This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Crashes when trying to run a SuperAntiSpyware scan

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am new to this forum but from what I have read from other posts it looks like you guys can help.

I was experiencing a lot of slow down on my computer especially when I tried to execute a program. Also I hear my hard drive just load and load and load. So I downloaded some antivirus tools based on the suggestions on techsupportalert.com to try and clean up my computer. Everything was going fine until I tried to run SuperAntiSpyware. During the scan (I was doing a complete scan) my computer crashed and restarted. I thought this might just be a fluke so I tried it two more times and both times I got the same result. I did see another post about a computer crashing while running SuperAntiSpyware but that person was experiencing some other problems that I am not having. So I thought that instead of just following the instructions given on that post, I thought it might be wiser to do my own post.

Here are the logs that the "are you infected" topic instructed to give:

Defogger:

defogger_disable by jpshortstuff (29.01.10.1)
Log created at 15:33 on 08/02/2010 (Alan)

Checking for autostart values…
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers…


Malwarebites:

Malwarebytes' Anti-Malware 1.44
Database version: 3710
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

2/8/2010 3:45:25 PM
mbam-log-2010-02-08 (15-45-25).txt

Scan type: Quick Scan
Objects scanned: 112956
Time elapsed: 5 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Gmer:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-06 00:10:46
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Alan\AppData\Local\Temp\kxldrpog.sys


—- System - GMER 1.0.15 —-

INT 0x52 ? 84526BF8
INT 0x53 ? 86709F00
INT 0x62 ? 84526BF8
INT 0x83 ? 86709F00
INT 0xA3 ? 84526BF8
INT 0xB3 ? 84526BF8

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8530D1F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 VMkbd.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 VMkbd.sys

Device \Driver\volmgr \Device\VolMgrControl 8530A1F8
Device \Driver\usbohci \Device\USBPDO-0 8690E1F8
Device \Driver\usbehci \Device\USBPDO-1 8690D1F8
Device \Driver\PCI_PNP7786 \Device\00000060 spft.sys
Device \Driver\netbt \Device\NetBT_Tcpip_{AE153BAD-0267-48ED-8F0B-57B92FFCA698} 872231F8

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\sptd \Device\153977791 spft.sys
Device \Driver\volmgr \Device\HarddiskVolume1 8530A1F8
Device \Driver\netbt \Device\NetBT_Tcpip_{F15000B1-725B-4A99-928C-102B0674CC15} 872231F8
Device \Driver\volmgr \Device\HarddiskVolume2 8530A1F8
Device \Driver\cdrom \Device\CdRom0 8690B1F8
Device \Driver\volmgr \Device\HarddiskVolume3 8530A1F8
Device \Driver\cdrom \Device\CdRom1 8690B1F8
Device \Driver\atapi \Device\Ide\IdePort0 8530C1F8
Device \Driver\atapi \Device\Ide\IdePort1 8530C1F8
Device \Driver\atapi \Device\Ide\IdePort2 8530C1F8
Device \Driver\atapi \Device\Ide\IdePort3 8530C1F8
Device \Driver\atapi \Device\Ide\IdePort4 8530C1F8
Device \Driver\atapi \Device\Ide\IdePort5 8530C1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-5 8530C1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-4 8530C1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 872231F8
Device \Driver\Smb \Device\NetbiosSmb 871AE1F8
Device \Driver\iScsiPrt \Device\RaidPort0 86A4C1F8

AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbohci \Device\USBFDO-0 8690E1F8
Device \Driver\usbohci \Device\USBFDO-0 hcmon.sys
Device \Driver\usbehci \Device\USBFDO-1 8690D1F8
Device \Driver\usbehci \Device\USBFDO-1 hcmon.sys
Device \Driver\USBSTOR \Device\0000007d 87B061F8
Device \Driver\USBSTOR \Device\0000007e 87B061F8
Device \Driver\ai5hk5h1 \Device\Scsi\ai5hk5h11Port7Path0Target0Lun0 869131F8
Device \Driver\ai5hk5h1 \Device\Scsi\ai5hk5h11 869131F8
Device \FileSystem\cdfs \Cdfs 8854E500

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x5C 0x79 0x65 0x7D …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0xB0 0x8B 0xA0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCA 0x64 0x81 0x79 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x5C 0x79 0x65 0x7D …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x3E 0xB0 0x8B 0xA0 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCA 0x64 0x81 0x79 …

—- Files - GMER 1.0.15 —-

File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0B42E.log 0 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0B440.log 0 bytes

—- EOF - GMER 1.0.15 —-


DDS:

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:11:08.04 on Sat 02/06/2010
Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.2285 [GMT -7:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\ZoomText 9.1\ZtUac.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\crypserv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\AVG\AVG8\avgnsx.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\vmnat.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\ZoomText 9.1\ZoomTextHelperService.exe
C:\Program Files\AVG\AVG8\avgemc.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\vmnetdhcp.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\windows defender\MSASCui.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Alan\Desktop\Temp Cleaning Folder\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: {E1FF080D-12A3-439A-A2EF-4BA95A3148E8} - No File
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
mRun: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\audios~1.lnk - c:\windows\installer\{2174d448-f6a7-49ec-b42d-67fe626094e9}\AudioSpooler.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\d-link~1.lnk - c:\program files\d-link airplus g\AirPlus.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: avgrsstx.dll c:\progra~1\google\google~3\GOEC62~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\alan\appdata\roaming\mozilla\firefox\profiles\oy3uhsk5.default\
FF - component: c:\users\alan\appdata\roaming\mozilla\firefox\profiles\oy3uhsk5.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\openoffice.org 3\program\npsoplugin.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\alan\appdata\roaming\mozilla\firefox\profiles\oy3uhsk5.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\users\alan\appdata\roaming\mozilla\firefox\profiles\oy3uhsk5.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 Ai2Chroniker;Ai2Chroniker;c:\windows\system32\drivers\Ai2Chroniker.sys [2010-1-2 6144]
R1 Ai2sXP;Ai2sXP;c:\windows\system32\drivers\Ai2sXP.sys [2008-8-21 7680]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-21 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-6 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-12-17 21504]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\program files\avg\avg8\avgemc.exe [2010-1-6 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\program files\avg\avg8\avgwdsvc.exe [2010-1-6 297752]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-9-27 240232]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2008-10-28 54960]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R2 ZoomText Helper Service;ZoomText Helper Service;c:\program files\zoomtext 9.1\ZoomTextHelperService.exe [2008-8-21 11776]
R3 Ai2Mmpd;Ai2Mmpd;c:\windows\system32\drivers\Ai2Mmpd.sys [2010-1-2 8192]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [2008-8-21 1335808]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-11-26 84832]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-12-17 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-1-2 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 42480]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-8-21 356920]

=============== Created Last 30 ================

2010-02-05 11:09 –d—– c:\users\alan\appdata\roaming\Dexpot
2010-02-05 10:57 –d—– c:\users\alan\appdata\roaming\Auslogics
2010-02-05 01:29 32,768 a——- c:\windows\system32\CleanMem.exe
2010-02-05 01:28 –d—– c:\windows\CleanMem
2010-02-05 01:28 –d—– c:\program files\CleanMem
2010-02-05 01:27 –d—– c:\program files\Auslogics
2010-02-05 01:24 –d—– c:\program files\Sophos
2010-02-04 21:34 –d—– c:\program files\Microsoft Security Essentials
2010-02-01 09:44 –d—– c:\program files\Lame for Audacity
2010-02-01 09:44 –d—– c:\program files\Audacity
2010-01-31 20:18 –d—– c:\users\alan\Tracing
2010-01-29 01:12 –d—– c:\program files\Veoh Networks
2010-01-23 00:07 –d—– c:\users\alan\.thumbnails
2010-01-22 09:48 –d—– c:\users\alan\.gimp-2.6
2010-01-22 09:47 –d—– c:\program files\GIMP-2.0
2010-01-17 14:00 –d–r– c:\program files\Skype
2010-01-13 19:47 156,672 a——- c:\windows\system32\t2embed.dll
2010-01-13 19:47 72,704 a——- c:\windows\system32\fontsub.dll
2010-01-13 19:06 –d—– c:\program files\Free Online TV Player
2010-01-13 17:55 –d—– c:\program files\The KMPlayer
2010-01-10 22:56 –d—– c:\program files\Privateer
2010-01-07 17:29 –d—– c:\users\alan\dwhelper
2010-01-07 15:06 –d—– c:\program files\Windows Portable Devices
2010-01-07 15:06 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-01-07 15:06 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-01-07 15:00 1,164,800 a——- c:\windows\system32\UIRibbonRes.dll
2010-01-07 15:00 92,672 a——- c:\windows\system32\UIAnimation.dll
2010-01-07 15:00 3,023,360 a——- c:\windows\system32\UIRibbon.dll
2010-01-07 14:58 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2010-01-07 14:58 234,496 a——- c:\windows\system32\oleacc.dll
2010-01-07 14:58 4,096 a——- c:\windows\system32\oleaccrc.dll
2010-01-07 14:44 –d—– c:\windows\system32\eu-ES
2010-01-07 14:44 –d—– c:\windows\system32\ca-ES
2010-01-07 14:44 –d—– c:\windows\system32\vi-VN
2010-01-07 13:54 –d—– c:\windows\system32\EventProviders
2010-01-07 13:52 1,575,936 a——- c:\windows\system32\WMVENCOD.DLL
2010-01-07 10:54 –d—– c:\program files\JRE
2010-01-07 10:27 377,344 a——- c:\windows\system32\winhttp.dll
2010-01-07 01:25 499,712 a——- c:\windows\system32\kerberos.dll
2010-01-07 01:25 270,848 a——- c:\windows\system32\schannel.dll

==================== Find3M ====================

2010-02-05 23:26 34,800 a——- c:\programdata\nvModes.dat
2010-02-05 23:26 34,800 a——- c:\progra~2\nvModes.dat
2010-01-18 00:00 143,360 a——- c:\windows\inf\infstrng.dat
2010-01-18 00:00 51,200 a——- c:\windows\inf\infpub.dat
2010-01-18 00:00 86,016 a——- c:\windows\inf\infstor.dat
2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2010-01-07 15:06 665,600 a——- c:\windows\inf\drvindex.dat
2010-01-06 23:01 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2010-01-06 23:01 11,952 a——- c:\windows\system32\avgrsstx.dll
2010-01-06 23:01 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2010-01-02 03:13 229,224 a——- c:\windows\system32\drivers\VMM.sys
2010-01-01 23:38 916,480 a——- c:\windows\system32\wininet.dll
2010-01-01 23:32 109,056 a——- c:\windows\system32\iesysprep.dll
2010-01-01 23:32 71,680 a——- c:\windows\system32\iesetup.dll
2010-01-01 21:57 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-12-08 18:45 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-03 14:12 167,936 a——- c:\windows\system32\Ai2XOR.dll
2009-12-03 14:12 58,368 a——- c:\windows\system32\Ai2d91.dll
2009-12-03 14:12 15,872 a——- c:\windows\system32\Ai2Ldr.dll
2009-11-09 05:31 24,064 a——- c:\windows\system32\nshhttp.dll
2009-11-09 05:30 30,720 a——- c:\windows\system32\httpapi.dll
2008-12-17 11:28 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2006-05-03 02:06 163,328 a–shr– c:\windows\system32\flvDX.dll
2007-02-21 03:47 31,232 a–shr– c:\windows\system32\msfDX.dll
2008-03-16 05:30 216,064 a–shr– c:\windows\system32\nbDX.dll
2008-12-18 09:27 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008121820081219\index.dat
2008-12-21 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008122120081222\index.dat
2008-12-25 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008122520081226\index.dat
2008-12-28 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008122820081229\index.dat
2009-01-05 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008122920090105\index.dat
2009-01-13 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009010520090112\index.dat
2009-01-13 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009011320090114\index.dat
2009-01-16 04:04 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009011620090117\index.dat
2009-01-18 12:26 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009011820090119\index.dat
2009-01-21 04:03 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009012120090122\index.dat
2009-01-23 04:04 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009012320090124\index.dat
2009-01-25 04:05 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009012520090126\index.dat
2009-02-02 04:09 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009012620090202\index.dat
2009-02-02 04:09 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009020220090203\index.dat
2009-02-04 04:09 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012009020420090205\index.dat

============= FINISH: 0:12:04.99 ===============


I hope I followed the instructions correctly. Thankyou.
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your log , I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



You will need to right click and choose "Run as Administrator" to run the tools we will use.


Please post the contents of Attach.txt in your next reply.

–Next–

You have multiple anti spyware running on your computer, Spyware Doctor, Windows Defender and SUPERAntiSpyware. Running more than one anti spyware at the same time does not only slow down your computer but
provides less protection than they are programmed to do, due to the fact that they will be conflicting with each other rather than providing sufficient protection for your computer. Please uninstall one of your anti spyware before proceeding with any of the fixes.

–Next–

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right-click SystemLook.exe then choose "Run as Administrator" to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    spft.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

–Next–

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator)
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"=-

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


To post in your next reply:
1. Attach.txt.
2. SystemLook log.
3. OTM script log.
Sounds fine. I will follow your instructions. I will have a complete post for you later tonight.
I disabled and/or uninstalled: Spyware Doctor Windows Defender Attach.txt: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 12/17/2008 2:08:49 AM System Uptime: 2/5/2010 10:48:39 PM (2 hours ago) Motherboard: ASUSTeK Computer INC. | | M2N-E SLI Processor: AMD Athlon™ 64 X2 Dual Core Processor 6000+ | Socket AM2 | 3015/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 279 GiB total, 120.717 GiB free. D: is CDROM () E: is CDROM () F: is FIXED (NTFS) - 20 GiB total, 19.442 GiB free. I: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet1 Device ID: ROOT\VMWARE\0000 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet1 PNP Device ID: ROOT\VMWARE\0000 Service: VMnetAdapter Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: VMware Virtual Ethernet Adapter for VMnet8 Device ID: ROOT\VMWARE\0001 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet8 PNP Device ID: ROOT\VMWARE\0001 Service: VMnetAdapter ==== System Restore Points =================== RP291: 2/5/2010 1:54:24 AM - Windows Update RP292: 2/5/2010 11:00:16 PM - Windows Update RP293: 2/5/2010 11:29:02 PM - Automatic Restore Point ==== Installed Programs ====================== µTorrent 4Musics MP3 Bitrate Changer 5.0 7-Zip 4.57 AbiWord 2.6.6 AbiWord Tools Plugins Adobe AIR Adobe Flash Player 10 Plugin Adobe Reader 9.3 Ai Squared Visual C++ Runtime Audacity 1.2.6 Auslogics Disk Defrag AutoUpdate AVG Free 8.5 C-Media CM6501 Like Sound Driver CCleaner Celestia 1.6.0 Chandler 1.0.3 CleanMem ClearPlay Easy Updates Crysis WARHEAD® D-Link AirPlus G Wireless LAN Adapter dBpoweramp FLAC Codec dBpoweramp Music Converter Dead Space™ Diskeeper Lite DivX Codec Dual-Core Optimizer EasyCleaner EPSON Copy Utility 3 EPSON Event Manager EPSON File Manager EPSON Print CD EPSON Printer Software EPSON Scan EPSON Scan Assistant EPSON SPR300 Reference Guide ERUNT 1.1j EssentialPIM Fireflies Screensaver (remove only) Fraps Free Online TV Player Freecorder Toolbar 3.02 Application GetASFStream GIMP 2.6.8 Google Earth Google SketchUp 7 GPL Ghostscript 8.63 Holding Pattern Coach Screen Saver Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) iDailyDiary 3.52 Java™ 6 Update 17 Java™ 6 Update 4 Java™ 6 Update 7 JumpStart Advanced Preschool JumpStart Advanced PreSchool Explore and Learn JumpStart Art for Fun JumpStart Languages Junk Mail filter update King's Bounty. The Legend (Remove Only) Kurzweil 1000 v.11 LAME v3.98.2 for Audacity LDS Gospel Resource LDS Scriptures CD-ROM Resource Edition MechWarrior 3 Mechwarrior CD Patch 1.0 Metacafe Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 3.5 SP1 Microsoft Antimalware Microsoft Application Error Reporting Microsoft Choice Guard Microsoft IntelliPoint 7.0 Microsoft IntelliType Pro 7.0 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Live Add-in 1.4 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Virtual PC 2007 SP1 Microsoft Visual Basic PowerPacks 2.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft XNA Framework Redistributable 2.0 Mobipocket Reader 6.2 Mozilla Firefox (3.5.7) MSVCRT MSXML 4.0 SP2 (KB973688) Network Stumbler 0.4.0 (remove only) NVIDIA Drivers NVIDIA PhysX v8.10.13 NVIDIA Stereoscopic 3D Driver Open Workbench OpenAL OpenDNS Updater 2.2 OpenOffice.org 3.1 Palm Desktop by ACCESS Privateer Punch! Home Design - AS3000 Python 2.5 comtypes-0.5.2 Python 2.5 PIL-1.1.6 Python 2.5 psyco-1.6 Python 2.5 pywin32-212 Python 2.5.2 QuickTime QuotePad 2.2 RapidTyping RCA Pearl (Model TH11, TC11 Series) Firmware Update Utility Real Checkers RealSpeak Solo for UK English Emily RFB&D Download Manager RiftSpace RoughDraft 3.0 Sansa Updater SaverBeans Screensaver Pack 0.2 Scribus [removed] Security Update for 2007 Microsoft Office System (KB969559) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) SEO Note Skype™ 4.1 Smart Defrag 1.10 Smartparts Desktop Sonar3 Sophos Anti-Rootkit 1.5.0 Spyware Doctor 6.0 Stamina 2.5 Streambox Vcr Suite 2 SUPER © Version 2008.bld.33 (Sep 2, 2008) SUPERAntiSpyware Free Edition Task Coach 0.73.2 The KMPlayer (remove only) The Ur-Quan Masters 0.6.2 TreeDBNotes 3 TypeFaster Typing Tutor Unity Web Player Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb976884) Veoh Web Player VideoLAN VLC media player 0.8.6d VMware Player VoiceText ™ WinAce Archiver Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer wxPython [removed] (ansi) for Python 2.5 X Plugin Manager 2.20 BETA 6 X² All In One Bonus Package 1.04 yWriter5 ZoomText 9.1 ==== Event Viewer Messages From Past Week ======== 2/5/2010 7:50:54 PM, Error: Service Control Manager [7023] - The WLAN AutoConfig service terminated with the following error: The remote procedure call failed and did not execute. 2/5/2010 7:50:05 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 2/5/2010 7:49:47 PM, Error: Microsoft-Windows-WLAN-AutoConfig [4002] - WLAN AutoConfig service has failed to start. Error Code: 1727 2/5/2010 7:49:45 PM, Error: EventLog [6008] - The previous system shutdown at 7:48:03 PM on 2/5/2010 was unexpected. 2/5/2010 12:17:29 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 2/5/2010 12:16:25 PM, Error: EventLog [6008] - The previous system shutdown at 12:14:52 PM on 2/5/2010 was unexpected. 2/5/2010 10:51:45 PM, Error: Service Control Manager [7001] - The IPsec Policy Agent service depends on the Base Filtering Engine service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2/5/2010 10:51:45 PM, Error: Service Control Manager [7001] - The Internet Connection Sharing (ICS) service depends on the Base Filtering Engine service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2/5/2010 10:50:34 PM, Error: Service Control Manager [7001] - The Windows Firewall service depends on the Base Filtering Engine service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 2/5/2010 10:49:59 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 2/5/2010 10:49:21 PM, Error: EventLog [6008] - The previous system shutdown at 10:47:39 PM on 2/5/2010 was unexpected. 2/4/2010 9:50:42 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection. 2/4/2010 9:48:43 PM, Error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists. 2/4/2010 9:33:34 PM, Error: Service Control Manager [7000] - The AVG Free8 E-mail Scanner service failed to start due to the following error: The system cannot find the file specified. 2/4/2010 9:33:33 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the service. 2/4/2010 9:33:03 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avg8wd service. 2/4/2010 8:59:18 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001346E45019. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 2/4/2010 8:42:17 PM, Error: netbt [4311] - Initialization failed because the driver device could not be created. Use the string "0018F30D6FF2" to identify the interface for which initialization failed. It represents the MAC address of the failed interface or the Globally Unique Interface Identifier (GUID) if NetBT was unable to map from GUID to MAC address. If neither the MAC address nor the GUID were available, the string represents a cluster device name. 2/4/2010 8:41:07 PM, Error: Service Control Manager [7016] - The NVIDIA Display Driver Service service has reported an invalid current state 32. 2/4/2010 7:56:08 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 10.20.2.155 for the Network Card with network address 001346E45019 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 2/2/2010 11:41:37 AM, Error: EventLog [6008] - The previous system shutdown at 11:40:19 AM on 2/2/2010 was unexpected. 2/2/2010 11:36:24 AM, Error: EventLog [6008] - The previous system shutdown at 11:33:54 AM on 2/2/2010 was unexpected. 2/1/2010 9:48:29 AM, Error: EventLog [6008] - The previous system shutdown at 9:45:35 AM on 2/1/2010 was unexpected. ==== End Of File =========================== System Look: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 20:50 on 10/02/2010 by Alan (Administrator - Elevation successful) ========== filefind ========== Searching for "spft.sys" No files found. -=End Of File=- OTM: All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found. ========== COMMANDS ========== [EMPTYTEMP] User: Alan ->Temp folder emptied: 31832 bytes ->Temporary Internet Files folder emptied: 38029 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 8569333 bytes ->Google Chrome cache emptied: 0 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 8.00 mb OTM by OldTimer - Version 3.1.8.0 log created on 02102010_210235
Hi,

You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall µTorrent, via Control Panel -> Programs and Features.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554

–Next–

I see that you have IObit installed in your computer. Many consider it as a rogue software. You can read more about it here.
However, removing this is your own choice.
If you wish to remove it, you can do the following:
  • Click on Start > Control Panel and double click on Programs and Features.
  • Locate Smart Defrag 1.10 and click on the Uninstall button to uninstall it.
  • Close Control Panel when done.
–Next–
  • Open Malwarebytes.
  • Click on the Update tab.
  • Click Check for Updates button.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
–Next–

Run an on-line scan with Kaspersky

Right click Internet Explorer or Firefox then choose "Run as Administrator" to run the program.

NOTE: After scanning with Kaspersky, close your browser then run it without administrator privileges for your browsing.

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
–Next–

Please run another OTL scan for me please.
  • Right click on the icon then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on your C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To post in your next reply:
1. Malwarebytes' log.
2. Kaspersky log.
3. OTL log.
4. How is your computer?
I uninstalled Smart Defrag 1.10 and disabled utorrent.

I wanted to let you know that the 3 hot links that you gave me concerning P2P dangers were all broken links. So I was unable to read the info you wanted me to read. So I have not uninstalled utorrent as of yet. I use it for something that is very important to me so I am little reluctant to uninstall it for this reason. However, that isn't to say that I won't, but I want to read up on it first. If you have any other similar links to articles I would be very happy to read them.

Also, Kaspersky is redoing their online scan and it is unavailable right now.

Here are the other logs:

Malwarebytes:

Malwarebytes' Anti-Malware 1.44
Database version: 3723
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

2/10/2010 11:55:30 PM
mbam-log-2010-02-10 (23-55-30).txt

Scan type: Quick Scan
Objects scanned: 113188
Time elapsed: 5 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)


OTL log:

OTL logfile created on: 2/11/2010 12:07:15 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Alan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): c:\pagefile.sys 4987 4987 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 278.56 Gb Total Space | 116.06 Gb Free Space | 41.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.53 Gb Total Space | 19.44 Gb Free Space | 99.55% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALAN-PC
Current User Name: Alan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Alan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\ZoomText 9.1\ZtUac.exe (Ai Squared )
PRC - C:\Program Files\ZoomText 9.1\ZoomTextHelperService.exe (Ai Squared )
PRC - C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Windows\System32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
PRC - C:\Windows\System32\vmnat.exe (VMware, Inc.)
PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Alan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Akamai) – c:\Program Files\Common Files\Akamai\rswin_3647.dll ()
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ZoomText Helper Service) – C:\Program Files\ZoomText 9.1\ZoomTextHelperService.exe (Ai Squared )
SRV - (nvsvc) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (VMnetDHCP) – C:\Windows\System32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\System32\vmnat.exe (VMware, Inc.)
SRV - (ufad-ws60) – C:\Program Files\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Crypkey License) – C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Diskeeper) – C:\Program Files\Executive Software\DiskeeperLite\DKService.exe (Executive Software International, Inc.)


========== Driver Services (SafeList) ==========

DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (vmm) – C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (Ai2sXP) – C:\Windows\System32\drivers\Ai2sXP.sys (Ai Squared )
DRV - (Ai2Mmpd) – C:\Windows\System32\drivers\Ai2Mmpd.sys (Ai Squared )
DRV - (Ai2Chroniker) – C:\Windows\System32\drivers\Ai2Chroniker.sys (Ai Squared )
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (VX3000) – C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (MpFilter) – C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (atksgt) – C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (vmci) – C:\Windows\System32\drivers\vmci.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\Windows\System32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (vmkbd) – C:\Windows\System32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (vmx86) – C:\Windows\System32\drivers\vmx86.sys (VMware, Inc.)
DRV - (hcmon) – C:\Windows\System32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMparport) – C:\Windows\System32\drivers\vmparport.sys (VMware, Inc.)
DRV - (VMnetBridge) – C:\Windows\System32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\Windows\System32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (vstor2-ws60) – C:\Program Files\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (VPCNetS2) – C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (StMp3Rec) – C:\Windows\System32\drivers\StMp3Rec.sys (Generic)
DRV - (NetworkX) – C:\Windows\system32\ckldrv.sys ()
DRV - (c65013264) – C:\Windows\System32\drivers\c6501.sys (C-Media Inc)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) – C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (ASPI) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\S-1-5-21-1967107133-2219403178-301070691-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.11.6a
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.0.1
FF - prefs.js..extensions.enabledItems: {fce36c1e-58d8-498a-b2a5-66ad1cedebbb}:0.76
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e}:0.6.4.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: [removed]:0.3


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2010/02/04 21:33:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/08 17:48:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/17 23:55:23 | 000,000,000 | —D | M]

[2008/12/17 01:47:51 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Extensions
[2010/02/10 12:29:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions
[2009/12/30 20:16:51 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/12/30 20:16:51 | 000,000,000 | —D | M] (Gmail Notifier) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
[2010/01/19 08:38:38 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/01/30 23:03:42 | 000,000,000 | —D | M] (No name found) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/01/07 11:32:12 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/01/11 23:14:03 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2008/12/17 01:47:52 | 000,000,000 | —D | M] (CustomizeGoogle) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2008/08/21 12:44:21 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\filtersetg@updater
[2009/02/22 22:32:56 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2010/01/15 10:51:17 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2009/12/30 20:16:51 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2010/01/30 23:03:42 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2008/08/24 08:50:41 | 000,000,523 | —- | M] () – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\searchplugins\daemon-search.xml
[2010/02/10 12:29:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (no name) - {E1FF080D-12A3-439A-A2EF-4BA95A3148E8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll File not found
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\..\Toolbar\ShellBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [C6501Sound] File not found
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.1.191
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Alan\Pictures\DCIM\1.22.10 Lily's botoz\1.22.10 Lily's botox.JPG
O24 - Desktop BackupWallPaper: C:\Users\Alan\Pictures\DCIM\1.22.10 Lily's botoz\1.22.10 Lily's botox.JPG
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3af0f345-a159-11de-b2f9-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{3af0f345-a159-11de-b2f9-005056c00008}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{c35808c6-cc93-11dd-81ae-0018f30d6ff2}\Shell - "" = AutoRun
O33 - MountPoints2\{c35808c6-cc93-11dd-81ae-0018f30d6ff2}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{d27dbb0d-6f44-11dd-a2c0-0018f30d6ff2}\Shell - "" = AutoRun
O33 - MountPoints2\{d27dbb0d-6f44-11dd-a2c0-0018f30d6ff2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/02/11 00:04:28 | 000,549,376 | —- | C] (OldTimer Tools) – C:\Users\Alan\Desktop\OTL.exe
[2010/02/10 20:56:49 | 000,000,000 | —D | C] – C:\_OTM
[2010/02/09 11:37:16 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Local\Adobe
[2010/02/08 19:12:44 | 000,000,000 | —D | C] – C:\ProgramData\Office Genuine Advantage
[2010/02/08 18:01:32 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2010/02/08 15:30:37 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\Malwarebytes
[2010/02/08 15:30:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/08 15:30:32 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/02/08 15:30:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/08 15:30:32 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/02/07 09:27:05 | 000,000,000 | —D | C] – C:\Users\Alan\Documents\The KMPlayer
[2010/02/07 00:03:15 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Local\Ai Squared
[2010/02/05 23:31:05 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/02/05 23:29:50 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/05 23:27:05 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\Temp Cleaning Folder
[2010/02/05 16:32:20 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\Arcade
[2010/02/05 16:30:19 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\Downloads
[2010/02/05 11:09:42 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\Dexpot
[2010/02/05 10:57:37 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\Auslogics
[2010/02/05 01:29:01 | 000,032,768 | —- | C] (PcWinTech.com) – C:\Windows\System32\CleanMem.exe
[2010/02/05 01:28:58 | 000,000,000 | —D | C] – C:\Windows\CleanMem
[2010/02/05 01:28:58 | 000,000,000 | —D | C] – C:\Program Files\CleanMem
[2010/02/05 01:27:54 | 000,000,000 | —D | C] – C:\Program Files\Auslogics
[2010/02/05 01:24:29 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2010/02/05 01:22:16 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\PC Optimizer Toolkit
[2010/02/04 21:34:36 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/02/01 09:44:42 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2010/02/01 09:44:01 | 000,000,000 | —D | C] – C:\Program Files\Audacity
[2010/01/31 20:18:14 | 000,000,000 | —D | C] – C:\Users\Alan\Tracing
[2010/01/29 02:11:58 | 000,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/01/29 02:11:58 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/01/29 02:11:57 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/01/29 02:11:57 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/01/29 02:11:57 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/01/29 02:11:57 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/01/29 02:11:57 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/01/29 02:11:57 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/01/29 02:11:57 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/01/29 02:11:57 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/01/29 02:11:57 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/01/29 02:11:57 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/01/29 02:11:57 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/01/29 02:11:57 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/01/29 01:12:47 | 000,000,000 | —D | C] – C:\Program Files\Veoh Networks
[2010/01/23 00:07:20 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\gtk-2.0
[2010/01/23 00:07:17 | 000,000,000 | —D | C] – C:\Users\Alan\.thumbnails
[2010/01/22 09:48:06 | 000,000,000 | —D | C] – C:\Users\Alan\.gimp-2.6
[2010/01/22 09:47:41 | 000,000,000 | —D | C] – C:\Program Files\GIMP-2.0
[2010/01/19 08:29:44 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/01/19 08:29:44 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/01/19 08:29:44 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/01/17 23:55:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/01/17 14:00:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/01/17 14:00:04 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/01/13 19:47:32 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/01/13 19:47:32 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/01/13 19:06:24 | 000,000,000 | —D | C] – C:\Program Files\Free Online TV Player
[2010/01/13 17:55:30 | 000,000,000 | —D | C] – C:\Program Files\The KMPlayer

========== Files - Modified Within 30 Days ==========

[2010/02/11 00:07:20 | 002,621,440 | -HS- | M] () – C:\Users\Alan\NTUSER.DAT
[2010/02/11 00:04:35 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Users\Alan\Desktop\OTL.exe
[2010/02/10 23:47:05 | 000,034,800 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/02/10 23:47:05 | 000,034,800 | —- | M] () – C:\ProgramData\nvModes.001
[2010/02/10 23:04:10 | 000,004,080 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/10 23:04:10 | 000,004,080 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/10 22:46:21 | 055,441,810 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/02/10 21:08:57 | 000,711,600 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/02/10 21:08:57 | 000,611,038 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/02/10 21:08:57 | 000,107,604 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/02/10 21:04:39 | 000,000,445 | —- | M] () – C:\Windows\System\c6501.INI
[2010/02/10 21:04:20 | 000,002,487 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Audio Spooler.lnk
[2010/02/10 21:04:11 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/02/10 21:04:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/02/10 21:04:05 | 3488,079,872 | -HS- | M] () – C:\hiberfil.sys
[2010/02/10 21:02:47 | 000,524,288 | -HS- | M] () – C:\Users\Alan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/02/10 21:02:47 | 000,065,536 | -HS- | M] () – C:\Users\Alan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/02/10 20:37:36 | 002,544,286 | -H– | M] () – C:\Users\Alan\AppData\Local\IconCache.db
[2010/02/09 21:58:39 | 000,002,377 | —- | M] () – C:\Users\Alan\Desktop\Skype.lnk
[2010/02/09 00:05:53 | 000,012,997 | —- | M] () – C:\Users\Alan\Desktop\THE WOW BUDGET.ods
[2010/02/08 15:33:10 | 000,000,000 | —- | M] () – C:\Users\Alan\defogger_reenable
[2010/02/05 15:27:20 | 000,001,660 | —- | M] () – C:\Users\Public\Desktop\ZoomText 9.1.lnk
[2010/01/23 00:07:20 | 000,000,896 | —- | M] () – C:\Users\Alan\.recently-used.xbel
[2010/01/19 21:22:28 | 000,142,495 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2010/01/14 11:12:06 | 000,181,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/01/12 00:54:57 | 000,023,552 | —- | M] () – C:\Users\Alan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2010/02/08 15:33:10 | 000,000,000 | —- | C] () – C:\Users\Alan\defogger_reenable
[2010/01/23 00:07:20 | 000,000,896 | —- | C] () – C:\Users\Alan\.recently-used.xbel
[2010/01/17 15:49:47 | 000,002,377 | —- | C] () – C:\Users\Alan\Desktop\Skype.lnk
[2010/01/07 13:53:25 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/11/06 12:52:09 | 000,034,800 | —- | C] () – C:\ProgramData\nvModes.001
[2009/11/06 12:52:07 | 000,034,800 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/28 15:19:48 | 000,000,094 | —- | C] () – C:\Windows\family.ini
[2009/07/16 15:50:42 | 000,000,680 | —- | C] () – C:\Users\Alan\AppData\Local\d3d9caps.dat
[2009/06/11 11:45:00 | 000,000,092 | —- | C] () – C:\Users\Alan\AppData\Local\fusioncache.dat
[2009/05/27 16:31:47 | 000,000,549 | —- | C] () – C:\Windows\ka.ini
[2009/02/01 03:46:00 | 000,000,044 | —- | C] () – C:\ProgramData\{3D55D1F4-1059-11DC-B281-197056D89593}
[2009/01/17 19:22:35 | 000,055,856 | —- | C] () – C:\Windows\System32\vnetinst.dll
[2008/12/27 01:26:48 | 000,339,968 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/12/27 01:26:48 | 000,114,688 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2008/12/23 23:02:18 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2008/12/19 00:06:19 | 000,023,552 | —- | C] () – C:\Users\Alan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/17 19:20:45 | 000,004,224 | —- | C] () – C:\Windows\System32\drivers\NVStrap.sys
[2008/12/17 02:07:01 | 000,007,680 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2008/12/17 02:06:27 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
[2008/11/21 14:47:52 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/11/21 14:45:16 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/11/21 14:45:16 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/11/21 14:44:16 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/11/18 20:16:07 | 000,138,184 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/10/21 00:32:47 | 000,000,275 | —- | C] () – C:\Windows\MugE.ini
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/10/04 21:03:27 | 000,000,080 | —- | C] () – C:\Windows\SuperUtil.ini
[2008/09/16 00:11:54 | 000,279,712 | —- | C] () – C:\Windows\System32\drivers\atksgt.sys
[2008/09/16 00:11:53 | 000,025,888 | —- | C] () – C:\Windows\System32\drivers\lirsgt.sys
[2008/09/09 15:59:35 | 000,027,648 | —- | C] () – C:\Windows\System32\AVSredirect.dll
[2008/09/09 15:16:43 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/09/09 15:16:43 | 000,383,238 | —- | C] () – C:\Windows\System32\libmp3lame-0.dll
[2008/08/29 14:47:19 | 000,043,520 | —- | C] () – C:\Windows\System32\CmdLineExt03.dll
[2008/08/24 08:44:03 | 000,717,296 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/08/21 15:03:02 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2008/08/21 11:51:35 | 000,000,048 | —- | C] () – C:\Windows\R300.ini
[2008/08/21 10:52:49 | 000,000,184 | —- | C] () – C:\Windows\EViewer.INI
[2008/08/21 10:05:52 | 000,004,975 | R— | C] () – C:\Windows\c6501.ini
[2008/08/21 10:05:44 | 000,053,248 | —- | C] () – C:\Windows\System32\c6501rm.dll
[2008/08/21 08:39:54 | 000,009,511 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2008/08/21 08:39:40 | 000,010,288 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/08/21 08:20:35 | 000,000,083 | —- | C] () – C:\Windows\Crypkey.ini
[2008/08/21 08:20:31 | 000,018,432 | —- | C] () – C:\Windows\Setup_ck.dll
[2008/08/21 08:20:31 | 000,016,896 | —- | C] () – C:\Windows\System32\Ckldrv.sys
[2008/08/21 07:47:30 | 000,000,090 | —- | C] () – C:\Windows\TestSupp.ini
[2008/06/05 08:58:26 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/04/14 19:20:46 | 000,237,568 | —- | C] () – C:\Windows\glut32.dll
[2008/02/13 12:54:52 | 000,467,001 | R— | C] () – C:\Windows\System32\W3MKDE.DLL
[2008/02/13 12:54:52 | 000,061,499 | R— | C] () – C:\Windows\System32\W3MKDERC.DLL
[2006/11/02 18:22:58 | 000,030,256 | —- | C] () – C:\Windows\System32\PMMailSend.dll
[2006/11/02 18:21:56 | 000,050,736 | —- | C] () – C:\Windows\System32\KESIMapiStub.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/11/10 08:01:28 | 000,006,144 | —- | C] () – C:\Windows\System32\classxps.dll
[2005/11/10 08:01:24 | 000,397,312 | —- | C] () – C:\Windows\System32\ClassX.dll
[2005/02/27 14:44:56 | 000,393,216 | —- | C] () – C:\Windows\System32\jogl.dll
[2005/02/27 14:44:56 | 000,073,728 | —- | C] () – C:\Windows\System32\jogl_cg.dll
[1995/08/23 11:45:58 | 000,002,016 | —- | C] () – C:\Windows\Sg5w30.dll
[1995/08/23 11:45:54 | 000,214,899 | —- | C] () – C:\Windows\Aplib2.dll
[1995/08/23 11:45:42 | 000,034,144 | —- | C] () – C:\Windows\Aplib1.dll
[1995/08/23 11:45:40 | 000,006,784 | —- | C] () – C:\Windows\Accupage.dll

========== LOP Check ==========

[2010/02/05 10:57:37 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Auslogics
[2008/12/17 13:37:42 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\BitTyrant
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\ClearPlay Inc
[2008/12/17 16:40:28 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\DAEMON Tools
[2008/12/17 16:40:27 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\DAEMON Tools Lite
[2008/12/17 16:40:27 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\DAEMON Tools Pro
[2010/02/05 12:30:11 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Dexpot
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\EPSON
[2009/07/28 15:35:43 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\EssentialPIM
[2009/01/17 11:37:10 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\flightgear.org
[2009/01/17 11:37:18 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\fltk.org
[2009/02/21 02:17:09 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\GetRightToGo
[2009/01/19 00:37:07 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Graboid Inc
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\GrabPro
[2010/01/23 00:07:20 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\gtk-2.0
[2009/07/28 15:13:27 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\HotSync
[2009/02/06 01:18:48 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\IObit
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\KESI
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Leadertech
[2008/12/17 01:47:51 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mobipocket
[2009/07/28 15:34:48 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Open Source Applications Foundation
[2010/01/02 01:44:11 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\OpenDNS Updater
[2008/12/17 01:47:52 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\OpenOffice.org
[2008/12/17 01:48:01 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Orbit
[2009/07/28 15:34:47 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Python-Eggs
[2009/07/09 13:05:08 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\QuotePad
[2009/11/16 00:44:10 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\RapidTyping
[2010/01/14 18:41:15 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\RFB&&D; Download Manager
[2009/12/30 23:03:22 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\SanDisk
[2008/12/17 01:49:17 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\SecondLife
[2009/01/18 23:52:53 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Spacejock Software
[2009/07/28 15:37:33 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\TaskCoach
[2009/04/10 22:51:55 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Thunderbird
[2009/07/09 13:02:01 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\TreeDBNotes 3
[2009/07/04 00:23:06 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\uqm
[2010/02/10 23:46:28 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\uTorrent
[2008/12/17 01:49:18 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\XRay Engine
[2008/12/17 01:47:29 | 000,000,000 | —D | M] – C:\Users\Guest\AppData\Roaming\BitTyrant
[2010/02/10 21:02:48 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >


Extras log (from OLT):

OTL Extras logfile created on: 2/11/2010 12:07:15 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Alan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): c:\pagefile.sys 4987 4987 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 278.56 Gb Total Space | 116.06 Gb Free Space | 41.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.53 Gb Total Space | 19.44 Gb Free Space | 99.55% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALAN-PC
Current User Name: Alan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12C52E84-12D6-45F1-9347-24C50E4B810E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BB862AD4-BEA7-4B54-A454-4E9670BB5168}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0501640C-19CF-49BF-9B57-8A8DFBA7E2F6}" = protocol=6 | dir=in | app=c:\program files\sightspeed\sightspeed.exe |
"{2021FBED-B9C1-4E1B-8094-20E64FE44880}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{203B7D2A-3D40-4AB1-914B-3D4AD4DEA763}" = protocol=6 | dir=in | app=c:\program files\rockstar games\rockstar games social club\rgsclauncher.exe |
"{215FB159-6725-4B36-AC1C-1E951E495B3B}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{3394767A-6AB8-4723-BC1F-61BF98762B06}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
"{373C3B00-B9E6-430B-B836-F8C30D6F89DA}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{48D70861-B022-46A7-B868-AF086651277A}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{5A8AF53D-16A1-4B3C-9896-E69EB03F2018}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{60B08A3E-BAE8-4A02-892C-50AE4C9668EE}" = protocol=6 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{873F490B-07A6-46DC-A185-9CC54A00CDA7}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{884F0362-1E6E-439E-BEDE-4B5DA28C0B65}" = protocol=6 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{91AAD5B1-2901-46B9-AA83-4966BB6402EF}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{96E95352-3143-41E7-9826-6B9EE7B926B5}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{A3071996-ABFC-4500-ACD1-BF8B312B4E76}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A3523C51-99CA-49D6-9E6D-9FAE24C7D95B}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{A6ACF641-D843-40AA-9EED-00431BFBE660}" = protocol=17 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{A84CAE42-4882-46D7-A15C-13DA3997620D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A85D5E4E-2BE2-4C5C-AED8-5FB48FCB2BA4}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{B0DA0CE7-33C1-457F-A6CC-6D5A9145EBBE}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{B215949A-BAB1-4704-AA52-2E9BE93B5155}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{B28205A9-0833-4718-B4AE-8412ADC96FAA}" = protocol=17 | dir=in | app=c:\program files\sightspeed\sightspeed.exe |
"{B780CFE9-9B4A-44BF-BD25-B4B3A77700F7}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{C2EBAE21-1817-44BC-9526-5796E40D7C4B}" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{C46ABB1C-2F7F-44CC-9BDE-B4BC1749AE98}" = protocol=17 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{C812FB58-CC81-47FA-8346-921EBA914D68}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{D2EF0059-CA8E-4A5D-BF8A-F46472D36932}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E99CF679-6A7B-4C97-BEEC-2D6A54BF33C5}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{EA7D5ECB-F200-4FE5-B022-8B4ABE046036}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{FC5DF286-0D6E-4844-841B-5947EFB82AAD}" = protocol=17 | dir=in | app=c:\program files\rockstar games\rockstar games social club\rgsclauncher.exe |
"TCP Query User{01A29EE2-7D99-44C1-B6FB-6E2A34C2E1BA}C:\windows\system32\electricsheep.scr" = protocol=6 | dir=in | app=c:\windows\system32\electricsheep.scr |
"TCP Query User{08472FB2-0B64-484E-906D-978F60604AB7}C:\program files\bittyrant\azureus.exe" = protocol=6 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"TCP Query User{2EBC50D3-B54D-439D-B997-D1A0186F1E05}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"TCP Query User{383056D8-2463-4253-BC11-E84753FEBB62}C:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe" = protocol=6 | dir=in | app=c:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe |
"TCP Query User{6C9475AE-549C-45F3-B882-217701530F1C}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{745C77AB-30CD-4799-9BA9-51FCEE3213DB}C:\program files\bittyrant\azureus.exe" = protocol=6 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"TCP Query User{A517BD55-B918-4C7D-8B62-02C452AD0809}C:\dead space\dead space.exe" = protocol=6 | dir=in | app=c:\dead space\dead space.exe |
"TCP Query User{B03D41C5-505A-4A5A-B84B-AC835F26F486}C:\users\alan\desktop\racer064c\racer\racer.exe" = protocol=6 | dir=in | app=c:\users\alan\desktop\racer064c\racer\racer.exe |
"TCP Query User{B434085D-F493-4C40-B254-30090C05850C}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{CA19EEA6-197F-477F-BD7E-3A04ACEAAF9E}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{DD69E6D3-CCD4-4E8B-A306-507EF8E1E221}C:\users\alan\documents\alan's documents\secondlife\slvoice.exe" = protocol=6 | dir=in | app=c:\users\alan\documents\alan's documents\secondlife\slvoice.exe |
"TCP Query User{ED8EA372-5D8C-46F9-9FB2-18422CF96852}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{1AC244A5-6E19-46EC-8332-7FCAF27B461A}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{29181DAF-9BCA-4968-BA47-2C3E0ED31128}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{4A955AA3-BC5C-43B3-A5C7-ACE0074DA169}C:\program files\bittyrant\azureus.exe" = protocol=17 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"UDP Query User{4F7086B5-AE7F-4596-B031-03D1E56B17DF}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{64899064-0E59-45E1-8EA9-74DDD1FFB717}C:\users\alan\desktop\racer064c\racer\racer.exe" = protocol=17 | dir=in | app=c:\users\alan\desktop\racer064c\racer\racer.exe |
"UDP Query User{699BBA50-F773-4C86-97A9-D62C307A6131}C:\windows\system32\electricsheep.scr" = protocol=17 | dir=in | app=c:\windows\system32\electricsheep.scr |
"UDP Query User{7431AA80-4B92-46D2-BFB4-AC25EDFD9A6A}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{7FA76597-3AF3-4168-9F21-AD0DC15C4276}C:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe" = protocol=17 | dir=in | app=c:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe |
"UDP Query User{A8573DEA-9090-45C8-A27F-8388BA95413A}C:\program files\bittyrant\azureus.exe" = protocol=17 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"UDP Query User{D29BF2EF-E2B5-4A8F-B776-10B9C27AE7D2}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"UDP Query User{DC840F58-1D35-4530-BA41-569B80BC7BE5}C:\users\alan\documents\alan's documents\secondlife\slvoice.exe" = protocol=17 | dir=in | app=c:\users\alan\documents\alan's documents\secondlife\slvoice.exe |
"UDP Query User{EC62895D-05CC-4D36-9C62-D680C9861632}C:\dead space\dead space.exe" = protocol=17 | dir=in | app=c:\dead space\dead space.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03DE8444-C8D0-4C7E-9434-673D88498E7B}" = VoiceText ™
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1E9A9E08-0366-45EE-9B66-51852F8D9812}" = Open Workbench
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2174D448-F6A7-49EC-B42D-67FE626094E9}" = Kurzweil 1000 v.11
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{34A5E174-93FD-496D-8073-13F63128AED6}" = ZoomText 9.1
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{46CBBDF8-55B5-40DB-B459-7B848394309C}" = EPSON File Manager
"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8CCD293C-0563-4EB0-BFAF-F279B61A6F32}" = ClearPlay Easy Updates
"{8D48DDA6-D5D4-4858-A4F1-4952293E0201}" = RCA Pearl (Model TH11, TC11 Series) Firmware Update Utility
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware
"{A182077A-8D6B-4194-B48A-B4DC37C69907}" = RealSpeak Solo for UK English Emily
"{A3F60446-48FB-48A8-B5FC-BB3430AEF806}" = Diskeeper Lite
"{A53A11EA-0095-493F-86FA-A15E8A86A405}" = VMware Player
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC54E544-3E42-443C-A91D-A00A6974C592}" = NVIDIA PhysX v8.10.13
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AFB1DFA5-FB56-4C9F-97A0-1607BC14BC0C}" = Smartparts Desktop
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5749E57-AD4A-4B1B-ABC5-885FDBC286C9}" = D-Link AirPlus G Wireless LAN Adapter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D9140B72-FD9A-4650-8A24-03AC9827AAB8}" = Ai Squared Visual C++ Runtime
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E43ED0A0-C85E-40F0-807C-6A8A9D2FAEF3}_is1" = King's Bounty. The Legend (Remove Only)
"{E5D52570-5EF1-4576-A434-6CCD92268F0F}" = Google SketchUp 7
"{E622695B-3A22-4774-993D-318049488C0B}" = LDS Scriptures CD-ROM Resource Edition
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F17B8386-A74A-4E4E-A7DD-435372991E14}" = Microsoft Visual Basic PowerPacks 2.0
"{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4Musics MP3 Bitrate Changer 5.0_is1" = 4Musics MP3 Bitrate Changer 5.0
"7-Zip" = 7-Zip 4.57
"AbiWord2" = AbiWord 2.6.6
"AbiwordToolsPlugins" = AbiWord Tools Plugins
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity_is1" = Audacity 1.2.6
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner
"Celestia_is1" = Celestia 1.6.0
"Chandler" = Chandler 1.0.3
"CleanMem" = CleanMem
"C-Media C6501 Like Sound Driver" = C-Media CM6501 Like Sound Driver
"comtypes-py2.5" = Python 2.5 comtypes-0.5.2
"Crysis WARHEAD®" = Crysis WARHEAD®
"dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"EssentialPIM" = EssentialPIM
"Fireflies" = Fireflies Screensaver (remove only)
"Fraps" = Fraps
"Free Online TV Player_is1" = Free Online TV Player
"Freecorder Toolbar3.02" = Freecorder Toolbar 3.02 Application
"GetASFStream" = GetASFStream
"GPL Ghostscript 8.63" = GPL Ghostscript 8.63
"Holding Pattern Coach" = Holding Pattern Coach Screen Saver
"iDailyDiary_is1" = iDailyDiary 3.52
"JumpStart Advanced Preschool" = JumpStart Advanced Preschool
"JumpStart Advanced PreSchool Explore and Learn" = JumpStart Advanced PreSchool Explore and Learn
"JumpStart Art for Fun" = JumpStart Art for Fun
"JumpStart Languages" = JumpStart Languages
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LDS Gospel Resource" = LDS Gospel Resource
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MechWarrior 3" = MechWarrior 3
"Mechwarrior CD Patch" = Mechwarrior CD Patch 1.0
"Metacafe" = Metacafe
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"OpenDNS Updater" = OpenDNS Updater 2.2
"PIL-py2.5" = Python 2.5 PIL-1.1.6
"Privateer" = Privateer
"PROR" = Microsoft Office Professional 2007
"psyco-py2.5" = Python 2.5 psyco-1.6
"Punch! Home Design - AS3000" = Punch! Home Design - AS3000
"pywin32-py2.5" = Python 2.5 pywin32-212
"QuotePad_is1" = QuotePad 2.2
"RapidTyping" = RapidTyping
"RealCheckers_is1" = Real Checkers
"RFB&D; Download Manager_is1" = RFB&D; Download Manager
"RiftSpace" = RiftSpace
"RoughDraft" = RoughDraft 3.0
"SaverBeans Screensaver Pack" = SaverBeans Screensaver Pack 0.2
"Scribus [removed]" = Scribus [removed]
"SEO Note_is1" = SEO Note
"Silent Package Run-Time Sample" = EPSON SPR300 Reference Guide
"Sonar3_is1" = Sonar3
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"Stamina" = Stamina 2.5
"Streambox Vcr Suite_is1" = Streambox Vcr Suite 2
"SUPER ©" = SUPER © Version 2008.bld.33 (Sep 2, 2008)
"Task Coach_is1" = Task Coach 0.73.2
"The KMPlayer" = The KMPlayer (remove only)
"The Ur-Quan Masters" = The Ur-Quan Masters 0.6.2
"TreeDBNotes 3" = TreeDBNotes 3
"TypeFaster" = TypeFaster Typing Tutor
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WinAce Archiver" = WinAce Archiver
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"wxPython2.8-ansi-py25_is1" = wxPython [removed] (ansi) for Python 2.5
"X Plugin Manager" = X Plugin Manager 2.20 BETA 6
"x2_allinone_bonus_package_is1" = X² All In One Bonus Package 1.04
"yWriter5_is1" = yWriter5

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Sansa Updater" = Sansa Updater

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


I did try agian to run a complete scan with SuperAntiSpyware and this time it did not crash on me! It did detect an adware cookie which I removed. Would you like to see this log also?

My computer seems to be running better and does not seem to be slowing down or constantly loading. However it was worse at sometimes during the day then others. So I will need to check this over the next day to see if there are any other problems. I thought that if I do find it slowing down and loading a lot then I would check the current running processes and copy and paste it to a txt document. Would this be helpful at all?
Hi,

Sorry about those links.
Here are some good reading regarding P2P:
http://www.infoworld.com/d/security-centra…-p-id-theft-103
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

It did detect an adware cookie which I removed. Would you like to see this log also?

- Yes please.

I thought that if I do find it slowing down and loading a lot then I would check the current running processes and copy and paste it to a txt document.
Would this be helpful at all?

- Log them then post. Thanks.

–Next–

Right click OTL.exe then choose "Run as Administrator" to run the tool.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O3 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\..\Toolbar\ShellBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
–Next–

Have you used Mail clients before? Perhaps you can recognize these files?
C:\Windows\System32\PMMailSend.dll
C:\Windows\System32\KESIMapiStub.dll


Please go to the site below to scan the following files:
Virus Total

Click on Browse, and upload the following file for analysis or copy/paste the text below into the browse box:
C:\Windows\System32\PMMailSend.dll

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"

Repeat the procedure with the following files:
C:\Windows\System32\KESIMapiStub.dll
C:\ProgramData\{3D55D1F4-1059-11DC-B281-197056D89593}


Please post the results in your next reply.

To post in your next reply:
1. SuperAntiSpyware log.
2. OTL fix log.
3. Regarding the files.
4. Virus Total log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI