This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Incredibly Frustrating Virus

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently my computer has started redirecting my google searches to ones that are something like 'results2.google.com' etc etc
I have managed to stop it doing that, but firefox still often complains on start up that 'Firefox has detected that the server is redirecting the request for this address in a way that will never complete.'
I cannot access websites like Malwarebyes, or update my malwarebytes program or super antispyware and AVG and Spybot do not detect anything.

here is the HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:52:47 PM, on 24/03/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Mozilla Firefox 3.6 Beta 1\firefox.exe
C:\Program Files\Sony\Content Transfer\ContentTransfer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\valued customer\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.1; .NET CLR 3.5.30729; OfficeLiveConnector.1.4; OfficeLivePatch.1.3; .NET CLR 3.0.30729)" -"http://www.habbo.com.au/client"
O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-AU\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/…NPUplden-au.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1059820C-EEBF-478E-BC5B-60B4E048C9BA}: NameServer = 10.4.16.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1059820C-EEBF-478E-BC5B-60B4E048C9BA}: NameServer = 10.4.16.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1059820C-EEBF-478E-BC5B-60B4E048C9BA}: NameServer = 10.4.16.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: Symantec Eraser Service (EraserSvc10824) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe

–
End of file - 12783 bytes


Help would be much appreciated!

Thanks

Also, usually on my third attempt of running GMRE the computer blue screens
Hello, mysteryme
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.




  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized
OTL.Txt

OTL logfile created on: 27/03/2010 11:33:37 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\valued customer\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.44 Gb Total Space | 162.60 Gb Free Space | 56.37% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 93.35 Gb Free Space | 31.32% Space Free | Partition Type: NTFS
Drive E: | 9.65 Gb Total Space | 1.70 Gb Free Space | 17.64% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVID
Current User Name: valued customer
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/27 11:33:00 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\valued customer\Downloads\OTL.exe
PRC - [2010/03/21 19:41:59 | 000,508,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/21 19:41:58 | 000,617,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/03/21 19:41:57 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/21 19:41:55 | 000,710,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/21 19:41:54 | 001,086,744 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/20 21:21:22 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox 3.6 Beta 1\firefox.exe
PRC - [2010/03/17 23:27:11 | 011,952,304 | —- | M] (Mozilla Messaging) – C:\Program Files\Mozilla Thunderbird\thunderbird.exe
PRC - [2009/11/13 22:31:14 | 000,092,008 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/10/20 19:39:28 | 000,340,456 | —- | M] (Kaspersky Lab) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
PRC - [2009/09/16 07:28:52 | 000,204,848 | —- | M] () – C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2009/09/16 07:04:58 | 000,331,824 | —- | M] (AnchorFree Inc.) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2009/04/11 17:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/30 17:28:36 | 001,533,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/03/30 17:28:36 | 000,183,152 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2008/09/11 11:52:52 | 000,237,650 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\stacsv.exe
PRC - [2008/09/11 11:50:38 | 000,446,556 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008/07/11 17:51:32 | 000,423,200 | —- | M] (Sony Corporation) – C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
PRC - [2008/06/27 15:53:08 | 000,077,824 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe
PRC - [2008/04/28 16:26:44 | 000,599,344 | —- | M] (Validity Sensors, Inc.) – C:\Windows\System32\vfsFPService.exe
PRC - [2008/04/26 19:15:26 | 000,361,808 | —- | M] () – C:\Windows\SMINST\BLService.exe
PRC - [2008/03/18 16:27:12 | 000,013,312 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe
PRC - [2008/03/13 13:24:52 | 000,699,456 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpAgent.exe
PRC - [2008/03/13 13:24:52 | 000,302,144 | —- | M] (DigitalPersona, Inc.) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe


========== Modules (SafeList) ==========

MOD - [2010/03/27 11:33:00 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\valued customer\Downloads\OTL.exe
MOD - [2010/03/21 19:41:59 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
MOD - [2009/04/11 17:21:38 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (EraserSvc10824)
SRV - [2010/03/21 19:41:57 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/04 17:16:46 | 000,332,720 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2009/11/13 22:31:14 | 000,092,008 | —- | M] (TomTom) [Auto | Running] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2009/10/20 19:39:28 | 000,340,456 | —- | M] (Kaspersky Lab) [Auto | Running] – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe – (AVP)
SRV - [2009/09/25 12:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/09/16 07:29:04 | 000,057,640 | —- | M] () [On_Demand | Stopped] – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe – (HssTrayService)
SRV - [2009/09/16 07:28:52 | 000,204,848 | —- | M] () [Auto | Running] – C:\Program Files\Hotspot Shield\bin\openvpnas.exe – (HotspotShieldService)
SRV - [2009/09/16 07:04:58 | 000,331,824 | —- | M] (AnchorFree Inc.) [Auto | Running] – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe – (HssSrv)
SRV - [2009/03/30 17:28:36 | 001,533,808 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV - [2008/09/11 11:52:52 | 000,237,650 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\stacsv.exe – (STacSV)
SRV - [2008/06/27 15:53:08 | 000,077,824 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe – (AESTFilters)
SRV - [2008/04/28 16:26:44 | 000,599,344 | —- | M] (Validity Sensors, Inc.) [Auto | Running] – C:\Windows\System32\vfsFPService.exe – (vfsFPService)
SRV - [2008/04/26 19:15:26 | 000,361,808 | —- | M] () [Auto | Running] – C:\Windows\SMINST\BLService.exe – (Recovery Service for Windows)
SRV - [2008/03/18 16:27:12 | 000,013,312 | —- | M] (Agere Systems) [Auto | Running] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2008/03/13 13:24:52 | 000,302,144 | —- | M] (DigitalPersona, Inc.) [Auto | Running] – C:\Program Files\DigitalPersona\Bin\DpHostW.exe – (DpHost)
SRV - [2008/01/21 13:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2006/04/15 04:04:54 | 000,087,840 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.56.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/03/22 19:42:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files\Mozilla Firefox 3.6 Beta 1\components [2010/03/20 21:21:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3.6 Beta 1\plugins [2010/03/26 22:01:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.3\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/03/17 23:27:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.3\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010/03/25 21:56:43 | 000,000,000 | —D | M]

[2010/02/17 16:12:25 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Extensions
[2010/02/17 16:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\valued customer\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/07/19 19:38:22 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Extensions\[removed]
[2009/03/29 01:41:36 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Extensions\[removed]
[2010/03/25 21:07:32 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Firefox\Profiles\8w3hks3x.default\extensions
[2009/09/03 01:33:40 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\valued customer\AppData\Roaming\mozilla\Firefox\Profiles\8w3hks3x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/17 21:35:31 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Firefox\Profiles\8w3hks3x.default\extensions\[removed]
[2010/01/04 16:21:26 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Firefox\Profiles\8w3hks3x.default\extensions\[removed]
[2010/03/17 21:35:28 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\mozilla\Firefox\Profiles\8w3hks3x.default\extensions\staged-xpis
[2010/01/04 16:21:16 | 000,002,055 | —- | M] () – C:\Users\valued customer\AppData\Roaming\Mozilla\FireFox\Profiles\8w3hks3x.default\searchplugins\daemon-search.xml
[2009/11/05 20:54:01 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/03/30 21:10:38 | 000,279,888 | —- | M] (Musicnotes, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npmusicn.dll
[2009/03/10 09:30:50 | 005,817,072 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ScorchPDFWrapper.dll

O1 HOSTS File: ([2010/03/25 23:40:03 | 000,380,222 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 13123 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident\4.0; File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL; Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-AU\local\search.html ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: &Virtual; keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/…NPUplden-au.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~2\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~2\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Users\valued customer\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\valued customer\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/11 20:31:29 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 13:34:27 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 13:34:27 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/03/25 22:51:04 | 000,000,000 | —D | C] – C:\fixit
[2010/03/25 22:46:11 | 000,000,000 | —D | C] – C:\Users\valued customer\AppData\Roaming\J River
[2010/03/25 21:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2010/03/25 21:55:51 | 000,000,000 | —D | C] – C:\Program Files\Kaspersky Lab
[2010/03/25 21:55:20 | 000,311,312 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\klif.sys
[2010/03/25 21:47:59 | 000,000,000 | —D | C] – C:\Program Files\Kaspersky Internet Security
[2010/03/24 22:45:45 | 000,000,000 | —D | C] – C:\MGtools
[2010/03/24 20:05:13 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/03/24 20:05:11 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/03/24 20:05:11 | 000,000,000 | —D | C] – C:\Users\valued customer\AppData\Local\temp
[2010/03/24 19:48:26 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/03/24 18:27:50 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/24 18:27:47 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/24 18:27:38 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/24 18:23:49 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/03/24 17:35:27 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/03/24 17:35:27 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/03/24 17:35:27 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/03/24 17:35:17 | 000,000,000 | —D | C] – C:\ComboFix
[2010/03/21 19:41:59 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/03/14 16:43:53 | 001,640,400 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll.old
[2010/03/14 16:34:55 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2008/11/06 11:10:47 | 003,063,561 | —- | C] (Macromedia, Inc.) – C:\ProgramData\MobileTV.exe
[2008/11/06 11:10:47 | 002,989,660 | —- | C] (Macromedia, Inc.) – C:\ProgramData\DVD.exe
[2008/11/06 11:10:47 | 002,864,396 | —- | C] (Macromedia, Inc.) – C:\ProgramData\MPV.exe
[2008/11/06 11:10:46 | 002,331,174 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Karaoke.exe
[2008/11/06 11:10:46 | 002,231,606 | —- | C] (Macromedia, Inc.) – C:\ProgramData\Games.exe

========== Files - Modified Within 14 Days ==========

[2010/03/27 11:36:13 | 008,912,896 | -HS- | M] () – C:\Users\valued customer\NTUSER.DAT
[2010/03/27 11:32:47 | 057,871,315 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/03/27 11:29:56 | 000,000,948 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1428815032-1628162306-70752314-1003UA.job
[2010/03/27 11:29:16 | 000,694,870 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/03/27 11:29:16 | 000,602,994 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/03/27 11:29:16 | 000,107,066 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/03/27 11:29:05 | 000,035,845 | —- | M] () – C:\ProgramData\nvModes.001
[2010/03/27 11:28:53 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/27 11:28:50 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1428815032-1628162306-70752314-1003Core.job
[2010/03/26 22:02:29 | 000,035,845 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/03/26 22:00:32 | 000,000,020 | -HS- | M] () – C:\Users\valued customer\ntuser.ini
[2010/03/26 21:59:51 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/26 21:59:51 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/26 21:59:51 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/26 21:59:33 | 3186,577,408 | -HS- | M] () – C:\hiberfil.sys
[2010/03/26 07:40:15 | 000,001,076 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/03/26 07:40:11 | 000,524,288 | -HS- | M] () – C:\Users\valued customer\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/03/26 07:40:11 | 000,065,536 | -HS- | M] () – C:\Users\valued customer\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/03/26 07:40:07 | 003,853,686 | -H– | M] () – C:\Users\valued customer\AppData\Local\IconCache.db
[2010/03/25 23:40:03 | 000,380,222 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/03/25 21:57:27 | 000,108,059 | —- | M] () – C:\Windows\System32\drivers\klin.dat
[2010/03/25 21:57:27 | 000,095,259 | —- | M] () – C:\Windows\System32\drivers\klick.dat
[2010/03/25 21:55:21 | 000,311,312 | —- | M] (Kaspersky Lab) – C:\Windows\System32\drivers\klif.sys
[2010/03/25 21:16:22 | 000,000,036 | —- | M] () – C:\Users\valued customer\AppData\Local\housecall.guid.cache
[2010/03/24 22:47:51 | 000,000,000 | —- | M] () – C:\Windows\System32\settings.dat
[2010/03/24 20:03:03 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/03/24 18:49:22 | 000,128,336 | —- | M] () – C:\Users\valued customer\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/24 18:47:30 | 000,423,816 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/03/24 18:24:36 | 000,001,672 | —- | M] () – C:\Users\valued customer\Desktop\CCleaner.lnk
[2010/03/24 17:11:05 | 000,001,356 | —- | M] () – C:\Users\valued customer\AppData\Local\d3d9caps.dat
[2010/03/23 23:51:06 | 000,380,770 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.bak
[2010/03/23 22:23:13 | 000,106,496 | —- | M] () – C:\Users\valued customer\Desktop\March Tahlia Invoice.doc
[2010/03/21 19:42:00 | 000,242,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2010/03/21 19:41:59 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2010/03/21 19:41:59 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2010/03/21 19:41:55 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys

========== Files Created - No Company Name ==========

[2010/03/26 22:00:32 | 000,000,020 | -HS- | C] () – C:\Users\valued customer\ntuser.ini
[2010/03/25 21:57:27 | 000,108,059 | —- | C] () – C:\Windows\System32\drivers\klin.dat
[2010/03/25 21:57:27 | 000,095,259 | —- | C] () – C:\Windows\System32\drivers\klick.dat
[2010/03/25 21:16:22 | 000,000,036 | —- | C] () – C:\Users\valued customer\AppData\Local\housecall.guid.cache
[2010/03/24 22:47:51 | 000,000,000 | —- | C] () – C:\Windows\System32\settings.dat
[2010/03/24 18:24:36 | 000,001,672 | —- | C] () – C:\Users\valued customer\Desktop\CCleaner.lnk
[2010/03/24 17:49:06 | 3186,577,408 | -HS- | C] () – C:\hiberfil.sys
[2010/03/24 17:35:27 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/03/24 17:35:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/03/24 17:35:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/03/24 17:35:27 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/03/24 17:35:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/03/23 22:22:04 | 000,106,496 | —- | C] () – C:\Users\valued customer\Desktop\March Tahlia Invoice.doc
[2010/03/14 16:43:54 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2009/09/07 00:52:36 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2009/07/01 15:38:57 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/11 22:22:20 | 000,000,426 | —- | C] () – C:\Users\valued customer\AppData\Roaming\Poladroid prefs.plist
[2009/03/05 07:54:58 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/02/11 21:03:14 | 000,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2008/12/29 12:58:06 | 000,001,356 | —- | C] () – C:\Users\valued customer\AppData\Local\d3d9caps.dat
[2008/12/29 00:55:53 | 000,000,038 | —- | C] () – C:\Windows\System32\net32gdilib.dll
[2008/11/07 23:15:51 | 000,000,000 | —- | C] () – C:\Users\valued customer\AppData\Local\FnF4.txt
[2008/11/07 11:37:36 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/11/06 22:17:17 | 000,058,368 | —- | C] () – C:\Users\valued customer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/06 11:10:46 | 000,000,021 | —- | C] () – C:\ProgramData\hpqp.txt
[2008/10/31 04:46:12 | 000,000,000 | —- | C] () – C:\Users\valued customer\AppData\Local\QSwitch.txt
[2008/10/31 04:46:12 | 000,000,000 | —- | C] () – C:\Users\valued customer\AppData\Local\DSwitch.txt
[2008/10/31 04:46:12 | 000,000,000 | —- | C] () – C:\Users\valued customer\AppData\Local\AtStart.txt
[2008/08/24 06:18:51 | 000,000,247 | —- | C] () – C:\ProgramData\hpqp.ini
[2008/08/24 06:10:45 | 000,035,845 | —- | C] () – C:\ProgramData\nvModes.001
[2008/08/24 06:10:14 | 000,035,845 | —- | C] () – C:\ProgramData\nvModes.dat
[2008/08/24 05:41:45 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2008/08/24 05:40:53 | 000,003,072 | —- | C] () – C:\Windows\System32\716xCoInstaller.dll
[2008/08/11 21:08:25 | 000,000,384 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/01/14 17:47:06 | 000,099,712 | —- | C] () – C:\Windows\HPBroker.dll
[2007/11/15 10:17:34 | 000,204,800 | —- | C] () – C:\Windows\System32\CogentBioSDK.dll
[2006/11/02 23:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 18:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
[2001/11/15 07:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2009/03/31 19:14:43 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\BitDefender
[2008/11/07 16:26:38 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\Command & Conquer 3 Kane's Wrath
[2010/01/04 16:41:30 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\DAEMON Tools Lite
[2008/10/31 04:45:50 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\DigitalPersona
[2010/02/16 18:31:22 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\EarMaster
[2009/01/25 21:05:30 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\F-Secure
[2008/12/28 23:39:25 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\FMZilla
[2009/01/25 01:59:43 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\GrabPro
[2010/03/25 22:46:12 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\J River
[2009/10/02 00:12:30 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\LG Electronics
[2009/09/03 00:26:06 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\LimeWire
[2009/04/02 23:24:39 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\MRTalk
[2008/11/07 16:39:57 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\muvee Technologies
[2009/01/25 02:03:06 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\Orbit
[2009/01/27 19:22:05 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\Sony
[2009/09/22 19:00:03 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\stickies
[2010/01/11 23:35:22 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\SystemRequirementsLab
[2010/02/17 16:12:23 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\Thunderbird
[2009/10/03 13:12:40 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\tidysongs15.27F6A35B76E5883BF9E6FEE514586561E60595CA.1
[2009/07/19 19:38:21 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\TomTom
[2010/03/25 22:40:24 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\TuneUpMedia
[2010/03/01 20:24:16 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\uTorrent
[2009/12/28 18:17:16 | 000,000,000 | —D | M] – C:\Users\valued customer\AppData\Roaming\WildTangent
[2010/03/26 07:40:15 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2005/12/08 19:23:58 | 002,039,808 | —- | M] () – C:\OTwo.exe


< MD5 for: AGP440.SYS >
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\ERDNT\cache\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 20:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/08/11 18:13:57 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008/08/11 18:13:57 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\ERDNT\cache\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 13:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 13:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 20:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/08/11 18:13:57 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 20:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 20:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 20:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/01/13 16:30:08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/21 13:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 13:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 13:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 20:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/11 17:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\ERDNT\cache\netlogon.dll
[2009/04/11 17:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 17:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 13:24:05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 20:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 13:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 13:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 13:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/21 13:24:50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 17:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\ERDNT\cache\scecli.dll
[2009/04/11 17:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 17:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %SYSTEMDRIVE%\*.exe >
[2005/12/08 19:23:58 | 002,039,808 | —- | M] () – C:\OTwo.exe


< MD5 for: AGP440.SYS >
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\ERDNT\cache\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\drivers\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/21 13:23:01 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 20:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/08/11 18:13:57 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_4c9c5a00\atapi.sys
[2008/08/11 18:13:57 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=0D83C87A801A3DFCD1BF73893FE7518C – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_dd1bb97e219e87cb\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\ERDNT\cache\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 17:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/21 13:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/21 13:23:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 20:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/08/11 18:13:57 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=96DC4E1A9F90CCD489950A8935425C59 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_dda556493abc2795\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 20:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 20:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 20:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/01/13 16:30:08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/21 13:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\drivers\iaStorV.sys
[2008/01/21 13:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/21 13:23:23 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 20:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/11 17:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\ERDNT\cache\netlogon.dll
[2009/04/11 17:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 17:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/21 13:24:05 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 20:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/21 13:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\drivers\nvstor.sys
[2008/01/21 13:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/21 13:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/21 13:24:50 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2009/04/11 17:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\ERDNT\cache\scecli.dll
[2009/04/11 17:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 17:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 398 bytes -> C:\Windows\System32\msln.exe:9ce190833d3d7f908d37ad769c2b4070
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >








Extras.Txt

OTL Extras logfile created on: 27/03/2010 11:33:37 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\valued customer\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.44 Gb Total Space | 162.60 Gb Free Space | 56.37% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 93.35 Gb Free Space | 31.32% Space Free | Partition Type: NTFS
Drive E: | 9.65 Gb Total Space | 1.70 Gb Free Space | 17.64% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVID
Current User Name: valued customer
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox 3.6 Beta 1\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Free Music Zilla\FMZilla.exe" = C:\Program Files\Free Music Zilla\FMZilla.exe:*:Enabled:FMZilla – ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{6A57CA51-6461-41CE-AB6F-9040CB7A8F94}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A48D6E71-993A-4C0A-835E-32034B01B8A7}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08A61B86-4100-4CEE-9C71-8C6693B52707}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{0B6CB059-457E-442F-B2B4-E0465B084BDB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{28F075D3-6594-4703-A99D-1C3517FDC99A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{4165849B-26EB-4CEC-9DBD-F63485F262A7}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{42A53992-F380-4EF9-9AF9-6444B710EF90}" = protocol=17 | dir=in | app=c:\program files\sony\media manager for walkman\mediamanager.exe |
"{51F9C9D9-EB3C-41A4-B204-DBA34BA12DEB}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{545F3651-0E47-457A-A236-4773042AC940}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{570A323A-459C-4756-A5FF-B3E523AB4A83}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{5EF1A85A-F1CC-422A-959E-FC9C586A0D3E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{6FE86274-66F4-4F35-9DDA-EF6F2381E7AB}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{863E88C6-741F-4255-8486-C23F2C4E45DB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{971592D6-528D-429E-ABFE-BBE399B8C94E}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{9C44A6B7-2AF1-4E08-AB62-6B0ED0D45C70}" = protocol=6 | dir=in | app=c:\program files\sony\media manager for walkman\mediamanager.exe |
"{A7C6E2D9-BE21-442F-8D00-277AB5B6710D}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{A857A18D-C9CD-473B-AD14-25FD0EB0D2D5}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{AAFD1DBA-C506-4AF0-B219-6E2211560ACC}" = protocol=6 | dir=in | app=d:\warcraft iii\frozen throne.exe |
"{B10E1718-9EF6-4973-B732-8A657A2799C9}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{C82268C0-E8B4-4BA4-9FE2-73A51DB5EF32}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C998505D-ECF2-4E1D-BF89-C94A26573852}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D84055FF-8250-4F03-83AD-CBFF33A78268}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{D91730BC-2F91-4C77-9890-18842FC5C24E}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{EDE76C1A-8B86-4271-81E3-4898A20D1C49}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F220C7AB-A9CF-4E57-8CB0-268E20FFA654}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F47EFF09-8F85-416A-9C13-D57568EAA5CC}" = protocol=17 | dir=in | app=d:\warcraft iii\frozen throne.exe |
"{F70860D8-E113-42DF-AEE8-F1EA6678F765}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{FB6866B3-3372-4D9D-BCF1-63A06A18D2A9}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{12FCC324-13F8-429C-99E8-FC21B339E550}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{24C282EC-BC64-4C25-9B8D-BFF96030B637}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{31BB8403-8F7C-4B68-8A47-40F495F0A3C4}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"TCP Query User{416D552A-AB62-4095-8CFB-1864128E5AE0}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{479FF59E-6805-4EE8-9F68-A87D45B533AD}C:\program files\hobbyist software\off-helper\off-helper.exe" = protocol=6 | dir=in | app=c:\program files\hobbyist software\off-helper\off-helper.exe |
"TCP Query User{5B0FC2A7-3019-4A27-AAEE-6A65B40411C6}C:\program files\valve\hl.exe" = protocol=6 | dir=in | app=c:\program files\valve\hl.exe |
"TCP Query User{5F0153F5-E479-4F25-9C8C-C3F38D1CBBA3}C:\program files\soulseekns\slsk.exe" = protocol=6 | dir=in | app=c:\program files\soulseekns\slsk.exe |
"TCP Query User{8B8648A1-F370-4D93-A623-E13CBB49882D}C:\program files\free music zilla\fmzilla.exe" = protocol=6 | dir=in | app=c:\program files\free music zilla\fmzilla.exe |
"TCP Query User{AE762DE8-0377-4865-8944-2D274C33EBBE}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{BD4F6071-B555-47B9-9D93-9997C7B0D1FA}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{CE47E2D7-62DC-45E8-AC52-907EC2D2281F}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{02FD43EA-049B-4E3D-AD4A-E67F19E42475}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{2D6DBCEC-F5C6-46C3-B8BF-4CC1F4274B35}C:\program files\free music zilla\fmzilla.exe" = protocol=17 | dir=in | app=c:\program files\free music zilla\fmzilla.exe |
"UDP Query User{37238CD9-7E5C-447A-B5FE-57B8D8DBC5CB}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{378AD1A9-2CD7-4122-9E9B-E234CDC75109}C:\program files\hobbyist software\off-helper\off-helper.exe" = protocol=17 | dir=in | app=c:\program files\hobbyist software\off-helper\off-helper.exe |
"UDP Query User{45C4EDE7-A0ED-4B36-9087-7F6DA3FB6B46}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{6CDA6A6B-40C8-427F-8897-A1555072F300}C:\program files\microsoft games\age of empires iii\age3.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"UDP Query User{7245E5B9-0AD7-4225-8E01-D40FFA994B94}C:\program files\valve\hl.exe" = protocol=17 | dir=in | app=c:\program files\valve\hl.exe |
"UDP Query User{857A9BF8-DBAF-4DC0-B825-D86DC08C3296}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{AC0B82F7-D3AB-484E-8978-0E345668F867}C:\program files\soulseekns\slsk.exe" = protocol=17 | dir=in | app=c:\program files\soulseekns\slsk.exe |
"UDP Query User{AD80425F-5D36-4C6D-8D66-909966A3F6C3}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{C15D0214-A638-43A2-9F53-4A2EB33EE227}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6204
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0A8C7880-F199-4807-ABD4-6E695B71A3D7}" = e-tax 2009
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 18
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{340F521E-3576-4E1A-B75C-EB0ACF751379}" = HP Wireless Assistant
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{34DAFDEC-A4B4-488A-A5CD-C91975A6F083}" = MediaRing Talk
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}" = Windows 7 Upgrade Advisor Beta
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}" = Microsoft SQL Server Native Client
"{51E5C397-0AA0-48DD-9CB6-7259AFFDFB0A}" = HP Easy Setup - Frontend
"{535A4F3D-06C3-446C-A2AA-DBB71EC192B8}" = LightScribe Applications
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{567E8236-C414-4888-8211-3D61608D57AE}" = Validity Sensors software
"{5A6ED905-D19D-4954-8499-0DAF386460F7}" = Media Manager for WALKMAN 1.2
"{5F4B558D-8AEB-4DEE-AAB3-C00D1D9A86BA}" = Sibelius Scorch (Firefox, Opera, Netscape only)
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90BC0F01-9D99-4686-AC14-2EEC0246FB84}" = Poladroid
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AAD72731-807A-4B79-AE05-9190B7002B7B}" = ProtectSmart Hard Drive Protection
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.1
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AE72E414-0935-4AC8-B7D6-12E3039BEC13}" = DigitalPersona Personal 3.0.1
"{AFA9D219-A7FD-4240-8793-E5C7C9D715F4}" = IKEA Home Planner
"{B16DA0F8-26BC-4FFC-9363-1D9F3E6C3E21}" = HP Customer Experience Enhancements
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B8169E45-8E23-430B-91D1-EC64540C8ED0}" = HP User Guides 0103
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}" = Google Talk Plugin
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C0D2F614-5CE5-4DCB-8678-E5C9AF7044F8}" = Microsoft SQL Server VSS Writer
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C6AA3FB7-804F-4808-AD91-B62D6ED9B788}" = Windows Vista Upgrade Advisor
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB16F6D9-EBC9-4BC6-B917-7AF53E99C067}" = LightScribe System Software [removed]
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"3B7076EB3C51070DE9D6902E9696507D9B471345" = Windows Driver Package - NETGEAR Inc. (RTLWUSB) Net (03/27/2006 5.1213.06.0327)
"5D38134BF8A10D640B30E6B014EECDBC5F881E3D" = Windows Driver Package - ENE (enecir) HIDClass (04/29/2008 2.5.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AOL Toolbar" = AOL Toolbar 5.0
"AudibleDownloadManager" = Audible Download Manager
"AVerMedia MCE Encoder x86" = AVerMedia MCE Encoder x86 3.0.1.0
"AVG9Uninstall" = AVG Free 9.0
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CCleaner" = CCleaner
"Classicsonline_DLM" = Classicsonline
"CueCard" = CueCard (remove only)
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"EADM" = EA Download Manager
"EarMaster Essential 5_is1" = EarMaster Essential 5
"Free Music Zilla_is1" = Free Music Zilla
"HijackThis" = HijackThis 2.0.2
"HotspotShield" = Hotspot Shield 1.30
"HP MiniCard Hybrid TV" = HP MiniCard Hybrid TV 1.3.0.58
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
"Mozilla Thunderbird (3.0.3)" = Mozilla Thunderbird (3.0.3)
"Musicnotes Player_is1" = Musicnotes Player V1.23.2
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Off-Helper_is1" = Off-Helper 1.10
"osu!" = osu!
"Picasa 3" = Picasa 3
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"SmartMusic 2010" = SmartMusic 2010
"Soulseek2" = SoulSeek 157 NS 13e
"ST6UNST #1" = Hazard Perception Test Demo
"Steam App 10180" = Call of Duty: Modern Warfare 2
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Stickies 6.7a" = Stickies 6.7a
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"System Explorer_is1" = System Explorer 1.5
"SystemRequirementsLab" = System Requirements Lab
"TomTom HOME" = TomTom HOME 2.7.3.1894
"TuneUpMedia" = TuneUp Companion 1.6.4
"VLC media player" = VLC media player 0.9.8a
"Warcraft III" = Warcraft III
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 24/03/2010 2:50:36 AM | Computer Name = David | Source = WinMgmt | ID = 10
Description =

Error - 24/03/2010 3:20:14 AM | Computer Name = David | Source = VSS | ID = 8194
Description =

Error - 24/03/2010 3:39:29 AM | Computer Name = David | Source = Application Error | ID = 1000
Description = Faulting application crjh9c4n.exe, version 1.0.15.15281, time stamp
0x4b2763f0, faulting module crjh9c4n.exe, version 1.0.15.15281, time stamp 0x4b2763f0,
exception code 0xc0000005, fault offset 0x0000c4b1, process id 0xfa4, application
start time 0x01cacb249aa9550d.

Error - 24/03/2010 3:44:20 AM | Computer Name = David | Source = Perflib | ID = 1010
Description =

Error - 24/03/2010 3:48:21 AM | Computer Name = David | Source = WinMgmt | ID = 10
Description =

Error - 24/03/2010 4:05:32 AM | Computer Name = David | Source = Application Error | ID = 1000
Description = Faulting application crjh9c4n.exe, version 1.0.15.15281, time stamp
0x4b2763f0, faulting module crjh9c4n.exe, version 1.0.15.15281, time stamp 0x4b2763f0,
exception code 0xc0000005, fault offset 0x0000c4b1, process id 0x4d0, application
start time 0x01cacb2879e350b9.

Error - 24/03/2010 4:49:09 AM | Computer Name = David | Source = Application Error | ID = 1000
Description = Faulting application vfsFPService.exe, version 2008.427.2153.41, time
stamp 0x4815591c, faulting module vfsFPService.exe, version 2008.427.2153.41, time
stamp 0x4815591c, exception code 0xc0000005, fault offset 0x00024b84, process id
0x6c0, application start time 0x01cacb26388f4b79.

Error - 24/03/2010 4:51:55 AM | Computer Name = David | Source = WinMgmt | ID = 10
Description =

Error - 24/03/2010 5:10:57 AM | Computer Name = David | Source = WinMgmt | ID = 10
Description =

Error - 24/03/2010 5:46:39 AM | Computer Name = David | Source = WinMgmt | ID = 10
Description =

[ DigitalPersona Pro Events ]
Error - 4/01/2009 4:09:36 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 31/01/2009 9:57:46 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 31/01/2009 10:03:26 PM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 30/06/2009 6:21:44 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 28/10/2009 12:28:30 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 1/11/2009 3:52:34 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 11/11/2009 12:09:41 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 9/01/2010 4:50:37 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 9/01/2010 4:50:39 AM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

Error - 12/02/2010 8:32:36 PM | Computer Name = David | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

[ Media Center Events ]
Error - 8/03/2009 2:08:29 AM | Computer Name = David | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

[ System Events ]
Error - 25/03/2010 3:13:04 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2010 3:13:04 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2010 5:40:17 AM | Computer Name = David | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.0.2 for the Network Card with network address
0016EABD5ADC has been denied by the DHCP server 10.0.0.138 (The DHCP Server sent
a DHCPNACK message).

Error - 25/03/2010 5:41:11 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2010 5:41:11 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2010 6:50:30 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2010 6:54:24 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 25/03/2010 6:54:24 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 26/03/2010 7:01:13 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =

Error - 26/03/2010 7:01:13 AM | Computer Name = David | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Hi,


  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.







Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
Hi,

the log for:

TDSSKiller]

16:25:05:492 5732 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
16:25:05:492 5732 ================================================================================
16:25:05:492 5732 SystemInfo:

16:25:05:492 5732 OS Version: 6.0.6002 ServicePack: 2.0
16:25:05:492 5732 Product type: Workstation
16:25:05:492 5732 ComputerName: DAVID
16:25:05:492 5732 UserName: valued customer
16:25:05:492 5732 Windows directory: C:\Windows
16:25:05:492 5732 Processor architecture: Intel x86
16:25:05:492 5732 Number of processors: 2
16:25:05:492 5732 Page size: 0x1000
16:25:05:507 5732 Boot type: Normal boot
16:25:05:507 5732 ================================================================================
16:25:05:507 5732 UnloadDriverW: NtUnloadDriver error 2
16:25:05:507 5732 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
16:25:06:381 5732 wfopen_ex: Trying to open file C:\Windows\system32\config\system
16:25:06:412 5732 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
16:25:06:412 5732 wfopen_ex: Trying to KLMD file open
16:25:06:412 5732 wfopen_ex: File opened ok (Flags 2)
16:25:06:412 5732 wfopen_ex: Trying to open file C:\Windows\system32\config\software
16:25:06:412 5732 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
16:25:06:412 5732 wfopen_ex: Trying to KLMD file open
16:25:06:412 5732 wfopen_ex: File opened ok (Flags 2)
16:25:06:412 5732 Initialize success
16:25:06:412 5732
16:25:06:412 5732 Scanning Services …
16:25:07:988 5732 Raw services enum returned 481 services
16:25:08:003 5732
16:25:08:003 5732 Scanning Kernel memory …
16:25:08:003 5732 Devices to scan: 2
16:25:08:003 5732
16:25:08:003 5732 Driver Name: atapi
16:25:08:003 5732 IRP_MJ_CREATE : 8ACF4140
16:25:08:003 5732 IRP_MJ_CREATE_NAMED_PIPE : 8263DA22
16:25:08:003 5732 IRP_MJ_CLOSE : 8ACF4140
16:25:08:003 5732 IRP_MJ_READ : 8263DA22
16:25:08:003 5732 IRP_MJ_WRITE : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_EA : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_EA : 8263DA22
16:25:08:003 5732 IRP_MJ_FLUSH_BUFFERS : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_VOLUME_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_VOLUME_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_DIRECTORY_CONTROL : 8263DA22
16:25:08:003 5732 IRP_MJ_FILE_SYSTEM_CONTROL : 8263DA22
16:25:08:003 5732 IRP_MJ_DEVICE_CONTROL : 8ACE2A5A
16:25:08:003 5732 IRP_MJ_INTERNAL_DEVICE_CONTROL : 8ACE2A2C
16:25:08:003 5732 IRP_MJ_SHUTDOWN : 8263DA22
16:25:08:003 5732 IRP_MJ_LOCK_CONTROL : 8263DA22
16:25:08:003 5732 IRP_MJ_CLEANUP : 8263DA22
16:25:08:003 5732 IRP_MJ_CREATE_MAILSLOT : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_SECURITY : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_SECURITY : 8263DA22
16:25:08:003 5732 IRP_MJ_POWER : 8ACE2A88
16:25:08:003 5732 IRP_MJ_SYSTEM_CONTROL : 8ACEFB70
16:25:08:003 5732 IRP_MJ_DEVICE_CHANGE : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_QUOTA : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_QUOTA : 8263DA22
16:25:08:003 5732 C:\Windows\system32\drivers\atapi.sys - Verdict: 1
16:25:08:003 5732
16:25:08:003 5732 Driver Name: atapi
16:25:08:003 5732 IRP_MJ_CREATE : 8ACF4140
16:25:08:003 5732 IRP_MJ_CREATE_NAMED_PIPE : 8263DA22
16:25:08:003 5732 IRP_MJ_CLOSE : 8ACF4140
16:25:08:003 5732 IRP_MJ_READ : 8263DA22
16:25:08:003 5732 IRP_MJ_WRITE : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_EA : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_EA : 8263DA22
16:25:08:003 5732 IRP_MJ_FLUSH_BUFFERS : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_VOLUME_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_VOLUME_INFORMATION : 8263DA22
16:25:08:003 5732 IRP_MJ_DIRECTORY_CONTROL : 8263DA22
16:25:08:003 5732 IRP_MJ_FILE_SYSTEM_CONTROL : 8263DA22
16:25:08:003 5732 IRP_MJ_DEVICE_CONTROL : 8ACE2A5A
16:25:08:003 5732 IRP_MJ_INTERNAL_DEVICE_CONTROL : 8ACE2A2C
16:25:08:003 5732 IRP_MJ_SHUTDOWN : 8263DA22
16:25:08:003 5732 IRP_MJ_LOCK_CONTROL : 8263DA22
16:25:08:003 5732 IRP_MJ_CLEANUP : 8263DA22
16:25:08:003 5732 IRP_MJ_CREATE_MAILSLOT : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_SECURITY : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_SECURITY : 8263DA22
16:25:08:003 5732 IRP_MJ_POWER : 8ACE2A88
16:25:08:003 5732 IRP_MJ_SYSTEM_CONTROL : 8ACEFB70
16:25:08:003 5732 IRP_MJ_DEVICE_CHANGE : 8263DA22
16:25:08:003 5732 IRP_MJ_QUERY_QUOTA : 8263DA22
16:25:08:003 5732 IRP_MJ_SET_QUOTA : 8263DA22
16:25:08:034 5732 C:\Windows\system32\drivers\atapi.sys - Verdict: 1
16:25:08:034 5732
16:25:08:034 5732 Completed
16:25:08:034 5732
16:25:08:034 5732 Results:
16:25:08:034 5732 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
16:25:08:034 5732 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
16:25:08:034 5732 File objects infected / cured / cured on reboot: 0 / 0 / 0
16:25:08:034 5732
16:25:08:034 5732 fclose_ex: Trying to close file C:\Windows\system32\config\system
16:25:08:034 5732 fclose_ex: Trying to close file C:\Windows\system32\config\software
16:25:08:050 5732 KLMD(ARK) unloaded successfully


however I cannot get GMER to work, it stops working with this error every time

Problem signature:
Problem Event Name: APPCRASH
Application Name: 37d2lmtd.exe
Application Version: 1.0.15.15281
Application Timestamp: 4b2763f0
Fault Module Name: 37d2lmtd.exe
Fault Module Version: 1.0.15.15281
Fault Module Timestamp: 4b2763f0
Exception Code: c0000005
Exception Offset: 0000c4b1
OS Version: 6.0.6002.2.2.0.768.3
Locale ID: 3081
Additional Information 1: 92b2
Additional Information 2: 1271210c068084a54168c733d75772e6
Additional Information 3: 6db5
Additional Information 4: 3cb7a97e5074fe75ba618a49cd1fab4a

Read our privacy statement:
http://go.microsoft.com/fwlink/?linkid=501…mp;clcid=0x0409
Hi, Looks like you ran Combofix. Have a look if you can find C:\Combofix.txt and post back with the content of the logfile.
ComboFix 10-03-23.03 - valued customer 24/03/2010 19:53:21.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3038.2148 [GMT 11:00]
Running from: c:\users\[removed]\Downloads\fixit.exe
AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\$recycle.bin\S-1-5-21-1428815032-1628162306-70752314-500
c:\$recycle.bin\S-1-5-21-2010075864-2896424615-16003732-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
D:\resycled
E:\resycled

.
((((((((((((((((((((((((( Files Created from 2010-02-24 to 2010-03-24 )))))))))))))))))))))))))))))))
.

2010-03-24 09:02 . 2010-03-24 09:03 ——– d—–w- c:\users\valued customer\AppData\Local\temp
2010-03-24 09:02 . 2010-03-24 09:02 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-24 07:27 . 2010-01-07 05:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-24 07:27 . 2010-01-07 05:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-24 07:27 . 2010-03-24 08:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-24 07:23 . 2010-03-24 07:24 ——– d—–w- c:\program files\CCleaner
2010-03-24 06:35 . 2010-03-24 08:48 ——– d—–w- C:\ComboFix
2010-03-21 08:41 . 2010-03-21 08:41 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-14 05:34 . 2010-03-23 13:45 ——– d—–w- c:\program files\Spyware Doctor
2010-03-10 05:20 . 2010-02-20 23:06 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-03-10 05:20 . 2010-02-20 23:05 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-03-10 05:20 . 2010-02-20 20:53 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-26 09:34 . 2010-02-26 09:34 15416 —-a-w- c:\windows\system32\HPMDPCoInst.dll
2010-02-26 09:33 . 2010-02-26 09:33 33848 —-a-w- c:\windows\system32\drivers\Accelerometer.sys
2010-02-26 06:17 . 2008-06-10 23:47 9022288 —-a-w- c:\users\valued customer\AppData\Roaming\TomTom\HOME\Profiles\rys8n5zh.default\extensions\[removed]\8-010-9369-1.dll
2010-02-24 02:49 . 2010-01-23 09:26 2048 —-a-w- c:\windows\system32\tzres.dll
2010-02-24 02:48 . 2010-01-25 12:00 471552 —-a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 02:48 . 2010-01-25 12:00 471552 —-a-w- c:\windows\system32\secproc.dll
2010-02-24 02:48 . 2010-01-25 08:21 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 02:48 . 2010-01-25 08:21 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 02:48 . 2010-01-25 08:21 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 02:48 . 2010-01-25 12:00 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 02:48 . 2010-01-25 12:00 152064 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 02:48 . 2010-01-25 11:58 332288 —-a-w- c:\windows\system32\msdrm.dll
2010-02-24 02:48 . 2010-01-25 08:21 518144 —-a-w- c:\windows\system32\RMActivate.exe
2010-02-24 02:47 . 2010-01-06 15:39 1696256 —-a-w- c:\windows\system32\gameux.dll
2010-02-24 02:47 . 2010-01-06 15:38 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2010-02-24 02:47 . 2010-01-06 13:30 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-24 08:49 . 2008-08-11 08:21 1076 —-a-w- c:\windows\bthservsdp.dat
2010-03-24 07:49 . 2010-02-21 02:59 ——– d—–w- c:\program files\Steam
2010-03-24 07:49 . 2008-10-30 17:46 128336 —-a-w- c:\users\valued customer\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-24 07:48 . 2008-08-23 19:10 35845 —-a-w- c:\programdata\nvModes.dat
2010-03-24 07:28 . 2008-11-18 07:57 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-03-24 06:11 . 2008-12-29 01:58 1356 —-a-w- c:\users\valued customer\AppData\Local\d3d9caps.dat
2010-03-24 05:22 . 2009-09-01 13:21 117760 —-a-w- c:\users\valued customer\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-22 13:16 . 2009-09-06 13:51 ——– d—–w- c:\users\valued customer\AppData\Roaming\Skype
2010-03-22 13:12 . 2009-09-06 13:52 ——– d—–w- c:\users\valued customer\AppData\Roaming\skypePM
2010-03-22 11:12 . 2009-10-03 02:34 ——– d—–w- c:\users\valued customer\AppData\Roaming\TuneUpMedia
2010-03-21 08:42 . 2009-09-10 11:10 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-21 08:41 . 2009-09-10 11:10 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-21 08:41 . 2009-09-10 11:10 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-20 10:21 . 2009-11-03 03:02 ——– d—–w- c:\program files\Mozilla Firefox 3.6 Beta 1
2010-03-17 12:27 . 2009-03-26 11:59 ——– d—–w- c:\program files\Mozilla Thunderbird
2010-03-10 13:38 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-03-10 11:35 . 2009-10-03 02:34 ——– d—–w- c:\programdata\TuneUpMedia
2010-03-05 23:40 . 2010-02-21 02:59 ——– d—–w- c:\program files\Common Files\Steam
2010-03-01 09:24 . 2008-12-28 13:31 ——– d—–w- c:\users\valued customer\AppData\Roaming\uTorrent
2010-02-26 09:34 . 2008-08-07 03:42 25656 —-a-w- c:\windows\system32\drivers\hpdskflt.sys
2010-02-26 09:34 . 2008-03-18 23:24 26168 —-a-w- c:\windows\system32\hpservice.exe
2010-02-26 09:34 . 2008-04-17 16:50 15416 —-a-w- c:\windows\system32\accelerometerdll.DLL
2010-02-25 10:18 . 2009-10-03 02:34 ——– d—–w- c:\program files\TuneUpMedia
2010-02-22 03:28 . 2010-03-03 05:29 1282824 —-a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-02-19 23:47 . 2010-02-19 23:47 3604480 —-a-w- c:\windows\system32\GPhotos.scr
2010-02-17 10:51 . 2009-07-12 07:46 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-02-17 10:51 . 2009-07-12 07:46 286720 ——w- c:\windows\Setup1.exe
2010-02-17 05:12 . 2009-03-26 11:59 ——– d—–w- c:\users\valued customer\AppData\Roaming\Thunderbird
2010-02-16 07:31 . 2010-02-16 07:31 ——– d—–w- c:\program files\EarMaster Essential 5
2010-02-16 07:31 . 2010-02-16 07:31 ——– d—–w- c:\users\valued customer\AppData\Roaming\EarMaster
2010-02-16 07:31 . 2010-02-16 07:31 ——– d—–w- c:\programdata\EarMaster
2010-02-15 11:50 . 2010-02-15 11:50 ——– d—–w- c:\programdata\Downloaded Installations
2010-02-11 11:01 . 2009-09-28 09:27 ——– d—–w- c:\users\valued customer\AppData\Roaming\dvdcss
2010-02-04 23:39 . 2010-02-04 23:39 251376 —-a-w- c:\users\valued customer\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
2010-02-04 11:30 . 2010-02-04 11:29 ——– d—–w- c:\program files\Google
2010-02-04 07:58 . 2009-09-09 10:03 ——– d—–w- c:\program files\iTunes
2010-02-04 07:57 . 2010-02-04 07:57 ——– d—–w- c:\program files\iPod
2010-02-04 07:57 . 2008-11-15 11:03 ——– d—–w- c:\program files\Common Files\Apple
2010-02-04 07:38 . 2010-02-04 07:38 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-04 06:51 . 2010-03-03 05:29 49152 —-a-w- c:\windows\Help\OEM\scripts\Interop.TaskScheduler.dll
2010-02-02 08:24 . 2008-11-19 09:04 ——– d—–w- c:\programdata\Messenger Plus!
2010-02-02 08:24 . 2008-11-18 07:15 ——– d—–w- c:\program files\Messenger Plus! Live
2010-01-28 12:11 . 2008-08-11 10:50 ——– d—–w- c:\program files\Common Files\Java
2010-01-28 12:11 . 2008-08-11 10:50 ——– d—–w- c:\program files\Java
2010-01-27 09:38 . 2008-08-11 10:19 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-27 04:05 . 2010-01-27 04:04 ——– d—–w- c:\program files\IDT
2010-01-25 07:05 . 2008-11-07 05:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-11 12:34 . 2010-01-11 12:34 290816 —-a-w- c:\users\valued customer\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_4.dll
2010-01-11 12:34 . 2010-01-11 12:34 290816 —-a-w- c:\users\valued customer\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_3.dll
2010-01-11 12:34 . 2010-01-11 12:34 290816 —-a-w- c:\users\valued customer\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_2.dll
2010-01-11 12:34 . 2010-01-11 12:34 290816 —-a-w- c:\users\valued customer\AppData\Roaming\SystemRequirementsLab\SRLProxy_nvd_1.dll
2010-01-09 13:51 . 2010-01-09 13:51 0 —-a-w- c:\windows\system32\cd.dat
2010-01-06 15:38 . 2010-02-24 02:47 173056 —-a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-24 02:47 458752 —-a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-24 02:47 2159616 —-a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 15:38 . 2010-02-24 02:47 542720 —-a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-04 05:20 . 2009-01-25 08:40 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-01-02 06:38 . 2010-01-22 01:56 916480 —-a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 01:56 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 01:56 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 01:56 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-03-09 22:30 . 2009-03-09 22:30 5817072 —-a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2008-08-11 07:13 . 2008-08-11 07:12 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-09-24 14:27 218160 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-12-06 2387968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"Steam"="c:\program files\Steam\Steam.exe" [2010-02-21 1217872]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"Google Update"="c:\users\valued customer\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-28 135664]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe" [2009-04-29 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1045800]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-06-26 468264]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-04-23 206392]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2008-07-11 423200]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-08 75008]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-09-11 446556]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-17 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 02:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^valued customer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Get 2 FREE Audiobooks.lnk]
path=c:\users\valued customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Get 2 FREE Audiobooks.lnk
backup=c:\windows\pss\Get 2 FREE Audiobooks.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^valued customer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MediaRing Talk.lnk]
path=c:\users\valued customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MediaRing Talk.lnk
backup=c:\windows\pss\MediaRing Talk.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^valued customer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Stickies.lnk]
path=c:\users\valued customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
backup=c:\windows\pss\Stickies.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D066UUtility]
2000-07-07 03:11 32768 —-a-w- c:\windows\twain_32\D66U\D066UUTY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2009-04-29 17:55 3338240 —-a-w- c:\program files\Electronic Arts\EADM\Core.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 12:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 02:11 25623336 —-a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2009-08-05 06:06 1830128 —-a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31 247144 —-a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):18,a5,f4,ea,09,fa,c9,01

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-01-04 691696]
R2 EraserSvc10824;Symantec Eraser Service;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-04-23 239160]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2007-07-19 167808]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-08-05 7408]
R3 XDva306;XDva306;c:\windows\system32\XDva306.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-01-30 64160]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-21 216200]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-21 242696]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-08-05 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-05 74480]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe [2008-06-27 77824]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-21 308064]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2010-02-26 26168]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-04-28 599344]
S3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\DRIVERS\AVerBDA716x.sys [2008-06-23 1020160]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-04-28 54784]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-07-08 96856]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-03-30 4232704]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-08-21 66592]
S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-04-28 40752]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-12-06 12:18 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1428815032-1628162306-70752314-1003Core.job
- c:\users\valued customer\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-28 05:31]

2010-03-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1428815032-1628162306-70752314-1003UA.job
- c:\users\valued customer\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-28 05:31]

2010-03-11 c:\windows\Tasks\HPCeeScheduleForvalued customer.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-08-11 22:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
IE: &AOL; Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-AU\local\search.html
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: {1059820C-EEBF-478E-BC5B-60B4E048C9BA} = 10.4.16.1
FF - ProfilePath - c:\users\valued customer\AppData\Roaming\Mozilla\Firefox\Profiles\8w3hks3x.default\
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\users\valued customer\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\valued customer\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox 3.6 Beta 1\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-24 20:03
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000009

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\DPPWDFLT.dll
.
Completion time: 2010-03-24 20:05:10
ComboFix-quarantined-files.txt 2010-03-24 09:05

Pre-Run: 177,916,502,016 bytes free
Post-Run: 177,834,315,776 bytes free

- - End Of File - - 7E036090460FFCCD27DB9DFA00A2EE5B
Hi,


[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.




Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI