This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Files mysteriously disappearing from external drive? help

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all

Glad I found this forum. Hoping one of you uber smart people can help me figure out wtf is going on in my computer. Long story short: I have a Seagate external drive hooked up. I back all my data up to it. The other day I accessed it and to my shock ALL FILES were gone. Poof. We're talking thousands of files. Weird though, the folder structure/tree was still completely in tact!! Every folder is there, it's just the files that are gone. I used Recuva This and got about 60% of it back. The other 40% is gone forever I guess. Very sad as there were about 500 family images that we lost.

Anyway, I add more files to this drive about three days ago to test. Sure enough they TOO are gone now but their folders are still there! Ugh! Important to note these files are NOT going to the recycle bin for some reason. They are just being zapped from the drive somehow.

SOMETHING/SOMEONE is making my files disappear. This drive is NOT being shared on the network. I ran scan disk and no errors were found. Here is my HT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:33:07 PM, on 1/31/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\LivePerson\Expert\LPExpertMessenger.exe
C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\RunServices: [Nod42 Service] nod143.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: LivePerson Expert Messenger.lnk = C:\Program Files (x86)\LivePerson\Expert\LPExpertMessenger.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD RAIDXpert (AMD_RAIDXpert) - AMD - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: B-Service - Unknown owner - C:\Users\bolero\AppData\Roaming\Mikogo\B-Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Easy Backup Button Service (HPBtnSrv) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11553 bytes\
Hello fringelunatic,

Welcome to WTT.

I am thinking that this may not be a malware problem but then again it might!

  • Please download OTL to your Desktop
  • Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and paste them into your reply.

Note: Unless otherwise instructed always post the logs in the forum. If reports don't fit on one post. It might be necessary to break the logs up to get them on the forum. Just use as many posts as you need, that's fine. :)
Thanks for your help. I did as you asked. Here is the report. What are you looking for?

OTL logfile created on: 2/2/2010 3:29:19 PM - Run 2
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\bolero\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 78.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 685.05 Gb Total Space | 518.09 Gb Free Space | 75.63% Space Free | Partition Type: NTFS
Drive D: | 13.44 Gb Total Space | 1.84 Gb Free Space | 13.69% Space Free | Partition Type: NTFS
Drive K: | 698.64 Gb Total Space | 696.04 Gb Free Space | 99.63% Space Free | Partition Type: NTFS <—— PS: this is the problem drive
Drive L: | 232.88 Gb Total Space | 95.67 Gb Free Space | 41.08% Space Free | Partition Type: NTFS

Computer Name: BOLERO-MAIN
Current User Name: bolero
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/02/02 15:23:46 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Users\bolero\Downloads\OTL.exe
PRC - [2010/01/28 14:09:31 | 002,757,512 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/01/15 19:09:37 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/12/10 19:18:26 | 000,045,056 | —- | M] (Intuit) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (QuickBooks)
PRC - [2009/11/05 12:20:04 | 000,136,176 | —- | M] (Google Inc.) – C:\Users\bolero\AppData\Local\Google\Update\1.2.183.13\GoogleCrashHandler.exe
PRC - [2009/08/28 19:42:54 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/01/28 14:35:12 | 007,013,376 | —- | M] (LivePerson Inc.) – C:\Program Files (x86)\LivePerson\Expert\LPExpertMessenger.exe
PRC - [2007/07/19 17:54:48 | 000,689,408 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
PRC - [2007/07/19 17:54:40 | 000,656,640 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe


========== Modules (SafeList) ==========

MOD - [2010/02/02 15:23:46 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Users\bolero\Downloads\OTL.exe
MOD - [2009/07/13 17:15:07 | 000,486,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009/07/13 17:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV:64bit: - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV:64bit: - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2009/10/28 20:21:28 | 000,660,256 | —- | M] (Apple Inc.) [On_Demand | Running] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV:64bit: - [2009/07/13 17:41:59 | 000,229,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wwansvc.dll – (WwanSvc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,202,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbiosrvc.dll – (WbioSrvc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,163,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpo.dll – (Power)
SRV:64bit: - [2009/07/13 17:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2009/07/13 17:41:54 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sppuinotify.dll – (sppuinotify)
SRV:64bit: - [2009/07/13 17:41:54 | 000,029,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sensrsvc.dll – (SensrSvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpsvc.dll – (PNRPsvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpsvc.dll – (p2pimsvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,187,904 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\provsvc.dll – (HomeGroupProvider)
SRV:64bit: - [2009/07/13 17:41:53 | 000,067,072 | —- | M] (Microsoft Corporation) [Unknown | Running] – C:\Windows\SysNative\RpcEpMap.dll – (RpcEptMapper)
SRV:64bit: - [2009/07/13 17:41:53 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpauto.dll – (PNRPAutoReg)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 17:41:18 | 000,231,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\ListSvc.dll – (HomeGroupListener)
SRV:64bit: - [2009/07/13 17:40:54 | 001,127,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FntCache.dll – (FontCache)
SRV:64bit: - [2009/07/13 17:40:28 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2009/07/13 17:40:28 | 000,291,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\defragsvc.dll – (defragsvc)
SRV:64bit: - [2009/07/13 17:40:13 | 000,083,968 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\bthserv.dll – (bthserv)
SRV:64bit: - [2009/07/13 17:40:10 | 000,100,864 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\bdesvc.dll – (BDESVC)
SRV:64bit: - [2009/07/13 17:40:05 | 000,114,688 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AxInstSv.dll – (AxInstSV)
SRV:64bit: - [2009/07/13 17:40:01 | 000,032,256 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appidsvc.dll – (AppIDSvc)
SRV:64bit: - [2009/07/13 17:39:51 | 001,503,744 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbengine.exe – (wbengine)
SRV:64bit: - [2009/07/13 17:39:28 | 003,524,608 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\sppsvc.exe – (sppsvc)
SRV:64bit: - [2009/07/13 17:39:11 | 000,689,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FXSSVC.exe – (Fax)
SRV:64bit: - [2009/04/07 12:49:46 | 001,038,088 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64)
SRV - [2009/12/16 12:07:51 | 000,185,640 | —- | M] () [On_Demand | Stopped] – C:\Users\bolero\AppData\Roaming\Mikogo\B-Service.exe – (B-Service)
SRV - [2009/12/10 19:18:26 | 000,045,056 | —- | M] (Intuit) [Auto | Running] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2009/09/21 02:31:17 | 001,028,432 | —- | M] (Lavasoft) [Auto | Stopped] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/08/28 19:42:54 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/07/13 19:20:14 | 000,000,000 | —D | M] [On_Demand | Stopped] – C:\Windows\Vss – (VSS)
SRV - [2009/07/13 19:20:14 | 000,000,000 | —D | M] [Unknown | Stopped] – C:\Windows\SysWOW64\Msdtc – (MSDTC)
SRV - [2009/07/13 17:16:12 | 000,165,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\provsvc.dll – (HomeGroupProvider)
SRV - [2009/07/13 17:15:11 | 000,253,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV - [2009/07/13 12:30:11 | 000,061,056 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2009/06/10 12:39:58 | 000,089,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2009/04/07 12:44:53 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/12/05 15:11:54 | 000,935,208 | —- | M] (Nero AG) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2008/09/30 18:59:26 | 000,192,512 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe – (HPBtnSrv)
SRV - [2008/09/04 04:21:50 | 000,122,880 | —- | M] (AMD) [On_Demand | Stopped] – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe – (AMD_RAIDXpert)
SRV - [2008/08/15 04:46:20 | 000,284,016 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe – (Adobe Version Cue CS4)
SRV - [2008/08/08 21:10:46 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2007/07/19 17:54:48 | 000,689,408 | —- | M] (American Power Conversion Corporation) [Auto | Running] – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe – (APC UPS Service)
SRV - [2006/10/27 00:47:54 | 000,065,824 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service)
SRV - [2004/10/22 03:24:18 | 000,073,728 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.5.0
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105


FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/01/21 21:34:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/01/21 21:31:31 | 000,000,000 | —D | M]

[2009/11/15 17:49:12 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mozilla\Extensions
[2010/02/01 19:19:08 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions
[2010/01/30 00:08:31 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/15 17:49:19 | 000,000,000 | —D | M] (Web Developer) – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/30 20:46:01 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions\[removed]
[2009/11/15 17:27:59 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 13:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (IE Developer Toolbar BHO) - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - Startup: C:\Users\bolero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LivePerson Expert Messenger.lnk = C:\Program Files (x86)\LivePerson\Expert\LPExpertMessenger.exe (LivePerson Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{39be0bc3-0ad3-11df-a913-00242115fa88}\Shell - "" = AutoRun
O33 - MountPoints2\{39be0bc3-0ad3-11df-a913-00242115fa88}\Shell\AutoRun\command - "" = M:\WD SmartWare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
64bit: O35 - comfile [open] – "%1" %* File not found
64bit: O35 - exefile [open] – "%1" %* File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2009/07/13 19:20:14 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:64bit: Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:64bit: BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 19:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/02/01 23:13:24 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/02/01 09:43:20 | 000,000,000 | —D | C] – C:\ProgramData\Sony
[2010/02/01 09:43:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2010/02/01 08:24:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/02/01 08:20:02 | 000,000,000 | —D | C] – C:\Users\bolero\Desktop\backups from reg
[2010/01/31 23:52:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinDirStat
[2010/01/31 23:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\WhatsRunning
[2010/01/31 20:09:07 | 000,022,096 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/01/31 20:09:06 | 000,120,912 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/01/31 20:09:05 | 000,028,752 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/01/31 20:09:03 | 000,051,280 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/01/31 20:09:00 | 000,063,568 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/01/31 20:07:23 | 000,152,672 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/01/31 20:07:23 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/01/31 20:07:21 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/01/31 20:07:21 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/01/31 19:26:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Seagate
[2010/01/31 18:34:27 | 000,000,000 | —D | C] – C:\ProgramData\Hitman Pro
[2010/01/31 16:07:19 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\MigWiz
[2010/01/31 15:33:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/01/31 14:55:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrendMicro
[2010/01/31 14:16:33 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Malwarebytes
[2010/01/31 14:16:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/01/31 14:16:28 | 000,022,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/01/31 14:16:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/01/31 14:16:28 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/01/31 13:34:23 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\TrueCrypt
[2010/01/31 13:34:13 | 000,000,000 | —D | C] – C:\ProgramData\TrueCrypt
[2010/01/31 13:34:11 | 000,222,160 | —- | C] (TrueCrypt Foundation) – C:\Windows\SysWow64\drivers\truecrypt.sys
[2010/01/31 13:34:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrueCrypt
[2010/01/30 20:38:49 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/01/30 20:37:11 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2010/01/30 20:11:41 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\WinBatch
[2010/01/30 19:01:36 | 000,000,000 | —D | C] – C:\Users\bolero\Documents\My Adobe Captivate Projects
[2010/01/30 19:00:51 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\adobe.captivate.swfcomment.AdobeCaptivateReviewer.4875E02D9FB21EE389F73B8D1
702B320485DF8CE.1
[2010/01/30 17:25:04 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Western Digital
[2010/01/30 17:24:54 | 000,000,000 | —D | C] – C:\ProgramData\Western Digital
[2010/01/30 17:23:52 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\Western Digital
[2010/01/30 01:58:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Citrix
[2010/01/30 00:08:27 | 000,000,000 | —D | C] – C:\Program Files\Recuva
[2010/01/29 23:39:17 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/01/29 23:38:58 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\SUPERAntiSpyware.com
[2010/01/29 23:38:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\SUPERAntiSpyware
[2010/01/29 17:12:27 | 004,194,304 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\Windows\SysWow64\cdintf400.dll
[2010/01/28 16:56:58 | 000,000,000 | —D | C] – C:\Users\bolero\Documents\TurboTax
[2010/01/28 16:56:41 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Intuit
[2010/01/28 16:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AnswerWorks 5.0
[2010/01/28 16:52:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\TurboTax
[2010/01/27 11:11:31 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\mIRC
[2010/01/27 11:11:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\mIRC
[2010/01/22 21:30:57 | 000,000,000 | —D | C] – C:\ProgramData\{E7D4E1BB-A8A8-4E3B-BEA6-38DD8E4522DF}
[2010/01/22 21:26:20 | 000,000,000 | —D | C] – C:\ProgramData\{4275E5EA-6E30-48EB-A209-F964539CBE1C}
[2010/01/21 21:47:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASIO4ALL v2
[2010/01/21 18:32:20 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Publish Providers
[2010/01/21 18:25:33 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\Sony
[2010/01/21 18:22:39 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Sony
[2010/01/20 22:19:28 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\DeskShare
[2010/01/20 22:13:58 | 000,000,000 | —D | C] – C:\ProgramData\Deskshare
[2010/01/20 22:13:56 | 000,000,000 | —D | C] – C:\Windows\XSxS
[2010/01/20 22:13:56 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\Xenocode
[2010/01/20 22:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xenocode
[2010/01/20 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DeskShare Shared
[2010/01/20 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Deskshare
[2010/01/19 22:09:02 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/01/19 21:34:55 | 000,356,352 | —- | C] (eSellerate Inc.) – C:\Windows\eSellerateEngine.dll

========== Files - Modified Within 14 Days ==========

[2010/02/02 15:29:12 | 005,242,880 | -HS- | M] () – C:\Users\bolero\NTUSER.DAT
[2010/02/02 15:25:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2327562318-2441480392-3380623591-1000UA.job
[2010/02/02 12:34:42 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2327562318-2441480392-3380623591-1000Core.job
[2010/02/01 22:45:27 | 000,009,504 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/01 22:45:26 | 000,009,504 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/01 21:56:00 | 000,774,192 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/02/01 21:56:00 | 000,656,430 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/02/01 21:56:00 | 000,120,262 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/02/01 15:59:49 | 000,047,973 | —- | M] () – C:\Users\bolero\Desktop\rockband_creator.jpg
[2010/02/01 15:44:39 | 000,046,971 | —- | M] () – C:\Users\bolero\Desktop\slash_guitar_contest.jpg
[2010/02/01 09:55:44 | 294,489,930 | —- | M] () – C:\Users\bolero\Desktop\backup3.reg
[2010/02/01 09:52:53 | 000,000,162 | -H– | M] () – C:\Users\bolero\Desktop\~$ackup2.reg
[2010/02/01 09:45:51 | 000,002,584 | —- | M] () – C:\Users\bolero\Desktop\Register Sound Forge Pro.htm
[2010/02/01 08:44:12 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/02/01 08:44:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/02/01 08:43:54 | 2141,249,535 | -HS- | M] () – C:\hiberfil.sys
[2010/02/01 08:42:33 | 004,569,368 | -H– | M] () – C:\Users\bolero\AppData\Local\IconCache.db
[2010/02/01 08:38:43 | 000,422,428 | —- | M] () – C:\Users\bolero\Desktop\cc_20100201_083754.reg
[2010/02/01 08:37:45 | 295,682,646 | —- | M] () – C:\Users\bolero\Desktop\backup2.reg
[2010/02/01 08:24:05 | 000,001,891 | —- | M] () – C:\Users\bolero\Desktop\CCleaner.lnk
[2010/02/01 08:19:47 | 296,032,750 | —- | M] () – C:\Users\bolero\Desktop\backup.reg
[2010/02/01 03:31:03 | 000,000,496 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/01/31 23:52:47 | 000,001,037 | —- | M] () – C:\Users\bolero\Desktop\WinDirStat.lnk
[2010/01/31 23:20:59 | 000,000,989 | —- | M] () – C:\Users\bolero\Desktop\What's Running.lnk
[2010/01/31 20:14:52 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/01/31 19:41:34 | 000,019,016 | —- | M] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2010/01/31 14:16:32 | 000,001,015 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/31 13:34:13 | 000,001,064 | —- | M] () – C:\Users\Public\Desktop\TrueCrypt.lnk
[2010/01/31 13:34:11 | 000,222,160 | —- | M] (TrueCrypt Foundation) – C:\Windows\SysWow64\drivers\truecrypt.sys
[2010/01/31 12:32:25 | 000,042,645 | —- | M] () – C:\Users\bolero\Desktop\Newegg.pdf
[2010/01/29 17:12:28 | 000,000,090 | —- | M] () – C:\Windows\QBChanUtil_Trigger.ini
[2010/01/28 14:09:26 | 000,152,672 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/01/28 13:57:59 | 000,051,280 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/01/28 13:57:40 | 000,120,912 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/01/28 13:54:45 | 000,028,752 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/01/28 13:54:30 | 000,063,568 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/01/28 13:54:07 | 000,022,096 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys\
[2010/01/20 22:57:47 | 000,007,168 | —- | M] () – C:\Users\bolero\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/19 22:42:32 | 000,000,230 | —- | M] () – C:\Windows\ctrunonce.reg
[2010/01/19 21:34:55 | 000,356,352 | —- | M] (eSellerate Inc.) – C:\Windows\eSellerateEngine.dll

========== Files Created - No Company Name ==========

[2010/02/01 09:55:21 | 294,489,930 | —- | C] () – C:\Users\bolero\Desktop\backup3.reg
[2010/02/01 09:52:53 | 000,000,162 | -H– | C] () – C:\Users\bolero\Desktop\~$ackup2.reg
[2010/02/01 09:45:51 | 000,002,584 | —- | C] () – C:\Users\bolero\Desktop\Register Sound Forge Pro.htm
[2010/02/01 08:38:04 | 000,422,428 | —- | C] () – C:\Users\bolero\Desktop\cc_20100201_083754.reg
[2010/02/01 08:37:21 | 295,682,646 | —- | C] () – C:\Users\bolero\Desktop\backup2.reg
[2010/02/01 08:24:05 | 000,001,891 | —- | C] () – C:\Users\bolero\Desktop\CCleaner.lnk
[2010/02/01 08:19:23 | 296,032,750 | —- | C] () – C:\Users\bolero\Desktop\backup.reg
[2010/01/31 23:52:47 | 000,001,037 | —- | C] () – C:\Users\bolero\Desktop\WinDirStat.lnk
[2010/01/31 23:20:59 | 000,000,989 | —- | C] () – C:\Users\bolero\Desktop\What's Running.lnk
[2010/01/31 20:09:00 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2010/01/31 18:34:36 | 000,019,016 | —- | C] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2010/01/31 14:16:32 | 000,001,015 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/31 13:34:13 | 000,001,064 | —- | C] () – C:\Users\Public\Desktop\TrueCrypt.lnk
[2010/01/31 12:32:25 | 000,042,645 | —- | C] () – C:\Users\bolero\Desktop\Newegg.pdf
[2010/01/24 14:43:00 | 001,984,512 | —- | C] () – C:\Users\Public\Documents\cm_vol2_print_061009.doc
[2010/01/19 22:42:32 | 000,000,230 | —- | C] () – C:\Windows\ctrunonce.reg
[2010/01/18 21:27:05 | 000,007,168 | —- | C] () – C:\Users\bolero\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/29 13:38:58 | 000,002,319 | R— | C] () – C:\Windows\SysWow64\emaud.ini
[2009/12/29 13:38:58 | 000,000,035 | R— | C] () – C:\Windows\SysWow64\ctzapxx.ini
[2009/12/11 22:44:15 | 000,001,511 | —- | C] () – C:\Windows\Concordance.Ini
[2009/11/15 17:03:51 | 000,743,126 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\SysWow64\OGACheckControl.DLL
[2009/07/13 15:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 13:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/27 14:22:30 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/04/03 12:18:50 | 001,073,152 | —- | C] () – C:\Windows\SysWow64\libmysql_c.dll
[2009/03/29 14:38:34 | 000,000,524 | —- | C] () – C:\Windows\pear.ini
[2009/03/24 20:48:14 | 000,000,481 | —- | C] () – C:\Windows\my.ini
[2009/03/03 09:47:31 | 000,000,090 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2009/03/02 21:01:46 | 002,463,976 | —- | C] () – C:\Windows\SysWow64\NPSWF32.dll
[2008/11/19 20:45:01 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/11/19 20:45:01 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/09/19 03:59:22 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\libxml2.dll

========== LOP Check ==========

[2009/11/15 17:47:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Ableton
[2009/11/15 17:48:00 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Ambient Design
[2009/11/15 17:48:00 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Aptana
[2010/02/01 08:54:44 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\BPFTP
[2009/11/18 11:22:37 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\CopyTrans
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Dev-Cpp
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\FileZilla
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Forte
[2009/11/15 17:49:12 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mikogo
[2009/07/06 10:19:22 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\PACE Anti-Piracy
[2010/01/29 21:10:09 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Propellerhead Software
[2010/01/21 18:32:20 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Publish Providers
[2009/11/18 12:09:47 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\SharePod
[2010/01/22 14:15:32 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Sony
[2009/11/15 17:49:20 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\SystemRequirementsLab
[2010/01/31 14:32:25 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\TrueCrypt
[2009/11/15 17:49:20 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2010/01/30 02:35:33 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\webex
[2010/01/31 12:33:38 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Western Digital
[2010/01/30 20:11:41 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\WinBatch
[2009/11/18 11:19:57 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\WindSolutions
[2010/02/01 03:31:03 | 000,000,496 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/13 21:08:49 | 000,013,152 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 17:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 17:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 17:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 17:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 17:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 17:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 17:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 17:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/13 17:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 17:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 17:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 17:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 17:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 17:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 17:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 17:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 17:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 17:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 17:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 17:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:C119EC96
@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:24051EFF
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:63238B95
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:901E30B2
< End of report >

What are you looking for?


Anything that might be causing the problem. :)

Now

Please run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
    O33 - MountPoints2\{39be0bc3-0ad3-11df-a913-00242115fa88}\Shell - "" = AutoRun
    O33 - MountPoints2\{39be0bc3-0ad3-11df-a913-00242115fa88}\Shell\AutoRun\command - "" = M:\WD SmartWare.exe – File not found
    
    :Commands
    [emptytemp]
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • It will produce a log for you on reboot, please post that log in your next reply.
After that

It is a pretty big download but is very useful at detecting\cleaning rootkits or whatever it finds.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop
  • Double click the setup file to run it
  • Accept the agreement
  • A pop up window will appear.
  • On the Autoscan panel check all items
  • Click on Start Scan
  • When finished (this can take some time… just be patient and let it do its job) click the Report button
  • Click the + button left top to expand the critical events
  • Highlight Ctrl A and copy Ctrl C
  • Save to Notepad Ctrl V
Copy and past the report back here.

Click exit to uninstall Kaspersky AVP. Click yes to the prompts to complete the process.

Note: This tool will self uninstall when you click Exit so please save the log before closing it.

Here is the log file after the reboot. Downloading Kaperksy now. Thanks so much for all your help! All processes killed ========== OTL ========== Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{39be0bc3-0ad3-11df-a913-00242115fa88}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39be0bc3-0ad3-11df-a913-00242115fa88}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{39be0bc3-0ad3-11df-a913-00242115fa88}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39be0bc3-0ad3-11df-a913-00242115fa88}\ not found. File M:\WD SmartWare.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: bolero ->Temp folder emptied: 84067011 bytes ->Temporary Internet Files folder emptied: 592313502 bytes ->Java cache emptied: 9803378 bytes ->FireFox cache emptied: 130367201 bytes ->Google Chrome cache emptied: 12408110 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 65072 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67630 bytes RecycleBin emptied: 5335650116 bytes Total Files Cleaned = 5,879.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.1.27.1 log created on 02022010_175347 Files\Folders moved on Reboot… C:\Users\bolero\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot…
Hello fringelunatic,

Hmm… let's have another look. This time we will add in a couple more things to look at. But before that do this:

Make sure that external drive is plugged in an turned on.

Download Flash_Disinfector.exe by sUBs from here and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you run it. Don't delete this folder…it will help protect your drives from future infection.

After that

Run OTL again.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • It will produce a log for you. Post the log here.
Yes that was a possibility with a 64 bit machine. Try right clicking on it and running it as Administrator. If that doesn't work move on to the OTL
Doesn't work running as admin either.

Here is OTL log:

OTL logfile created on: 2/2/2010 11:29:27 PM - Run 3
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\bolero\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 685.05 Gb Total Space | 517.12 Gb Free Space | 75.49% Space Free | Partition Type: NTFS
Drive D: | 13.44 Gb Total Space | 1.84 Gb Free Space | 13.69% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 144.43 Gb Free Space | 62.02% Space Free | Partition Type: NTFS
Drive K: | 698.64 Gb Total Space | 696.04 Gb Free Space | 99.63% Space Free | Partition Type: NTFS

Computer Name: BOLERO-MAIN
Current User Name: bolero
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/02/02 15:23:46 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Users\bolero\Downloads\OTL.exe
PRC - [2010/01/28 14:09:31 | 002,757,512 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/01/15 19:09:37 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/12/10 19:18:26 | 000,045,056 | —- | M] (Intuit) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2009/08/28 19:42:54 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/01/28 14:35:12 | 007,013,376 | —- | M] (LivePerson Inc.) – C:\Program Files (x86)\LivePerson\Expert\LPExpertMessenger.exe
PRC - [2007/07/19 17:54:48 | 000,689,408 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe
PRC - [2007/07/19 17:54:40 | 000,656,640 | —- | M] (American Power Conversion Corporation) – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\apcsystray.exe


========== Modules (SafeList) ==========

MOD - [2010/02/02 15:23:46 | 000,548,864 | —- | M] (OldTimer Tools) – C:\Users\bolero\Downloads\OTL.exe
MOD - [2009/07/13 17:15:07 | 000,486,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009/07/13 17:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV:64bit: - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV:64bit: - [2010/01/28 14:09:28 | 000,040,384 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2009/10/28 20:21:28 | 000,660,256 | —- | M] (Apple Inc.) [On_Demand | Stopped] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV:64bit: - [2009/07/13 17:41:59 | 000,229,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wwansvc.dll – (WwanSvc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,202,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbiosrvc.dll – (WbioSrvc)
SRV:64bit: - [2009/07/13 17:41:56 | 000,163,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpo.dll – (Power)
SRV:64bit: - [2009/07/13 17:41:55 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2009/07/13 17:41:54 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sppuinotify.dll – (sppuinotify)
SRV:64bit: - [2009/07/13 17:41:54 | 000,029,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sensrsvc.dll – (SensrSvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpsvc.dll – (PNRPsvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpsvc.dll – (p2pimsvc)
SRV:64bit: - [2009/07/13 17:41:53 | 000,187,904 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\provsvc.dll – (HomeGroupProvider)
SRV:64bit: - [2009/07/13 17:41:53 | 000,067,072 | —- | M] (Microsoft Corporation) [Unknown | Running] – C:\Windows\SysNative\RpcEpMap.dll – (RpcEptMapper)
SRV:64bit: - [2009/07/13 17:41:53 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpauto.dll – (PNRPAutoReg)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 17:41:18 | 000,231,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\ListSvc.dll – (HomeGroupListener)
SRV:64bit: - [2009/07/13 17:40:54 | 001,127,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FntCache.dll – (FontCache)
SRV:64bit: - [2009/07/13 17:40:28 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2009/07/13 17:40:28 | 000,291,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\defragsvc.dll – (defragsvc)
SRV:64bit: - [2009/07/13 17:40:13 | 000,083,968 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\bthserv.dll – (bthserv)
SRV:64bit: - [2009/07/13 17:40:10 | 000,100,864 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\bdesvc.dll – (BDESVC)
SRV:64bit: - [2009/07/13 17:40:05 | 000,114,688 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AxInstSv.dll – (AxInstSV)
SRV:64bit: - [2009/07/13 17:40:01 | 000,032,256 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appidsvc.dll – (AppIDSvc)
SRV:64bit: - [2009/07/13 17:39:51 | 001,503,744 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbengine.exe – (wbengine)
SRV:64bit: - [2009/07/13 17:39:28 | 003,524,608 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\sppsvc.exe – (sppsvc)
SRV:64bit: - [2009/07/13 17:39:11 | 000,689,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FXSSVC.exe – (Fax)
SRV:64bit: - [2009/04/07 12:49:46 | 001,038,088 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64)
SRV - [2009/12/16 12:07:51 | 000,185,640 | —- | M] () [On_Demand | Stopped] – C:\Users\bolero\AppData\Roaming\Mikogo\B-Service.exe – (B-Service)
SRV - [2009/12/10 19:18:26 | 000,045,056 | —- | M] (Intuit) [Auto | Running] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2009/09/21 02:31:17 | 001,028,432 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/08/28 19:42:54 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/07/13 19:20:14 | 000,000,000 | —D | M] [On_Demand | Stopped] – C:\Windows\Vss – (VSS)
SRV - [2009/07/13 19:20:14 | 000,000,000 | —D | M] [Unknown | Stopped] – C:\Windows\SysWOW64\Msdtc – (MSDTC)
SRV - [2009/07/13 17:16:12 | 000,165,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\provsvc.dll – (HomeGroupProvider)
SRV - [2009/07/13 17:15:11 | 000,253,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV - [2009/07/13 12:30:11 | 000,061,056 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2009/06/10 12:39:58 | 000,089,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2009/04/07 12:44:53 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/12/05 15:11:54 | 000,935,208 | —- | M] (Nero AG) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2008/09/30 18:59:26 | 000,192,512 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe – (HPBtnSrv)
SRV - [2008/09/04 04:21:50 | 000,122,880 | —- | M] (AMD) [On_Demand | Stopped] – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe – (AMD_RAIDXpert)
SRV - [2008/08/15 04:46:20 | 000,284,016 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe – (Adobe Version Cue CS4)
SRV - [2008/08/08 21:10:46 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2007/08/24 06:59:20 | 000,068,464 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service)
SRV - [2007/07/19 17:54:48 | 000,689,408 | —- | M] (American Power Conversion Corporation) [Auto | Running] – C:\Program Files (x86)\APC\APC PowerChute Personal Edition\mainserv.exe – (APC UPS Service)
SRV - [2004/10/22 03:24:18 | 000,073,728 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.5.0
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105


FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/01/21 21:34:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/01/21 21:31:31 | 000,000,000 | —D | M]

[2009/11/15 17:49:12 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mozilla\Extensions
[2010/02/02 19:30:24 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions
[2010/01/30 00:08:31 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/11/15 17:49:19 | 000,000,000 | —D | M] (Web Developer) – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/01/30 20:46:01 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mozilla\Firefox\Profiles\eu6jcvcy.default\extensions\[removed]
[2009/11/15 17:27:59 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/02/02 17:54:15 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (IE Developer Toolbar BHO) - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O4 - Startup: C:\Users\bolero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LivePerson Expert Messenger.lnk = C:\Program Files (x86)\LivePerson\Expert\LPExpertMessenger.exe (LivePerson Inc.)
O4 - Startup: C:\Users\bolero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_03.02.2010_03-10.lnk = C:\Users\bolero\Desktop\Virus Removal Tool\setup_9.0.0.722_03.02.2010_03-10\startup.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files (x86)\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.microsoft.com/download/7/4…helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
64bit: O35 - comfile [open] – "%1" %* File not found
64bit: O35 - exefile [open] – "%1" %* File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2009/07/13 19:20:14 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:64bit: Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:64bit: BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 19:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/02/02 22:01:51 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/02/02 22:00:21 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/02/02 18:23:59 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2010/02/02 18:23:26 | 000,352,784 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\1180314.sys
[2010/02/02 18:23:26 | 000,157,712 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\11803141.sys
[2010/02/02 18:23:26 | 000,040,464 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\11803142.sys
[2010/02/02 18:23:25 | 000,000,000 | —D | C] – C:\Users\bolero\Desktop\Virus Removal Tool
[2010/02/02 17:53:47 | 000,000,000 | —D | C] – C:\_OTL
[2010/02/01 23:47:08 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\MixMeister Technology
[2010/02/01 23:46:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\MixMeister Fusion
[2010/02/01 09:43:20 | 000,000,000 | —D | C] – C:\ProgramData\Sony
[2010/02/01 09:43:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sony
[2010/02/01 08:24:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/02/01 08:20:02 | 000,000,000 | —D | C] – C:\Users\bolero\Desktop\backups from reg
[2010/01/31 23:52:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinDirStat
[2010/01/31 23:20:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\WhatsRunning
[2010/01/31 20:09:07 | 000,022,096 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/01/31 20:09:06 | 000,120,912 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/01/31 20:09:05 | 000,028,752 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/01/31 20:09:03 | 000,051,280 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/01/31 20:09:00 | 000,063,568 | —- | C] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/01/31 20:07:23 | 000,152,672 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/01/31 20:07:23 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/01/31 20:07:21 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/01/31 20:07:21 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/01/31 19:26:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Seagate
[2010/01/31 16:07:19 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\MigWiz
[2010/01/31 15:33:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/01/31 14:55:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrendMicro
[2010/01/31 14:16:33 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Malwarebytes
[2010/01/31 14:16:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/01/31 14:16:28 | 000,022,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/01/31 14:16:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/01/31 14:16:28 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/01/31 13:34:23 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\TrueCrypt
[2010/01/31 13:34:13 | 000,000,000 | —D | C] – C:\ProgramData\TrueCrypt
[2010/01/31 13:34:11 | 000,222,160 | —- | C] (TrueCrypt Foundation) – C:\Windows\SysWow64\drivers\truecrypt.sys
[2010/01/31 13:34:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrueCrypt
[2010/01/30 20:38:49 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/01/30 20:37:11 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2010/01/30 20:11:41 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\WinBatch
[2010/01/30 19:01:36 | 000,000,000 | —D | C] – C:\Users\bolero\Documents\My Adobe Captivate Projects
[2010/01/30 19:00:51 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\adobe.captivate.swfcomment.AdobeCaptivateReviewer.4875E02D9FB21EE389F73B8D1
702B320485DF8CE.1
[2010/01/30 17:25:04 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Western Digital
[2010/01/30 17:24:54 | 000,000,000 | —D | C] – C:\ProgramData\Western Digital
[2010/01/30 17:23:52 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\Western Digital
[2010/01/30 01:58:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Citrix
[2010/01/30 00:08:27 | 000,000,000 | —D | C] – C:\Program Files\Recuva
[2010/01/29 23:39:17 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/01/29 23:38:58 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\SUPERAntiSpyware.com
[2010/01/29 23:38:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\SUPERAntiSpyware
[2010/01/29 17:12:27 | 004,194,304 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\Windows\SysWow64\cdintf400.dll
[2010/01/28 16:56:58 | 000,000,000 | —D | C] – C:\Users\bolero\Documents\TurboTax
[2010/01/28 16:56:41 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Intuit
[2010/01/28 16:56:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AnswerWorks 5.0
[2010/01/28 16:52:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\TurboTax
[2010/01/27 11:11:31 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\mIRC
[2010/01/27 11:11:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\mIRC
[2010/01/22 21:30:57 | 000,000,000 | —D | C] – C:\ProgramData\{E7D4E1BB-A8A8-4E3B-BEA6-38DD8E4522DF}
[2010/01/22 21:26:20 | 000,000,000 | —D | C] – C:\ProgramData\{4275E5EA-6E30-48EB-A209-F964539CBE1C}
[2010/01/21 21:47:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASIO4ALL v2
[2010/01/21 18:32:20 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Publish Providers
[2010/01/21 18:25:33 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\Sony
[2010/01/21 18:22:39 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Roaming\Sony
[2010/01/20 22:19:28 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\DeskShare
[2010/01/20 22:13:58 | 000,000,000 | —D | C] – C:\ProgramData\Deskshare
[2010/01/20 22:13:56 | 000,000,000 | —D | C] – C:\Windows\XSxS
[2010/01/20 22:13:56 | 000,000,000 | —D | C] – C:\Users\bolero\AppData\Local\Xenocode
[2010/01/20 22:13:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xenocode
[2010/01/20 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DeskShare Shared
[2010/01/20 22:13:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Deskshare

========== Files - Modified Within 14 Days ==========

[2010/02/02 23:30:48 | 005,242,880 | -HS- | M] () – C:\Users\bolero\NTUSER.DAT
[2010/02/02 23:25:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2327562318-2441480392-3380623591-1000UA.job
[2010/02/02 22:48:28 | 000,007,168 | —- | M] () – C:\Users\bolero\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/02 22:03:58 | 000,000,231 | —- | M] () – C:\Windows\win.ini
[2010/02/02 18:23:59 | 000,002,257 | —- | M] () – C:\Users\bolero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_03.02.2010_03-10.lnk
[2010/02/02 18:05:31 | 000,009,504 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/02 18:05:31 | 000,009,504 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/02 17:58:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/02/02 17:58:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/02/02 17:57:57 | 2141,249,535 | -HS- | M] () – C:\hiberfil.sys
[2010/02/02 17:54:20 | 004,568,137 | -H– | M] () – C:\Users\bolero\AppData\Local\IconCache.db
[2010/02/02 17:54:15 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2010/02/02 12:34:42 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2327562318-2441480392-3380623591-1000Core.job
[2010/02/02 08:43:33 | 000,024,246 | —- | M] () – C:\Users\bolero\Desktop\chart_music.top.gif
[2010/02/01 21:56:00 | 000,774,192 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/02/01 21:56:00 | 000,656,430 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/02/01 21:56:00 | 000,120,262 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/02/01 09:55:44 | 294,489,930 | —- | M] () – C:\Users\bolero\Desktop\backup3.reg
[2010/02/01 09:52:53 | 000,000,162 | -H– | M] () – C:\Users\bolero\Desktop\~$ackup2.reg
[2010/02/01 09:45:51 | 000,002,584 | —- | M] () – C:\Users\bolero\Desktop\Register Sound Forge Pro.htm
[2010/02/01 08:38:43 | 000,422,428 | —- | M] () – C:\Users\bolero\Desktop\cc_20100201_083754.reg
[2010/02/01 08:37:45 | 295,682,646 | —- | M] () – C:\Users\bolero\Desktop\backup2.reg
[2010/02/01 08:24:05 | 000,001,891 | —- | M] () – C:\Users\bolero\Desktop\CCleaner.lnk
[2010/02/01 08:19:47 | 296,032,750 | —- | M] () – C:\Users\bolero\Desktop\backup.reg
[2010/02/01 03:31:03 | 000,000,496 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/01/31 23:52:47 | 000,001,037 | —- | M] () – C:\Users\bolero\Desktop\WinDirStat.lnk
[2010/01/31 23:20:59 | 000,000,989 | —- | M] () – C:\Users\bolero\Desktop\What's Running.lnk
[2010/01/31 20:14:52 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/01/31 19:41:34 | 000,019,016 | —- | M] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2010/01/31 14:16:32 | 000,001,015 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/31 13:34:13 | 000,001,064 | —- | M] () – C:\Users\Public\Desktop\TrueCrypt.lnk
[2010/01/31 13:34:11 | 000,222,160 | —- | M] (TrueCrypt Foundation) – C:\Windows\SysWow64\drivers\truecrypt.sys
[2010/01/29 17:12:28 | 000,000,090 | —- | M] () – C:\Windows\QBChanUtil_Trigger.ini
[2010/01/28 14:09:26 | 000,152,672 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/01/28 13:57:59 | 000,051,280 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/01/28 13:57:40 | 000,120,912 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2010/01/28 13:54:45 | 000,028,752 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/01/28 13:54:30 | 000,063,568 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/01/28 13:54:07 | 000,022,096 | —- | M] (ALWIL Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys

========== Files Created - No Company Name ==========

[2010/02/02 18:23:59 | 000,002,257 | —- | C] () – C:\Users\bolero\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_03.02.2010_03-10.lnk
[2010/02/01 09:55:21 | 294,489,930 | —- | C] () – C:\Users\bolero\Desktop\backup3.reg
[2010/02/01 09:52:53 | 000,000,162 | -H– | C] () – C:\Users\bolero\Desktop\~$ackup2.reg
[2010/02/01 08:38:04 | 000,422,428 | —- | C] () – C:\Users\bolero\Desktop\cc_20100201_083754.reg
[2010/02/01 08:37:21 | 295,682,646 | —- | C] () – C:\Users\bolero\Desktop\backup2.reg
[2010/02/01 08:24:05 | 000,001,891 | —- | C] () – C:\Users\bolero\Desktop\CCleaner.lnk
[2010/02/01 08:19:23 | 296,032,750 | —- | C] () – C:\Users\bolero\Desktop\backup.reg
[2010/01/31 23:52:47 | 000,001,037 | —- | C] () – C:\Users\bolero\Desktop\WinDirStat.lnk
[2010/01/31 23:20:59 | 000,000,989 | —- | C] () – C:\Users\bolero\Desktop\What's Running.lnk
[2010/01/31 20:09:00 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2010/01/31 18:34:36 | 000,019,016 | —- | C] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2010/01/31 14:16:32 | 000,001,015 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/31 13:34:13 | 000,001,064 | —- | C] () – C:\Users\Public\Desktop\TrueCrypt.lnk
[2010/01/18 21:27:05 | 000,007,168 | —- | C] () – C:\Users\bolero\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/29 13:38:58 | 000,002,319 | R— | C] () – C:\Windows\SysWow64\emaud.ini
[2009/12/29 13:38:58 | 000,000,035 | R— | C] () – C:\Windows\SysWow64\ctzapxx.ini
[2009/12/11 22:44:15 | 000,001,511 | —- | C] () – C:\Windows\Concordance.Ini
[2009/11/15 17:03:51 | 000,743,126 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\SysWow64\OGACheckControl.DLL
[2009/07/13 15:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 13:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/27 14:22:30 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/04/03 12:18:50 | 001,073,152 | —- | C] () – C:\Windows\SysWow64\libmysql_c.dll
[2009/03/29 14:38:34 | 000,000,524 | —- | C] () – C:\Windows\pear.ini
[2009/03/24 20:48:14 | 000,000,481 | —- | C] () – C:\Windows\my.ini
[2009/03/03 09:47:31 | 000,000,090 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2009/03/02 21:01:46 | 002,463,976 | —- | C] () – C:\Windows\SysWow64\NPSWF32.dll
[2008/11/19 20:45:01 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/11/19 20:45:01 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/09/19 03:59:22 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\libxml2.dll

========== LOP Check ==========

[2009/11/15 17:47:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Ableton
[2009/11/15 17:48:00 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Ambient Design
[2009/11/15 17:48:00 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Aptana
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Artisteer
[2010/02/02 21:43:16 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\BPFTP
[2009/11/18 11:22:37 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\CopyTrans
[2009/12/29 11:35:34 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Cycling '74
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Dev-Cpp
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\FileZilla
[2009/11/15 17:48:40 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Forte
[2009/11/15 17:49:12 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Mikogo
[2009/07/06 10:19:22 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\PACE Anti-Piracy
[2010/01/29 21:10:09 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Propellerhead Software
[2010/01/21 18:32:20 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Publish Providers
[2009/11/18 12:09:47 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\SharePod
[2010/01/22 14:15:32 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Sony
[2009/11/15 17:49:20 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\SystemRequirementsLab
[2010/01/31 14:32:25 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\TrueCrypt
[2009/11/15 17:49:20 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2010/01/30 02:35:33 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\webex
[2010/01/31 12:33:38 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\Western Digital
[2010/01/30 20:11:41 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\WinBatch
[2009/11/18 11:19:57 | 000,000,000 | —D | M] – C:\Users\bolero\AppData\Roaming\WindSolutions
[2010/02/01 03:31:03 | 000,000,496 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/13 21:08:49 | 000,013,648 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 17:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 17:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 17:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 17:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 17:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 17:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 17:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 17:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/13 17:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 17:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 17:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 17:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 17:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 17:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 17:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 17:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 17:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 17:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 17:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 17:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:C119EC96
@Alternate Data Stream - 99 bytes -> C:\ProgramData\Temp:24051EFF
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:63238B95
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:901E30B2
< End of report >
Hello fringelunatic,

Well I think your machine is clean of malware.

I see you are receiving help elsewhere.

I am thinking this is likely a technical thing and the other site may be on to something when they say that those files might not actually be lost.

In any event you should not be receiving help from two sites on the same problem. As I am not a tech and as we have looked at the malware side I think you should pursue the other possibilites.

We have a couple of last steps to perform and then you're all set.[image unavailable: Posted Image]

  • Double-click OTL.exe to run it. (Vista users, please right click on OTL.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

MBAM can be uninstalled via control panel add/remove but it may be a useful tool to keep.

Next, we need to clean your restore points and set a new one:

Please go here for directions on how to do this. You need to turn System Protection off to delete all old restore points, reboot and then turn System Protection back on to create a new restore point.

——————————————————————————————————————-

A reminder: Remember to turn back on any anti-malware programs you may have turned off during the cleaning process.

——————————————————————————————————————-

Now that your machine is clean here are some things that I think are worth having a look at if you don't already know about them:

———————————————————————————————————————

Regularly check that your Java is up to date. Older versions are vunerable to malicious attack.
  • Download from here Java Runtime Environment (JDK) Update
  • Scroll to where it says "Windows XP/Vista/2000/2003/2008 online" and download and follow the instructions to install.

    Reboot your computer.
    You also need to uininstall older versions of Java.

  • Click Start > Control Panel > Programs
  • Remove all Java updates except the latest one you have just installed.
——————————————————————————————————————–

Be sure and give the Temp folders a cleaning out now and then. This helps with security and your computer will run more efficiently. I clean mine once a week. For ease of use, you might consider the following free program: ——————————————————————————————————————–

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
* Consider using an alternate browser.

Opera may be downloaded from here. It is one of the least targeted of all browers.

Avant may be downloaded from here. Another one that is less well known.

Firefox may be downloaded from Here. I use Firefox because I like it. Used to be one of the safest but now targeted probably as much as IE.

———————————————————————————————————————–

To help protect your computer in the future here are some free programs you can look at:

If your Microsoft Update is not working automatically. Keep your operating system up to date by visiting
  • Microsoft Windows Update

    monthly.

    And to keep your system clean

    update and run Malwarebytes & SUPERAntiSpyware weekly, and be aware of what emails you open and websites you visit.
Go here for some good advice about how to prevent infection.

Have a safe and happy computing day!
I gave up on the other sites. I haven't even checked them. I thank you for your help. As for the files not being gone, I disagree. All recovery apps I have run say many of them have been overwritten.
It happened again! Everything I had on the drive just got wiped out EXCEPT two files I purposely marked as READ ONLY. I THINK this happened when I went to print a web page to Adobe PDF. I heard the drive click to life and then when I checked it everything was gone! How can I find out what happened? Is there an audit trail or something?? What is going on here???? ANyone???
Well Kaspersky AVP is pretty comprehensive. I suppose it might not have scanned that drive. Did you have all those boxes checked?

You didn't post the results of the scan so I could only take your word for it that nothing was there.

You could check that out but for now let's do this:

Make sure it's set to Perform a full scan.

You have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here.

If you no-longer have Malwarebytes please download from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform a Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy & Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI