoo Media Inc.) [Kernel | System | Stopped] -- C:\Program Files\Movies Toolbar\Datamngr\setmgrc1.cfg -- (F06DEFF2-5B9C-490D-910F-35D3A9119622)
DRV - [2014/04/24 12:30:34 | 000,055,224 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}Gt.sys -- ({1a147621-8c9a-4d6b-a557-6513a40d3207}Gt)
DRV - [2011/03/26 17:00:33 | 000,436,792 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2011/03/26 13:50:14 | 000,475,736 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2010/10/13 07:47:20 | 000,074,280 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3112.sys -- (Si3112)
DRV - [2010/06/09 17:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2010/06/09 17:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (KL1)
DRV - [2010/05/07 12:06:26 | 000,032,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2010/04/27 11:10:52 | 006,031,904 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2010/03/22 11:30:22 | 000,222,672 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2010/02/11 14:36:50 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009/11/18 02:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 02:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/11/02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2008/04/14 15:00:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/14 15:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2008/04/14 15:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2008/04/14 00:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2007/03/01 14:17:54 | 000,170,112 | R--- | M] (Trident Multimedia Technologies Co.,Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TridVid.sys -- (TridVid)
DRV - [2002/07/17 09:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.yahoo.com/?fr=mkg029
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://in.yahoo.com/?fr=mkg029
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope = {498D228A-C32C-4D5D-8424-7520FFBD02B1}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{194de045-cc5e-4840-b031-1ca9db98919d}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{3d29c02b-bf3e-4d3b-8a7a-e0e7d0f6dbab}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{6B528F7B-1290-4F85-BA27-8515B393FF4B}: "URL" = http://www.google.co...age={startPage}
IE - HKLM\..\SearchScopes\{6BA4BBC5-3A34-465E-A7AD-CA216AD72022}: "URL" = http://en.wikipedia....h={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}: "URL" = http://dts.search.as...q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweeti...q={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...73C4F4C2A&SSPV=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-se...121563&tsp=4941
IE - HKCU\..\SearchScopes\{1A8C80AB-6C1A-4B10-A8CF-9EB3B3084D8F}: "URL" = http://www.mysearchr...q={searchTerms}
IE - HKCU\..\SearchScopes\{3d29c02b-bf3e-4d3b-8a7a-e0e7d0f6dbab}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKCU\..\SearchScopes\{498D228A-C32C-4D5D-8424-7520FFBD02B1}: "URL" = http://search.condui...5942085711&UM=2
IE - HKCU\..\SearchScopes\{6B528F7B-1290-4F85-BA27-8515B393FF4B}: "URL" = http://www.google.co...age={startPage}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={D018BF43-BD88-4AE6-AA3F-1BC79EB5F84F}&mid=3ac47794288e47d0a61a25b3361040ba-41801852e3bc4bcc02a33eacb1fe720f428d8514&lang=en&ds=qw011&pr=sa&d=2012-09-04 12:39:41&v=15.3.0.10&pid=avg&sg=0&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}: "URL" = http://dts.search.as...q={searchTerms}
IE - HKCU\..\SearchScopes\{B4F334AD-3C3B-4198-9AD3-111B308F34FB}: "URL" = http://in.search.yah...p={searchTerms}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://in.search.yah...erms}&fr=mkg028
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..CT2269050.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=407453"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: 5qffxtbr%40Zwinky_5q.com:6.52.4.8852
FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.6
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20131118
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.22
FF - prefs.js..extensions.enabledAddons: keepvid.com%40helper.com:2.0.0.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:30.0
FF - prefs.js..keyword.URL: "http://dts.search.as...&o=APN10647&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: F:\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Rangasamy\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Documents and Settings\Rangasamy\Application Data\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/03/26 21:46:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 30.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/06/18 10:13:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 30.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\keepvid\SoundFrost.xpi [2013/12/05 23:13:13 | 000,038,411 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\Rangasamy\keepvid.xpi [2013/12/11 19:10:04 | 000,035,009 | ---- | M] ()
 
[2012/08/06 23:06:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Extensions
[2014/07/06 16:55:07 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions
[2014/07/06 16:55:07 | 000,000,000 | ---D | M] (Movies Toolbar (Dist. by Bandoo Media, Inc.)) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{95bef0b1-9d3a-41f3-bb8b-8275aaa48c66}
[2013/11/26 23:55:09 | 000,000,000 | ---D | M] (WOT) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2014/03/24 19:37:44 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/07/06 16:54:43 | 000,000,000 | ---D | M] (Ask New Tabs) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{BAB3307A-A1CE-D0B4-0112-47BF70236CE8}
[2014/06/10 10:56:08 | 000,000,000 | ---D | M] (Zwinky) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\[email protected]_5q.com
[2014/03/20 21:52:06 | 000,000,000 | ---D | M] (LastPass) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\[email protected]
[2014/07/01 16:54:02 | 000,209,499 | ---- | M] () (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\[email protected]
[2014/07/01 06:30:34 | 000,387,381 | ---- | M] () (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2013/07/02 21:49:56 | 000,345,379 | ---- | M] () (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{30E08C68-889E-11E0-95EF-DA7E4824019B}.xpi
[2014/06/05 14:28:06 | 000,967,387 | ---- | M] () (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014/05/04 11:22:53 | 000,731,942 | ---- | M] () (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2014/07/01 06:38:38 | 000,553,273 | ---- | M] () (No name found) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
[2014/07/06 16:54:57 | 000,002,660 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\Ask.xml
[2013/07/12 09:06:16 | 000,006,507 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\babylon.xml
[2013/07/12 09:06:39 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\delta.xml
[2013/12/06 20:51:21 | 000,001,084 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\dvdvideosofttb-customized-web-search.xml
[2013/03/12 12:02:20 | 000,009,615 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\my-web-search.xml
[2014/07/07 18:49:31 | 000,000,643 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\trovi-search.xml
[2013/12/11 22:57:30 | 000,000,921 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\yahoo.xml
[2014/06/18 10:13:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2014/06/18 10:13:56 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2014/06/18 10:13:56 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]_bak
[2014/06/18 10:13:56 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]_bak
[2014/06/18 10:13:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/06/18 10:14:16 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/12/11 19:10:04 | 000,035,009 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\RANGASAMY\KEEPVID.XPI
 
========== Chrome  ==========
 
CHR - Extension: No name found = C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: No name found = C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_1\
CHR - Extension: No name found = C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\18.1.0.443_0\
CHR - Extension: No name found = C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2008/04/14 15:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (keepvid.com) - {49ed9900-38cd-453c-bba7-3f2613317f5a} - C:\Documents and Settings\Rangasamy\keepvid.dll (keepvid.com Company)
O2 - BHO: (no name) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Rangasamy\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll File not found
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Movies Toolbar (Dist. by Bandoo Media, Inc.)) - {95bef0b1-9d3a-41f3-bb8b-8275aaa48c66} - C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (SoundFrost) - {d997c836-ff82-4519-b459-1482ba942a4f} - C:\Program Files\keepvid\SoundFrost.dll (SoundFrost Company)
O2 - BHO: (no name) - {E33CF602-D945-461A-83F0-819F76A199F8} - No CLSID value found.
O2 - BHO: (entrusted Toolbar) - {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Movies Toolbar (Dist. by Bandoo Media, Inc.)) - {95bef0b1-9d3a-41f3-bb8b-8275aaa48c66} - C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll ()
O3 - HKLM\..\Toolbar: (entrusted Toolbar) - {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (entrusted Toolbar) - {E44A1809-4D10-4AB8-B343-3326B64C7CDD} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
O3:HKU - HKCU\..\Toolbar\WebBrowser: (entrusted Toolbar) - {E44A1809-4D10-4AB8-B343-3326B64C7CDD} - C:\Documents and Settings\Rangasamy\Local Settings\Application Data\entrusted\prxtbent0.dll (ClientConnect Ltd.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_13_0_0_214_Plugin.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - Reg Error: Key error. File not found
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - Reg Error: Key error. File not found
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D797D6AD-7158-421C-B214-67038C9E10D3}: NameServer = 218.248.255.146,218.248.255.147
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL) - C:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (Client Connect LTD)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop Components:0 () - http://irda-exam.mod...a-modelexam.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O27 - HKLM IFEO\bitguard.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bprotect.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserdefender.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserprotect.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\dprotectsvc.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\jumpflip: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchinstaller.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotector.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings64.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\snapdo.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\umbrella.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\utiljumpflip.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\volaro: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\vonteera: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroids.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroidsservice.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/03/26 16:59:52 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2014/01/25 20:23:14 | 000,000,000 | ---- | M] () - E:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{1ee54543-6ed4-11e2-933e-f91138634fce}\Shell - "" = AutoRun
O33 - MountPoints2\{1ee54543-6ed4-11e2-933e-f91138634fce}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1ee54543-6ed4-11e2-933e-f91138634fce}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Common_Handset_USB_Driver.exe
O33 - MountPoints2\{958751c0-d52e-11e0-9086-fda07b0e6c8d}\Shell - "" = AutoRun
O33 - MountPoints2\{958751c0-d52e-11e0-9086-fda07b0e6c8d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{958751c0-d52e-11e0-9086-fda07b0e6c8d}\Shell\AutoRun\command - "" = H:\PhotoViewer.exe
O33 - MountPoints2\{e18ac740-6c1b-11e0-99e5-b8343b0fbca7}\Shell - "" = AutoRun
O33 - MountPoints2\{e18ac740-6c1b-11e0-99e5-b8343b0fbca7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e18ac740-6c1b-11e0-99e5-b8343b0fbca7}\Shell\AutoRun\command - "" = G:\LGAutoRun.exe
O33 - MountPoints2\{f4f26740-c45f-11e2-acca-81e184b502e5}\Shell - "" = AutoRun
O33 - MountPoints2\{f4f26740-c45f-11e2-acca-81e184b502e5}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f4f26740-c45f-11e2-acca-81e184b502e5}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: x64 - (c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll) -  File not found
O36 - AppCertDlls: x86 - (C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll) - C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/07/08 20:26:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2014/07/08 19:45:53 | 000,000,000 | ---D | C] -- C:\bluescreenview
[2014/07/08 19:33:46 | 001,057,176 | ---- | C] (Adobe) -- C:\install_flashplayer14x32_mssd_aaa_aih.exe
[2014/07/08 19:33:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\Adobe
[2014/07/08 19:27:40 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2014/07/08 19:20:36 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Rangasamy\Application Data\pcouffin.sys
[2014/07/08 19:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\Vso
[2014/07/08 19:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\My Documents\PcSetup
[2014/07/06 16:55:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\savevidmoviestoolbarha
[2014/07/06 16:54:37 | 000,000,000 | ---D | C] -- C:\Program Files\Movies Toolbar
[2014/07/06 16:54:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Datamngr
[2014/07/06 16:53:29 | 000,000,000 | ---D | C] -- C:\Program Files\Savevid
[2014/07/06 14:23:15 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Rangasamy\Recent
[2014/07/06 09:57:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Desktop\060714
[2014/07/06 07:06:38 | 000,035,640 | ---- | C] (AVG) -- C:\WINDOWS\System32\uxtuneup.dll
[2014/07/06 07:03:19 | 000,036,152 | ---- | C] (AVG) -- C:\WINDOWS\System32\TURegOpt.exe
[2014/07/06 07:02:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\AVG
[2014/07/06 07:02:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\AVG
[2014/07/06 07:00:09 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2014/07/06 06:59:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG
[2014/07/06 06:58:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2014/07/06 06:57:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\Youtube to MP3 Converter
[2014/07/06 06:56:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\SearchProtect
[2014/07/06 06:55:49 | 000,000,000 | ---D | C] -- C:\Program Files\SearchProtect
[2014/07/06 06:54:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\Youtube Downloader HD
[2014/07/06 06:54:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Youtube Downloader HD
[2014/07/06 06:54:45 | 000,000,000 | ---D | C] -- C:\Program Files\Youtube Downloader HD
[2014/07/04 21:50:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Desktop\0407
[2014/07/04 08:56:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Desktop\040714
[2014/07/03 10:56:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Desktop\M.S 3.714
[2014/07/01 15:19:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Desktop\DEVOTIONALSONG
[2014/06/28 12:27:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\dwhelper
[2014/06/26 18:34:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\AVG Secure Search
[2014/06/25 04:57:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Desktop\ARL
[2014/06/22 09:17:43 | 000,055,224 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}t.sys
[2014/06/18 10:13:55 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014/06/11 05:53:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013/12/06 07:06:55 | 000,089,088 | ---- | C] (keepvid.com Company) -- C:\Documents and Settings\Rangasamy\keepvid.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[1 C:\Documents and Settings\Rangasamy\*.tmp files -> C:\Documents and Settings\Rangasamy\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/07/08 20:47:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/07/08 20:46:28 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/07/08 20:46:28 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-343818398-412668190-299502267-1004.job
[2014/07/08 20:46:26 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-343818398-412668190-299502267-1003.job
[2014/07/08 20:46:26 | 000,000,230 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Logon.job
[2014/07/08 20:45:26 | 000,000,232 | -HS- | M] () -- C:\boot.ini
[2014/07/08 19:45:42 | 000,066,913 | ---- | M] () -- C:\bluescreenview.zip
[2014/07/08 19:33:06 | 001,057,176 | ---- | M] (Adobe) -- C:\install_flashplayer14x32_mssd_aaa_aih.exe
[2014/07/08 19:27:50 | 000,000,566 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2014/07/08 19:20:37 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\inst.exe
[2014/07/08 19:20:37 | 000,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\Rangasamy\Application Data\pcouffin.sys
[2014/07/08 19:20:37 | 000,007,887 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\pcouffin.cat
[2014/07/08 19:20:36 | 000,001,144 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\pcouffin.inf
[2014/07/08 18:53:00 | 000,000,432 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5F12E544-7916-45D9-AF3A-7D08947213CC}.job
[2014/07/08 18:45:52 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-343818398-412668190-299502267-1004.job
[2014/07/08 18:28:00 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-343818398-412668190-299502267-1004UA.job
[2014/07/08 16:27:14 | 000,000,224 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Windows XP End of Service Notification Monthly.job
[2014/07/08 10:44:57 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18UA.job
[2014/07/07 19:13:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/07/07 18:56:00 | 000,000,894 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/07/07 04:40:44 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/07/06 10:35:15 | 000,106,496 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/07/06 07:28:01 | 000,000,942 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-343818398-412668190-299502267-1004Core.job
[2014/07/06 07:03:11 | 000,001,757 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC TuneUp 2014.lnk
[2014/07/06 06:44:04 | 000,000,946 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-18Core.job
[2014/07/05 20:19:00 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2014/07/04 09:41:04 | 003,529,365 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Desktop\CSV_Utlization_by_101922_5765_03 Jul 2014.csv
[2014/06/28 09:15:25 | 000,001,127 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Desktop\IMG_20140628_071656.jpg.lnk
[2014/06/26 17:33:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2014/06/24 17:35:58 | 000,097,182 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Desktop\1962496_730346943675185_4746782230130653770_o.jpg
[2014/06/23 22:42:00 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-343818398-412668190-299502267-1003.job
[2014/06/23 11:47:45 | 000,042,784 | ---- | M] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys
[2014/06/21 07:37:12 | 000,000,038 | ---- | M] () -- C:\WINDOWS\AviSplitter.INI
[2014/06/20 16:59:50 | 000,055,224 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}t.sys
[2014/06/19 08:28:26 | 000,036,152 | ---- | M] (AVG) -- C:\WINDOWS\System32\TURegOpt.exe
[2014/06/19 08:28:18 | 000,035,640 | ---- | M] (AVG) -- C:\WINDOWS\System32\uxtuneup.dll
[2014/06/17 10:39:02 | 001,491,048 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Desktop\Rangaswamy June2014.JPG
[2014/06/17 06:11:58 | 000,001,063 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Desktop\CyberLink PowerDirector.lnk
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[1 C:\Documents and Settings\Rangasamy\*.tmp files -> C:\Documents and Settings\Rangasamy\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/07/08 19:45:36 | 000,066,913 | ---- | C] () -- C:\bluescreenview.zip
[2014/07/08 19:23:35 | 000,000,566 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2014/07/08 19:20:37 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Application Data\inst.exe
[2014/07/08 19:20:37 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Application Data\pcouffin.cat
[2014/07/08 19:20:36 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Application Data\pcouffin.inf
[2014/07/06 16:56:04 | 000,000,541 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Start Menu\Programs\Savevid.lnk
[2014/07/06 07:03:11 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC TuneUp 2014.lnk
[2014/07/04 09:40:54 | 003,529,365 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Desktop\CSV_Utlization_by_101922_5765_03 Jul 2014.csv
[2014/06/30 20:42:36 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-343818398-412668190-299502267-1004.job
[2014/06/30 05:00:37 | 1491,240,964 | ---- | C] () -- C:\Documents and Settings\Rangasamy\My Documents\MPEG2_Sep25_052854_0.mpg
[2014/06/28 11:59:07 | 114,278,404 | ---- | C] () -- C:\Documents and Settings\Rangasamy\My Documents\MPEG2_Dec13_061022_0.mpg
[2014/06/28 09:15:25 | 000,001,127 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Desktop\IMG_20140628_071656.jpg.lnk
[2014/06/24 17:35:57 | 000,097,182 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Desktop\1962496_730346943675185_4746782230130653770_o.jpg
[2014/06/17 10:38:55 | 001,491,048 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Desktop\Rangaswamy June2014.JPG
[2013/12/06 19:27:15 | 000,001,068 | RHS- | C] () -- C:\Documents and Settings\Rangasamy\ntuser.pol
[2013/12/06 07:07:31 | 000,258,783 | ---- | C] () -- C:\Documents and Settings\Rangasamy\main.dat
[2013/12/06 07:07:31 | 000,023,165 | ---- | C] () -- C:\Documents and Settings\Rangasamy\lastDev.dat
[2013/12/06 07:07:31 | 000,000,415 | ---- | C] () -- C:\Documents and Settings\Rangasamy\user.dat
[2013/12/06 07:07:31 | 000,000,295 | ---- | C] () -- C:\Documents and Settings\Rangasamy\lastUser.dat
[2013/12/06 07:06:53 | 000,087,502 | ---- | C] () -- C:\Documents and Settings\Rangasamy\helper.dat
[2013/12/06 07:06:53 | 000,035,009 | ---- | C] () -- C:\Documents and Settings\Rangasamy\keepvid.xpi
[2013/08/29 14:46:13 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2013/03/03 21:00:01 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\jesterss.dll
[2012/10/04 20:51:26 | 000,290,918 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/10/04 20:51:26 | 000,290,918 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-343818398-412668190-299502267-1004-0.dat
[2012/08/17 11:22:37 | 000,028,672 | R--- | C] () -- C:\WINDOWS\System32\VendorCmdRW.dll
[2012/08/17 11:22:33 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2012/08/06 23:59:29 | 000,106,496 | ---- | C] () -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/03 13:42:27 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
 
========== ZeroAccess Check ==========
 
[2011/03/26 17:03:50 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2010/09/09 17:25:17 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 13:56:36 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 15:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2014/07/08 20:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG
[2014/07/08 20:26:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2011/10/03 23:44:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2012/09/04 12:35:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2013/11/22 17:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Conduit
[2014/07/08 20:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Datamngr
[2011/08/07 13:01:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO
[2011/07/19 19:50:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2013/07/12 09:35:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Freemake
[2012/07/10 11:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2014/01/20 14:19:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IDM
[2011/11/29 13:10:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IM
[2011/11/29 13:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail
[2013/08/01 22:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\install_clap
[2013/11/10 20:24:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MyHeritage
[2011/08/27 15:59:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/03/30 23:10:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2011/06/19 20:51:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2012/08/16 22:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2012/09/26 12:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2013/12/08 17:34:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/10/04 13:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2014/07/06 06:59:04 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2013/11/23 16:54:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2013/11/23 16:54:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
[2013/11/22 18:17:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\AnvSoft
[2014/07/08 20:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\AVG
[2012/09/04 12:39:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\AVG Secure Search
[2013/07/12 09:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Babylon
[2014/01/20 14:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\DMCache
[2011/03/26 17:01:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Dream Aquarium
[2012/10/04 22:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\EurekaLog
[2014/04/17 14:38:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\IDM
[2013/11/10 20:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\MyHeritage
[2014/07/04 16:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Nitro PDF
[2014/07/06 06:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\OpenCandy
[2014/05/28 19:29:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\PriceGong
[2013/12/06 20:06:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Registry Mechanic
[2014/07/06 16:55:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\savevidmoviestoolbarha
[2013/12/01 13:45:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\SearchProtect
[2013/12/05 09:05:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Systweak
[2012/08/06 23:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\TeamViewer
[2012/09/26 12:49:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\TechSmith
[2012/08/16 22:20:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\TuneUpMedia
[2014/07/08 19:20:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Vso
[2014/07/06 06:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Youtube Downloader HD
[2014/07/06 06:57:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Youtube to MP3 Converter
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2013/09/30 04:14:20 | 098,466,785 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䐣甑噄6
[2013/09/30 04:14:20 | 098,466,785 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䐣甑噄6
[2013/09/29 20:30:29 | 098,463,575 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꖏ㋒噄6
[2013/09/29 20:30:29 | 098,463,575 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꖏ㋒噄6
[2013/09/28 22:18:45 | 098,442,955 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\눍룑噄6
[2013/09/28 22:18:45 | 098,442,955 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\눍룑噄6
[2013/09/28 04:17:49 | 098,372,650 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ﲖ木噄6
[2013/09/28 04:17:49 | 098,372,650 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ﲖ木噄6
[2013/09/27 17:20:13 | 098,201,609 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\죀룄噄6
[2013/09/27 17:20:13 | 098,201,609 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\죀룄噄6
[2013/09/26 16:50:42 | 097,927,968 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�噄6
[2013/09/26 16:50:42 | 097,927,968 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�噄6
[2013/09/26 09:43:23 | 097,892,804 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㔓仰噄6
[2013/09/26 09:43:23 | 097,892,804 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㔓仰噄6
[2013/09/25 14:23:08 | 097,673,008 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\♼噄6
[2013/09/25 14:23:08 | 097,673,008 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\♼噄6
[2013/09/24 20:14:10 | 097,531,747 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ᔝ噄6
[2013/09/24 20:14:10 | 097,531,747 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ᔝ噄6
[2013/09/24 14:11:46 | 098,852,061 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\딙噄6
[2013/09/24 14:11:46 | 098,852,061 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\딙噄6
[2013/09/24 07:11:29 | 098,840,431 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⒃⺗噄6
[2013/09/24 07:11:29 | 098,840,431 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⒃⺗噄6
[2013/09/24 03:52:14 | 098,798,431 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䑯噄6
[2013/09/24 03:52:14 | 098,798,431 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䑯噄6
[2013/09/23 17:02:46 | 098,646,441 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\鲍랺噄6
[2013/09/23 17:02:46 | 098,646,441 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\鲍랺噄6
[2013/09/23 10:59:40 | 098,615,159 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⊿浣噄6
[2013/09/23 10:59:40 | 098,615,159 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⊿浣噄6
[2013/09/22 17:12:14 | 098,586,517 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뫵蒮噄6
[2013/09/22 17:12:14 | 098,586,517 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뫵蒮噄6
[2013/09/22 04:39:11 | 098,547,399 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\Ƈ㺖噄6
[2013/09/22 04:39:11 | 098,547,399 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\Ƈ㺖噄6
[2013/09/21 15:20:03 | 098,533,909 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㈂鎬噄6
[2013/09/21 15:20:03 | 098,533,909 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㈂鎬噄6
[2013/09/20 17:45:04 | 098,474,815 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\꣜㝶噄6
[2013/09/20 17:45:04 | 098,474,815 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\꣜㝶噄6
[2013/09/19 22:07:09 | 098,378,485 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㼝�噄6
[2013/09/19 22:07:09 | 098,378,485 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㼝�噄6
[2013/09/19 04:40:36 | 098,201,083 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뀱郉噄6
[2013/09/19 04:40:36 | 098,201,083 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뀱郉噄6
[2013/09/18 10:40:38 | 098,106,403 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\쎣ⓧ噄6
[2013/09/18 10:40:38 | 098,106,403 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\쎣ⓧ噄6
[2013/09/17 21:39:28 | 097,949,955 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㯶噄6
[2013/09/17 21:39:28 | 097,949,955 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㯶噄6
[2013/09/16 18:15:08 | 097,787,879 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䫎渟噄6
[2013/09/16 18:15:08 | 097,787,879 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䫎渟噄6
[2013/09/16 04:49:29 | 097,671,483 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\蕄睶噄6
[2013/09/16 04:49:29 | 097,671,483 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\蕄睶噄6
[2013/09/15 11:58:16 | 097,600,188 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\襇ᝏ噄6
[2013/09/15 11:58:16 | 097,600,188 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\襇ᝏ噄6
[2013/09/14 16:44:04 | 097,542,592 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\꘍噄6
[2013/09/14 16:44:04 | 097,542,592 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\꘍噄6
[2013/09/13 17:13:04 | 097,463,612 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�ᦻ噄6
[2013/09/13 17:13:04 | 097,463,612 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�ᦻ噄6
[2013/09/13 11:11:01 | 097,443,711 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ᢟ噄6
[2013/09/13 11:11:01 | 097,443,711 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ᢟ噄6
[2013/09/12 04:43:47 | 097,181,529 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\똏ᱟ噄6
[2013/09/12 04:43:47 | 097,181,529 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\똏ᱟ噄6
[2013/09/11 22:44:10 | 097,170,353 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㑒ࣗ噄6
[2013/09/11 22:44:10 | 097,170,353 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㑒ࣗ噄6
[2013/09/11 04:14:05 | 097,021,647 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꪹ伖噄6
[2013/09/11 04:14:05 | 097,021,647 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꪹ伖噄6
[2013/09/10 17:55:07 | 096,922,344 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\骋噄6
[2013/09/10 17:55:07 | 096,922,344 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\骋噄6
[2013/09/10 11:54:57 | 096,910,367 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\땬埽噄6
[2013/09/10 11:54:57 | 096,910,367 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\땬埽噄6
[2013/09/10 05:34:48 | 096,851,172 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\肞戓噄6
[2013/09/10 05:34:48 | 096,851,172 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\肞戓噄6
[2013/09/09 15:43:15 | 096,601,965 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\앜斴噄6
[2013/09/09 15:43:15 | 096,601,965 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\앜斴噄6
[2013/09/09 03:42:54 | 096,566,691 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ᝡ噄6
[2013/09/09 03:42:54 | 096,566,691 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ᝡ噄6
[2013/09/08 15:43:15 | 096,555,248 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\턚⦳噄6
[2013/09/08 15:43:15 | 096,555,248 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\턚⦳噄6
[2013/09/08 03:02:56 | 096,533,415 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\捅Ŋ噄6
[2013/09/08 03:02:56 | 096,533,415 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\捅Ŋ噄6
[2013/09/07 20:10:33 | 096,511,910 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\셢鑱噄6
[2013/09/07 20:10:33 | 096,511,910 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\셢鑱噄6
[2013/09/07 04:40:55 | 096,496,803 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⩝횭噄6
[2013/09/07 04:40:55 | 096,496,803 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⩝횭噄6
[2013/09/05 05:34:53 | 095,956,132 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\穎슪噄6
[2013/09/05 05:34:53 | 095,956,132 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\穎슪噄6
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 267 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:661DFA1C
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9662AE0

< End of report >
 


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there what is your main antivirus is it AVG or Kaspersky ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]

:OTL
SRV - [2014/06/26 12:30:04 | 002,832,704 | ---- | M] (Client Connect LTD) [Auto | Stopped] -- C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe -- (CltMngSvc)
SRV - [2014/04/27 21:39:56 | 003,544,064 | ---- | M] (Bandoo Media Inc.) [Auto | Stopped] -- C:\Program Files\Movies Toolbar\Datamngr\DatamngrCoordinator.exe -- (DatamngrCoordinator)
SRV - [2014/02/05 14:34:51 | 000,796,152 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Savevid\SavevidService.exe -- (SavevidService)
DRV - [2014/06/20 16:59:50 | 000,055,224 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}t.sys -- ({1a147621-8c9a-4d6b-a557-6513a40d3207}t)
DRV - [2014/04/27 21:39:56 | 000,031,096 | ---- | M] (Bandoo Media Inc.) [Kernel | System | Stopped] -- C:\Program Files\Movies Toolbar\Datamngr\setmgrc1.cfg -- (F06DEFF2-5B9C-490D-910F-35D3A9119622)
DRV - [2014/04/24 12:30:34 | 000,055,224 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}Gt.sys -- ({1a147621-8c9a-4d6b-a557-6513a40d3207}Gt)
IE - HKLM\..\SearchScopes\{194de045-cc5e-4840-b031-1ca9db98919d}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{3d29c02b-bf3e-4d3b-8a7a-e0e7d0f6dbab}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}: "URL" = http://dts.search.as...q={searchTerms}
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweeti...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...73C4F4C2A&SSPV=
IE - HKCU\..\URLSearchHook: {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-se...121563&tsp=4941
IE - HKCU\..\SearchScopes\{1A8C80AB-6C1A-4B10-A8CF-9EB3B3084D8F}: "URL" = http://www.mysearchr...q={searchTerms}
IE - HKCU\..\SearchScopes\{3d29c02b-bf3e-4d3b-8a7a-e0e7d0f6dbab}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKCU\..\SearchScopes\{498D228A-C32C-4D5D-8424-7520FFBD02B1}: "URL" = http://search.condui...5942085711&UM=2
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}: "URL" = http://dts.search.as...q={searchTerms}
FF - prefs.js..CT2269050.browser.search.defaultthis.engineName: true
FF - prefs.js..extensions.enabledAddons: 5qffxtbr%40Zwinky_5q.com:6.52.4.8852
FF - prefs.js..extensions.enabledAddons: keepvid.com%40helper.com:2.0.0.0
FF - prefs.js..keyword.URL: "http://dts.search.as...&o=APN10647&q="
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\Rangasamy\keepvid.xpi [2013/12/11 19:10:04 | 000,035,009 | ---- | M] ()
[2014/06/10 10:56:08 | 000,000,000 | ---D | M] (Zwinky) -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\extensions\[email protected]_5q.com
[2013/07/12 09:06:16 | 000,006,507 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\babylon.xml
[2013/07/12 09:06:39 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\delta.xml
[2013/12/06 20:51:21 | 000,001,084 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\dvdvideosofttb-customized-web-search.xml
[2013/03/12 12:02:20 | 000,009,615 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\my-web-search.xml
[2014/07/07 18:49:31 | 000,000,643 | ---- | M] () -- C:\Documents and Settings\Rangasamy\Application Data\Mozilla\Firefox\Profiles\livpnmpt.default\searchplugins\trovi-search.xml
O2 - BHO: (keepvid.com) - {49ed9900-38cd-453c-bba7-3f2613317f5a} - C:\Documents and Settings\Rangasamy\keepvid.dll (keepvid.com Company)
O2 - BHO: (no name) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No CLSID value found.
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Rangasamy\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll File not found
O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O2 - BHO: (Movies Toolbar (Dist. by Bandoo Media, Inc.)) - {95bef0b1-9d3a-41f3-bb8b-8275aaa48c66} - C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll ()
O2 - BHO: (SoundFrost) - {d997c836-ff82-4519-b459-1482ba942a4f} - C:\Program Files\keepvid\SoundFrost.dll (SoundFrost Company)
O2 - BHO: (no name) - {E33CF602-D945-461A-83F0-819F76A199F8} - No CLSID value found.
O2 - BHO: (entrusted Toolbar) - {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Movies Toolbar (Dist. by Bandoo Media, Inc.)) - {95bef0b1-9d3a-41f3-bb8b-8275aaa48c66} - C:\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\IE\searchresultsDx.dll ()
O3 - HKLM\..\Toolbar: (entrusted Toolbar) - {e44a1809-4d10-4ab8-b343-3326b64c7cdd} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (entrusted Toolbar) - {E44A1809-4D10-4AB8-B343-3326B64C7CDD} - C:\Program Files\entrusted\prxtbent1.dll (Conduit Ltd.)
O3:HKU - HKCU\..\Toolbar\WebBrowser: (entrusted Toolbar) - {E44A1809-4D10-4AB8-B343-3326B64C7CDD} - C:\Documents and Settings\Rangasamy\Local Settings\Application Data\entrusted\prxtbent0.dll (ClientConnect Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O20 - AppInit_DLLs: (C:\PROGRA~1\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL) - C:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (Client Connect LTD)
O27 - HKLM IFEO\bitguard.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bprotect.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserdefender.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserprotect.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\dprotectsvc.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\jumpflip: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchinstaller.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotector.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings64.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\snapdo.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\umbrella.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\utiljumpflip.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\volaro: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\vonteera: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroids.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroidsservice.exe: Debugger - C:\WINDOWS\System32\tasklist.exe (Microsoft Corporation)
O36 - AppCertDlls: x64 - (c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll) -  File not found
O36 - AppCertDlls: x86 - (C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll) - C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll ()
[2014/07/08 19:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\Vso
[2014/07/08 19:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\My Documents\PcSetup
[2014/07/06 16:55:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\savevidmoviestoolbarha
[2014/07/06 16:54:37 | 000,000,000 | ---D | C] -- C:\Program Files\Movies Toolbar
[2014/07/06 16:54:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Datamngr
[2014/07/06 16:53:29 | 000,000,000 | ---D | C] -- C:\Program Files\Savevid
[2014/07/06 06:56:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Local Settings\Application Data\SearchProtect
[2014/07/06 06:55:49 | 000,000,000 | ---D | C] -- C:\Program Files\SearchProtect
[2014/07/06 06:54:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rangasamy\Application Data\Youtube Downloader HD
[2014/07/06 06:54:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Youtube Downloader HD
[2014/07/06 06:54:45 | 000,000,000 | ---D | C] -- C:\Program Files\Youtube Downloader HD
[2014/06/22 09:17:43 | 000,055,224 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}t.sys
[2013/12/06 07:06:55 | 000,089,088 | ---- | C] (keepvid.com Company) -- C:\Documents and Settings\Rangasamy\keepvid.dll
[2014/06/20 16:59:50 | 000,055,224 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{1a147621-8c9a-4d6b-a557-6513a40d3207}t.sys
[2013/12/06 07:06:53 | 000,087,502 | ---- | C] () -- C:\Documents and Settings\Rangasamy\helper.dat
[2013/12/06 07:06:53 | 000,035,009 | ---- | C] () -- C:\Documents and Settings\Rangasamy\keepvid.xpi
[2011/10/03 23:44:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2013/11/22 17:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Conduit
[2014/07/08 20:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Datamngr
[2011/08/07 13:01:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO
[2013/07/12 09:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Babylon
[2014/07/06 06:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\OpenCandy
[2014/05/28 19:29:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\PriceGong
[2014/07/06 16:55:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\savevidmoviestoolbarha
[2013/12/01 13:45:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\SearchProtect
[2013/12/05 09:05:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Systweak
[2014/07/06 06:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rangasamy\Application Data\Youtube Downloader HD

:Files
C:\Program Files\Movies Toolbar
C:\Program Files\SearchProtect
C:\Program Files\Savevid
C:\Program Files\entrusted

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

  • 0

#3
pissupoosa

pissupoosa

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Thanks for your reply. As my system even failed to wake up on safe mode, I had no other option then format. Formated it, and this is working well now. Thanks for your time.


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
No problem
  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics


Also tagged with one or more of these keywords: OTL

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP