This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect and anti-virus update blocked

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys,

Recently my google searches are being redirected and opened in a new browser window. Opened the search result a second time opens the correct page but still in a new window. Also updates for both windows update and Microtrend Anti-Virus are being blocked and state no internet access is available. Ive had a search online and tried some suggested methods of removal with no success i have run hijackthis and these are the results i am given. Any help in removing this would be greatly appreciated. Thanks. Am also running windows 7 as this is not stated in the log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:37:37 PM, on 12/04/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files (x86)\Microsoft Office\Office14\OfficeSAS\officeSASscheduler.exe
C:\Program Files (x86)\Microsoft Office\Office14\OfficeSAS\OfficeSAS.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10e.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O3 - Toolbar: Yahoo!7 Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: OfficeSAS.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 9192 bytes
Hello Slim375 and welcome to WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again Slim375

I have looked at your log but need some more information as HijackThis doesn’t show many of the more recent infections.

First I would like to bring this to your attention:

The ASK toolbar comes bundled with many third-party applications, is considered as Spyware and also comes with vulnerabilities.

See the following links and decide whether or not you wish to keep them:

http://secunia.com/advisories/product/15810/
http://www.benedelman.org/spyware/ask-toolbars/


Run OTL

Please download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Logs to include with next post:

OTL.txt
Extras.txt


Thanks

Satchfan
Hi Satchfan,
Thanks for looking into this problem for me!
Requested logs are as follows:

OTL.txt

OTL logfile created on: 4/13/2010 6:16:14 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Users\Gaming\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 78.00% Memory free
12.00 Gb Paging File | 11.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 620.18 Gb Free Space | 66.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 100.00 Mb Total Space | 71.85 Mb Free Space | 71.85% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GAMING-PC
Current User Name: Gaming
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Gaming\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe (Trend Micro Inc.)
PRC - C:\Program Files (x86)\Microsoft Office\Office14\OfficeSAS\OfficeSASScheduler.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Gaming\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (TmProxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV:64bit: - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV:64bit: - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV:64bit: - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV:64bit: - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV:64bit: - (osppsvc) – C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (StorSvc) – C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (VSS) – C:\Windows\Vss [2009/07/14 13:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/14 13:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 95 F7 87 C0 DA D9 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension [2010/03/03 15:42:10 | 000,000,000 | —D | M]

[2010/04/11 18:14:39 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\Mozilla\Extensions
[2010/03/08 18:29:40 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/04/11 22:17:54 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\Mozilla\Firefox\Profiles\stvd5ki1.default\extensions
[2010/04/11 18:14:22 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/02 02:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/02 02:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/02 02:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/02 02:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo!7 Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{8832a629-2722-11df-a01f-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8832a629-2722-11df-a01f-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2009/07/14 13:20:14 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:64bit: Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:64bit: BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias.dll (Microsoft Corporation)
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/04/13 18:14:33 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Users\Gaming\Desktop\OTL.exe
[2010/04/12 20:36:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/04/12 20:35:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/04/12 18:19:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrent
[2010/04/12 12:36:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/04/12 12:02:23 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Roaming\IObit
[2010/04/12 12:02:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2010/04/12 12:00:30 | 007,184,528 | —- | C] (IObit ) – C:\Users\Gaming\Desktop\asc-setup.exe
[2010/04/12 11:03:04 | 000,000,000 | —D | C] – C:\ProgramData\FrontLine Registry Cleaner
[2010/04/12 11:02:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Frontline Registry Cleaner
[2010/04/12 11:01:42 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/04/12 08:32:25 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Roaming\Malwarebytes
[2010/04/12 08:32:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/04/12 08:32:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/04/11 18:14:32 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Local\Mozilla
[2010/04/11 18:14:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/04/10 16:33:10 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Local\Diagnostics
[2010/04/05 12:13:59 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Roaming\uTorrent
[2010/04/02 13:13:36 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Roaming\Red Alert 3
[2010/04/02 09:35:29 | 000,000,000 | —D | C] – C:\Users\Gaming\Documents\My Games
[2010/04/02 08:17:07 | 000,000,000 | —D | C] – C:\ProgramData\Steam
[2010/04/02 08:17:05 | 000,000,000 | —D | C] – C:\ProgramData\PopCap Games
[2010/04/02 08:06:39 | 000,000,000 | —D | C] – C:\Users\Gaming\Documents\Ascaron Entertainment
[2010/04/02 08:06:39 | 000,000,000 | —D | C] – C:\Users\Gaming\AppData\Roaming\Ascaron Entertainment
[2010/03/31 16:42:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[4 C:\Users\Gaming\Desktop\*.tmp files -> C:\Users\Gaming\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Gaming\Documents\*.tmp files -> C:\Users\Gaming\Documents\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/04/13 18:18:22 | 003,670,016 | -HS- | M] () – C:\Users\Gaming\ntuser.dat
[2010/04/13 18:14:43 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Users\Gaming\Desktop\OTL.exe
[2010/04/13 18:14:09 | 000,000,396 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2010/04/13 18:00:41 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/04/13 18:00:41 | 000,014,848 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/04/13 17:12:06 | 000,717,892 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/04/13 17:12:06 | 000,622,110 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/04/13 17:12:06 | 000,108,232 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/04/13 17:07:33 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/04/13 17:07:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/04/13 17:07:26 | 535,683,071 | -HS- | M] () – C:\hiberfil.sys
[2010/04/12 22:24:29 | 001,201,146 | -H– | M] () – C:\Users\Gaming\AppData\Local\IconCache.db
[2010/04/12 21:18:44 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/04/12 21:18:42 | 000,000,824 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/04/12 18:19:23 | 000,000,943 | —- | M] () – C:\Users\Public\Desktop\µTorrent.lnk
[2010/04/12 12:36:58 | 000,002,093 | —- | M] () – C:\Users\Gaming\Desktop\HijackThis.lnk
[2010/04/12 12:24:24 | 000,000,434 | —- | M] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Gaming.job
[2010/04/12 12:23:07 | 000,524,288 | -HS- | M] () – C:\Users\Gaming\ntuser.dat{42df2fce-45cc-11df-8847-00241d706baf}.TMContainer00000000000000000002.regtrans-ms
[2010/04/12 12:23:07 | 000,524,288 | -HS- | M] () – C:\Users\Gaming\ntuser.dat{42df2fce-45cc-11df-8847-00241d706baf}.TMContainer00000000000000000001.regtrans-ms
[2010/04/12 12:23:07 | 000,065,536 | -HS- | M] () – C:\Users\Gaming\ntuser.dat{42df2fce-45cc-11df-8847-00241d706baf}.TM.blf
[2010/04/12 12:02:26 | 000,001,221 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/04/12 12:02:08 | 007,184,528 | —- | M] (IObit ) – C:\Users\Gaming\Desktop\asc-setup.exe
[2010/04/12 11:02:56 | 000,002,061 | —- | M] () – C:\Users\Gaming\Desktop\FrontLine Registry Cleaner.lnk
[2010/04/12 11:02:45 | 001,732,888 | —- | M] () – C:\Users\Gaming\Desktop\FrontlineRegCleanerSetup.exe
[2010/04/12 10:59:33 | 003,912,072 | —- | M] () – C:\Users\Gaming\Desktop\ComboFix.exe
[2010/04/07 19:25:17 | 000,901,632 | —- | M] () – C:\Users\Gaming\Desktop\A Schreurs Transcript.doc
[2010/04/04 17:46:38 | 000,024,064 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - Origin Energy.doc
[2010/04/04 16:54:24 | 000,024,064 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - Commonwealth Bank.doc
[2010/04/04 16:51:19 | 000,023,552 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - Mars.doc
[2010/04/04 16:48:27 | 000,035,840 | —- | M] () – C:\Users\Gaming\Desktop\A.SchreursResume1.doc
[2010/04/04 16:07:47 | 000,028,160 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - Newcrest.doc
[2010/04/04 14:16:16 | 000,642,080 | —- | M] () – C:\Users\Gaming\Desktop\scan0002.pdf
[2010/04/04 13:53:29 | 000,011,310 | —- | M] () – C:\Users\Gaming\Desktop\Grad Years.xlsx
[2010/04/04 13:26:52 | 000,028,160 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - BHP.doc
[2010/04/04 13:00:09 | 000,028,160 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - ABB Aust.doc
[2010/04/04 12:58:38 | 000,028,160 | —- | M] () – C:\Users\Gaming\Desktop\Cover Letter - ABB.doc
[2010/04/04 12:49:27 | 000,075,776 | —- | M] () – C:\Users\Gaming\Desktop\ABB Grad Program.doc
[2010/04/04 11:58:48 | 001,099,396 | —- | M] () – C:\Users\Gaming\Desktop\Transcript - 1.pdf
[2010/04/04 11:45:40 | 000,846,533 | —- | M] () – C:\Users\Gaming\Desktop\Transcript - 2.pdf
[2010/04/04 10:36:49 | 000,035,840 | —- | M] () – C:\Users\Gaming\Desktop\A.SchreursResume.doc
[2010/04/02 09:44:27 | 000,001,620 | —- | M] () – C:\Users\Gaming\Desktop\RelicCOH - Shortcut.lnk
[4 C:\Users\Gaming\Desktop\*.tmp files -> C:\Users\Gaming\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Gaming\Documents\*.tmp files -> C:\Users\Gaming\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/12 18:19:23 | 000,000,943 | —- | C] () – C:\Users\Public\Desktop\µTorrent.lnk
[2010/04/12 12:36:58 | 000,002,093 | —- | C] () – C:\Users\Gaming\Desktop\HijackThis.lnk
[2010/04/12 12:02:32 | 000,000,396 | —- | C] () – C:\Windows\tasks\AWC Startup.job
[2010/04/12 12:02:26 | 000,001,221 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/04/12 11:03:04 | 000,000,434 | —- | C] () – C:\Windows\tasks\FrontLine Registry Cleaner Scheduled Scan - Gaming.job
[2010/04/12 11:02:56 | 000,002,061 | —- | C] () – C:\Users\Gaming\Desktop\FrontLine Registry Cleaner.lnk
[2010/04/12 11:02:21 | 001,732,888 | —- | C] () – C:\Users\Gaming\Desktop\FrontlineRegCleanerSetup.exe
[2010/04/12 10:59:33 | 003,912,072 | —- | C] () – C:\Users\Gaming\Desktop\ComboFix.exe
[2010/04/12 10:52:49 | 000,524,288 | -HS- | C] () – C:\Users\Gaming\ntuser.dat{42df2fce-45cc-11df-8847-00241d706baf}.TMContainer00000000000000000002.regtrans-ms
[2010/04/12 10:52:48 | 000,524,288 | -HS- | C] () – C:\Users\Gaming\ntuser.dat{42df2fce-45cc-11df-8847-00241d706baf}.TMContainer00000000000000000001.regtrans-ms
[2010/04/12 10:52:48 | 000,065,536 | -HS- | C] () – C:\Users\Gaming\ntuser.dat{42df2fce-45cc-11df-8847-00241d706baf}.TM.blf
[2010/04/04 17:46:38 | 000,024,064 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - Origin Energy.doc
[2010/04/04 16:51:47 | 000,024,064 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - Commonwealth Bank.doc
[2010/04/04 16:48:27 | 000,035,840 | —- | C] () – C:\Users\Gaming\Desktop\A.SchreursResume1.doc
[2010/04/04 16:06:00 | 000,028,160 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - Newcrest.doc
[2010/04/04 14:16:12 | 000,642,080 | —- | C] () – C:\Users\Gaming\Desktop\scan0002.pdf
[2010/04/04 13:25:22 | 000,028,160 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - BHP.doc
[2010/04/04 13:00:08 | 000,028,160 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - ABB Aust.doc
[2010/04/04 12:54:52 | 000,028,160 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - ABB.doc
[2010/04/04 12:25:13 | 000,075,776 | —- | C] () – C:\Users\Gaming\Desktop\ABB Grad Program.doc
[2010/04/04 12:16:20 | 000,901,632 | —- | C] () – C:\Users\Gaming\Desktop\A Schreurs Transcript.doc
[2010/04/04 12:04:01 | 000,846,533 | —- | C] () – C:\Users\Gaming\Desktop\Transcript - 2.pdf
[2010/04/04 12:04:00 | 001,099,396 | —- | C] () – C:\Users\Gaming\Desktop\Transcript - 1.pdf
[2010/04/04 10:57:40 | 000,023,552 | —- | C] () – C:\Users\Gaming\Desktop\Cover Letter - Mars.doc
[2010/04/04 10:36:49 | 000,035,840 | —- | C] () – C:\Users\Gaming\Desktop\A.SchreursResume.doc
[2010/04/04 10:24:59 | 000,011,310 | —- | C] () – C:\Users\Gaming\Desktop\Grad Years.xlsx
[2010/04/02 09:44:27 | 000,001,620 | —- | C] () – C:\Users\Gaming\Desktop\RelicCOH - Shortcut.lnk
[2010/03/23 16:54:47 | 000,722,382 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/03/03 15:35:25 | 003,670,016 | -HS- | C] () – C:\Users\Gaming\ntuser.dat
[2010/03/03 15:35:25 | 000,524,288 | -HS- | C] () – C:\Users\Gaming\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2010/03/03 15:35:25 | 000,524,288 | -HS- | C] () – C:\Users\Gaming\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2010/03/03 15:35:25 | 000,262,144 | -HS- | C] () – C:\Users\Gaming\ntuser.dat.LOG1
[2010/03/03 15:35:25 | 000,065,536 | -HS- | C] () – C:\Users\Gaming\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2010/03/03 15:35:25 | 000,000,020 | -HS- | C] () – C:\Users\Gaming\ntuser.ini
[2010/03/03 15:35:25 | 000,000,000 | -HS- | C] () – C:\Users\Gaming\ntuser.dat.LOG2
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/26 16:24:18 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini

========== LOP Check ==========

[2010/04/02 08:06:39 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\Ascaron Entertainment
[2010/04/12 12:02:23 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\IObit
[2010/03/14 14:10:08 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\iWin
[2010/04/12 10:51:04 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\LimeWire
[2010/04/02 13:13:39 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\Red Alert 3
[2010/03/04 09:29:50 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\The Creative Assembly
[2010/04/13 18:14:06 | 000,000,000 | —D | M] – C:\Users\Gaming\AppData\Roaming\uTorrent
[2010/04/13 18:14:09 | 000,000,396 | —- | M] () – C:\Windows\Tasks\AWC Startup.job
[2010/04/12 12:24:24 | 000,000,434 | —- | M] () – C:\Windows\Tasks\FrontLine Registry Cleaner Scheduled Scan - Gaming.job
[2009/07/14 15:08:49 | 000,015,222 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2008/04/11 07:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe


< MD5 for: AGP440.SYS >
[2009/04/22 15:52:58 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=3D530DBF2154679DD0B0D47CA42CE90C – C:\Windows.old\Windows\System32\drivers\AGP440.sys
[2009/04/22 15:52:58 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=3D530DBF2154679DD0B0D47CA42CE90C – C:\Windows.old\Windows\System32\DriverStore\FileRepository\machine.inf_amd64_neutral_5a774c2b239a352c\AGP440.sys
[2009/04/22 15:52:58 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=3D530DBF2154679DD0B0D47CA42CE90C – C:\Windows.old\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7100.0_none_87248120cc241bf9\AGP440.sys
[2009/07/14 11:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 11:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 11:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 11:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/04/22 15:52:52 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=F57B8BB59FB27784B67D54D9161D3CD9 – C:\Windows.old\Windows\System32\drivers\atapi.sys
[2009/04/22 15:52:52 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=F57B8BB59FB27784B67D54D9161D3CD9 – C:\Windows.old\Windows\System32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_6240958557aee151\atapi.sys
[2009/04/22 15:52:52 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=F57B8BB59FB27784B67D54D9161D3CD9 – C:\Windows.old\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7100.0_none_aa49bbff2efd111b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/14 11:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 11:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 11:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/04/22 15:39:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=85703F94D6830B69EA30CD1EBB6289B8 – C:\Windows.old\Windows\System32\cngaudit.dll
[2009/04/22 15:39:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=85703F94D6830B69EA30CD1EBB6289B8 – C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7100.0_none_b5757f0a3d07c039\cngaudit.dll
[2009/07/14 11:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
[2009/04/22 15:20:04 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=EC9930C8CDF46295A1354256435CB5DE – C:\Windows.old\Windows\SysWOW64\cngaudit.dll
[2009/04/22 15:20:04 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=EC9930C8CDF46295A1354256435CB5DE – C:\Windows.old\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7100.0_none_5956e38684aa4f03\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/04/22 15:48:29 | 000,410,704 | —- | M] (Intel Corporation) MD5=100D70F4650864A12E6D34B5FAA15068 – C:\Windows.old\Windows\System32\drivers\iaStorV.sys
[2009/04/22 15:48:29 | 000,410,704 | —- | M] (Intel Corporation) MD5=100D70F4650864A12E6D34B5FAA15068 – C:\Windows.old\Windows\System32\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/04/22 15:48:29 | 000,410,704 | —- | M] (Intel Corporation) MD5=100D70F4650864A12E6D34B5FAA15068 – C:\Windows.old\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7100.0_none_7c22e65d953b3d0e\iaStorV.sys
[2009/07/14 11:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 11:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/04/22 15:40:41 | 000,690,688 | —- | M] (Microsoft Corporation) MD5=527F726F895A94F040DF2605BFF8F32E – C:\Windows.old\Windows\System32\netlogon.dll
[2009/04/22 15:40:41 | 000,690,688 | —- | M] (Microsoft Corporation) MD5=527F726F895A94F040DF2605BFF8F32E – C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7100.0_none_cac94b28456d2ad6\netlogon.dll
[2009/07/14 11:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/04/22 15:21:18 | 000,561,152 | —- | M] (Microsoft Corporation) MD5=A3EA8619FBBC2D270D79C241CE426618 – C:\Windows.old\Windows\SysWOW64\netlogon.dll
[2009/04/22 15:21:18 | 000,561,152 | —- | M] (Microsoft Corporation) MD5=A3EA8619FBBC2D270D79C241CE426618 – C:\Windows.old\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7100.0_none_d51df57a79cdecd1\netlogon.dll
[2009/07/14 11:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 11:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 11:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/04/22 15:48:24 | 000,167,504 | —- | M] (NVIDIA Corporation) MD5=1C09D38432424726932E5B1D62FA561B – C:\Windows.old\Windows\System32\drivers\nvstor.sys
[2009/04/22 15:48:24 | 000,167,504 | —- | M] (NVIDIA Corporation) MD5=1C09D38432424726932E5B1D62FA561B – C:\Windows.old\Windows\System32\DriverStore\FileRepository\nvraid.inf_amd64_neutral_4d1b6b7b67c54c8c\nvstor.sys
[2009/04/22 15:48:24 | 000,167,504 | —- | M] (NVIDIA Corporation) MD5=1C09D38432424726932E5B1D62FA561B – C:\Windows.old\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7100.0_none_06ec570ccc71e6e6\nvstor.sys
[2009/07/14 11:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 11:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 11:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 11:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 11:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 11:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2009/04/22 15:21:47 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=686BAFE6AF35AF1C8D5EB536A8500430 – C:\Windows.old\Windows\SysWOW64\scecli.dll
[2009/04/22 15:21:47 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=686BAFE6AF35AF1C8D5EB536A8500430 – C:\Windows.old\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7100.0_none_0f7420931aef738c\scecli.dll
[2009/04/22 15:41:00 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=BDBED21EC7818C2AA12A55697572C283 – C:\Windows.old\Windows\System32\scecli.dll
[2009/04/22 15:41:00 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=BDBED21EC7818C2AA12A55697572C283 – C:\Windows.old\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7100.0_none_051f7640e68eb191\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
< End of report >



Extras.txt

OTL Extras logfile created on: 4/13/2010 6:16:14 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Users\Gaming\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 78.00% Memory free
12.00 Gb Paging File | 11.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 620.18 Gb Free Space | 66.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 100.00 Mb Total Space | 71.85 Mb Free Space | 71.85% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GAMING-PC
Current User Name: Gaming
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{20140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 (Beta)
"{20140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010 (Beta)
"{20140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Beta)
"{393ADA10-CEC5-47E7-AE6D-A9591C125EEF}" = Microsoft LifeCam
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security Pro
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C5A08BF-BB99-4998-81BD-F6CC32483B34}" = Microsoft Corporation
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security Pro
"CutePDF Writer Installation" = CutePDF Writer 2.8
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{20140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 (Beta)
"{20140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 (Beta)
"{20140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010 (Beta)
"{20140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010 (Beta)
"{20140000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2010 (Beta)
"{20140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010 (Beta)
"{20140000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2010 (Beta)
"{20140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010 (Beta)
"{20140000-011A-0000-0000-0000000FF1CE}" = Microsoft Office Send-a-Smile
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ULTIMATER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"CutePDF Professional (Evaluation)_is1" = CutePDF Professional 3.6 (Evaluation)
"Frontline Registry Cleaner1.2" = Frontline Registry Cleaner
"HijackThis" = HijackThis 2.0.2
"LogMeIn Hamachi" = LogMeIn Hamachi
"Messenger Plus! Live" = Messenger Plus! Live
"Office14.PRJPRO" = Microsoft Project Professional 2010
"Steam App 10180" = Call of Duty: Modern Warfare 2
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Steam App 10500" = Empire: Total War
"Steam App 12470" = Port Royale 2
"Steam App 13230" = Unreal Tournament 2004
"Steam App 13640" = Tom Clancy's Ghost Recon: Advanced Warfighter
"Steam App 16810" = Sid Meier's Civilization IV: Colonization
"Steam App 17480" = Command and Conquer: Red Alert 3
"Steam App 18500" = Defense Grid: The Awakening
"Steam App 240" = Counter-Strike: Source
"Steam App 25890" = Hearts of Iron III
"Steam App 25980" = Majesty 2
"Steam App 32370" = Star Wars: Knights of the Old Republic
"Steam App 33100" = Alien Shooter
"Steam App 33110" = Alien Shooter: Revisited
"Steam App 33120" = Alien Shooter 2: Reloaded
"Steam App 33130" = Zombie Shooter
"Steam App 33520" = Tropico
"Steam App 33530" = Tropico 2
"Steam App 34030" = Napoleon: Total War
"Steam App 3590" = Plants vs. Zombies
"Steam App 37900" = Boggle
"Steam App 37910" = Battleship
"Steam App 38050" = Risk
"Steam App 38060" = Risk 2
"Steam App 41500" = Torchlight
"Steam App 440" = Team Fortress 2
"Steam App 500" = Left 4 Dead
"ULTIMATER" = Microsoft Office Ultimate 2007
"uTorrent" = µTorrent
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xfire" = Xfire (remove only)
"Yahoo! Companion" = Yahoo!7 Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"Yahoo!7 Messenger" = Yahoo!7 Messenger

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/17/2010 4:22:27 PM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: msnmsgr.exe, version: 14.0.8089.726, time
stamp: 0x4a6ce533 Faulting module name: PresenceIM.dll, version: 14.0.8089.726,
time stamp: 0x4a6ce51e Exception code: 0xc0000005 Fault offset: 0x0002186c Faulting
process id: 0xad4 Faulting application start time: 0x01cac60f76d38a6d Faulting application
path: C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe Faulting module
path: C:\Program Files (x86)\Windows Live\Messenger\PresenceIM.dll Report Id: cdc7cdfd-3202-11df-a8f8-00241d706baf

Error - 3/18/2010 2:40:13 AM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: msnmsgr.exe, version: 14.0.8089.726, time
stamp: 0x4a6ce533 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x836610e9 Faulting process id: 0x3f4 Faulting application
start time: 0x01cac665b1c4b81c Faulting application path: C:\Program Files (x86)\Windows
Live\Messenger\msnmsgr.exe Faulting module path: unknown Report Id: 1a7ba705-3259-11df-ab22-00241d706baf

Error - 3/18/2010 8:43:51 PM | Computer Name = Gaming-PC | Source = Application Hang | ID = 1002
Description = The program Steam.exe version 1.0.778.935 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1288 Start
Time: 01cac6f8a942c047 Termination Time: 0 Application Path: C:\Program Files (x86)\Steam\Steam.exe

Report
Id: 57f2f08a-32f0-11df-aca3-00241d706baf

Error - 3/18/2010 8:55:20 PM | Computer Name = Gaming-PC | Source = Application Hang | ID = 1002
Description = The program Steam.exe version 1.0.778.935 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 438 Start
Time: 01cac6fdaeaf3b69 Termination Time: 0 Application Path: C:\Program Files (x86)\Steam\Steam.exe

Report
Id: e368a30e-32f1-11df-aca3-00241d706baf

Error - 3/19/2010 4:09:18 AM | Computer Name = Gaming-PC | Source = Application Hang | ID = 1002
Description = The program Steam.exe version 1.0.778.935 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: f68 Start
Time: 01cac6ff16ed130b Termination Time: 0 Application Path: C:\Program Files (x86)\Steam\Steam.exe

Report
Id: b38c1bbc-332e-11df-aca3-00241d706baf

Error - 4/7/2010 7:29:23 AM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7600.16385,
time stamp: 0x4a5bc69e Faulting module name: TSToolbar.dll_unloaded, version: 0.0.0.0,
time stamp: 0x4a6d7405 Exception code: 0xc0000005 Fault offset: 0x100133e5 Faulting
process id: 0x10d0 Faulting application start time: 0x01cad64591799df0 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
TSToolbar.dll Report Id: d0521633-4238-11df-85ba-00241d706baf

Error - 4/11/2010 4:17:13 AM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: msnmsgr.exe, version: 14.0.8089.726, time
stamp: 0x4a6ce533 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x33da0a47 Faulting process id: 0xf18 Faulting application
start time: 0x01cad94f36a9f05f Faulting application path: C:\Program Files (x86)\Windows
Live\Messenger\msnmsgr.exe Faulting module path: unknown Report Id: a14854b5-4542-11df-b167-00241d706baf

Error - 4/12/2010 8:04:19 AM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: msnmsgr.exe, version: 14.0.8089.726, time
stamp: 0x4a6ce533 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x00000000 Faulting process id: 0xf64 Faulting application
start time: 0x01cada383272e0d0 Faulting application path: C:\Program Files (x86)\Windows
Live\Messenger\msnmsgr.exe Faulting module path: unknown Report Id: 859c9eda-462b-11df-a473-00241d706baf

Error - 4/13/2010 3:14:01 AM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: msnmsgr.exe, version: 14.0.8089.726, time
stamp: 0x4a6ce533 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xe8000000 Faulting process id: 0xd20 Faulting application
start time: 0x01cadad8de8f45af Faulting application path: C:\Program Files (x86)\Windows
Live\Messenger\msnmsgr.exe Faulting module path: unknown Report Id: 22429a66-46cc-11df-afc9-00241d706baf

Error - 4/13/2010 3:15:43 AM | Computer Name = Gaming-PC | Source = Application Error | ID = 1000
Description = Faulting application name: msnmsgr.exe, version: 14.0.8089.726, time
stamp: 0x4a6ce533 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x8ba5a5a5 Faulting process id: 0xc90 Faulting application
start time: 0x01cadad91fc52635 Faulting application path: C:\Program Files (x86)\Windows
Live\Messenger\msnmsgr.exe Faulting module path: unknown Report Id: 5ebc905c-46cc-11df-afc9-00241d706baf

[ System Events ]
Error - 4/11/2010 7:41:19 PM | Computer Name = Gaming-PC | Source = DCOM | ID = 10005
Description =

Error - 4/11/2010 8:40:19 PM | Computer Name = Gaming-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 4/11/2010 8:40:19 PM | Computer Name = Gaming-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 4/11/2010 8:40:19 PM | Computer Name = Gaming-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 4/11/2010 10:24:05 PM | Computer Name = Gaming-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/11/2010 10:24:09 PM | Computer Name = Gaming-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/12/2010 8:02:15 AM | Computer Name = Gaming-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/12/2010 8:02:24 AM | Computer Name = Gaming-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/13/2010 3:07:23 AM | Computer Name = Gaming-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/13/2010 3:07:29 AM | Computer Name = Gaming-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!


< End of report >

Regards,

Slim375
Hi Slim375 Good work running the scans. Your logs definitely show some entries that need to be investigated but I have just come in from work and need a bit more time. Please bear with me while I come up with a plan of action and I'll post it to you as soon as I can Thanks Satchfan
Hi satchfan, No worries thanks again for looking into this issue for me. In regards to the ASK toolbar i was not aware this had installed itself so i will remove this after you have completed assisting so as not to intterupt the process. have Also i have now been recieving a fake windows internet security popup appearing at random times over my current IE tab as shown below 📎virus_popup.png hope this helps you Thanks again, Slim375
Hello Slim375

Thanks for your patience. A couple of things before we start cleaning your computer:

LimeWire, uTorrent, etc.

I see you have P2P software (LimeWire, uTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. It likely contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file-sharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

Please see this topic for more information: Perils of P2P File Sharing.

Should you decide not to uninstall them, I would ask that you don’t use these while we are trying to clean your computer.

I also recommend that you uninstall IObit. It is has been proved to be untrustworthy in its programming and is pretty ineffective now that it can no longer be propped up by MBAM

See:

http://forums.malwarebytes.org/index.php?showtopic=29681
http://forums.malwarebytes.org/index.php?showtopic=30989
http://forums.malwarebytes.org/index.php?showtopic=33217


Uninstall ComboFix

You have tried to run ComboFix on your 64 bit system which you should not have been doing. Neither should you have used ComboFix without expert help – this tool has the potential to cause irreparable damage to your computer unless used under expert supervision
• Click START then RUN
• Now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.


Run OTL.exe
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found -
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
    O33 - MountPoints2\{8832a629-2722-11df-a01f-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{8832a629-2722-11df-a01f-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe – File not found
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "AutoUpdateDisableNotify" = 0
    
    :Commands
    [emptytemp]
    [start explorer]
    [Resethosts]
    [Reboot]

  • Click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Please download exeHelper by Raktor to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up; press any key to close it once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)


Please delete the copy of Malwarebytes that is on your computer.


Download Malwarebytes' Anti-Malware• Double-click mbam-setup.exe and follow the prompts to install the program.
• At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
• If an update is found, it will download and install the latest version.
• Once the program has loaded, select Perform quick scan, then click Scan.
• When the scan is complete, click OK, then Show Results to view the results.
• Be sure that everything is checked, and click Remove Selected.
• When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
• The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
• Copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Logs to include in your next post:

OTL.txt
exehelperlog.txt
Malwarebytes log


Please let me know what is happening with your computer now.

Thanks

Satchfan
Hey Satchfan, I have uninstallled the requested programs and ran OTL as requested however the link for exehelper.com gives me a 404 unavilable error is the link correct or is there another location i can obtain this from? Thanks, Slim
Satchfan, Disregard the previous post i tried the link again this morning and it worked so maybe it was an update. logs are as follows OLT.TXT All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8832a629-2722-11df-a01f-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8832a629-2722-11df-a01f-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8832a629-2722-11df-a01f-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8832a629-2722-11df-a01f-806e6f6e6963}\ not found. File D:\autorun.exe not found. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AutoUpdateDisableNotify" | 0 /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gaming ->Temp folder emptied: 2112021 bytes ->Temporary Internet Files folder emptied: 17431656 bytes ->Java cache emptied: 983951 bytes ->FireFox cache emptied: 47246140 bytes ->Flash cache emptied: 4219 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 200704 bytes %systemroot%\System32 .tmp files removed: 755200 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 49714 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 74014563 bytes Total Files Cleaned = 136.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.1.1 log created on 04152010_174342 Files\Folders moved on Reboot… C:\Users\Gaming\AppData\Local\Temp\Low\TMFBE_4028\.inuse moved successfully. C:\Users\Gaming\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Gaming\AppData\Local\Temp\~DF05ABCC6338714FD0.TMP not found! File\Folder C:\Users\Gaming\AppData\Local\Temp\~DF5314AD7166A1EC74.TMP not found! File\Folder C:\Users\Gaming\AppData\Local\Temp\~DF79FBA43EC86AB43B.TMP not found! File\Folder C:\Users\Gaming\AppData\Local\Temp\~DF88D72DCDFAAE4C04.TMP not found! File\Folder C:\Users\Gaming\AppData\Local\Temp\~DF90E4A29C193D75F4.TMP not found! File\Folder C:\Users\Gaming\AppData\Local\Temp\~DFA630092ED5E76A40.TMP not found! C:\Users\Gaming\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XXB96TO5\Google_Redirect_anti_virus_update_blocked_t111504[1].html moved successfully. C:\Users\Gaming\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XXB96TO5\iframe[2].htm moved successfully. C:\Users\Gaming\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\Gaming\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. Registry entries deleted on Reboot… EXEHELPER.TXT exeHelper by Raktor Build 20100414 Run at 07:58:58 on 04/16/10 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– MALWAREBYTES LOG Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3993 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 16/04/2010 8:08:03 AM mbam-log-2010-04-16 (08-08-03).txt Scan type: Quick scan Objects scanned: 103855 Time elapsed: 3 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61db4be0-39a6-4dce-86c4-3f8e0929a80f}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Regards, Slim
Satchfan, Just to add to my last post have used the pc most of the afternoon and seems that all the issues are still present after the actions. upon reset malwarebytes deleted the files it found however this resulted in the internet not working due to it not finding the DNS server follow another reset this seemed to resolve itself . Thanks, Slim
Hello Slim365

Sorry to have been a while.

From your Malwarebytes, (MBAM), log, it is clear that you have a DNS changer infection.

Please print out these instructions, or copy and paste them into notepad, as you will be working offline some of the time and won’t be able to connect to this site.

As you might or might not know, a DNS changer infects your router. We’ll need to clean your computer off-line, so that the router can't re-infect your computer.

Before using the router again, it needs to be re-set it to its default settings in order to remove the infection.

Some routers you can re-set quite easily just by rebooting them: others need a different approach. With some types of internet, (eg. DSL connections that use PPPoE in the router), you will need to know the data to re-setup the router itself.

If you don’t know the router's default password, you can look it up HERE before disconnecting from the Internet.

The instructions that follow work in most cases.

Warning: If it doesn't work, you will lose internet connection and will need to talk to your router provider to ascertain how to re-setup your router.


Step 1

If you no-longer have Malwarebytes please download it from here.

DISCONNECT YOUR SYSTEM FROM THE INTERNET AND YOUR ROUTER, • Double-click mbam-setup.exe and follow the prompts to install the program.
• Once the program has loaded, select Perform quick scan, then click Scan.
• When the scan is complete, click OK, then Show Results to view the results.
• Be sure that everything is checked, and click Remove Selected.
• When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
• The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
• Copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Step 2

Reset the router to its default configuration.

This can be done by inserting something tiny like a paper clip end or sharp pencil tip into the small hole labelled "reset" located at the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).

NOTE: If there are other infected machines using the same router, they will need to be cleared with the above steps before resetting the router, otherwise, the malware will simply go back and change the router's DNS settings.

You’ll also need to reconfigure any security settings you had in place prior to the reset.

See: http://www.onguardonline.gov/default.aspx#tutorials-wireless for video tutorials on how to properly configure your router's encryption and security settings.

You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Once you have run Malwarebytes' Anti-Malware on the infected system, and reset the router to its default configuration, reconnect to the internet, and to your router.

Please post the Malwarebytes log and let me know how things are running now.

Thanks

Satchfan
Satchfan,

I had suspected that the router had been infected from a preusal of the forums here yesterday but wanted to wait for your response before i reset anything. I have now reset the router and reconfigured it so that the internet is working again. Google searches are not being redirected currently and trend has successfully updated so i believe this has solved the issue. Is there any advice you can give as how to avoid this sort of infection on the router in the future? Scan results are as below:

Prior to router reset

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3993

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

18/04/2010 9:40:11 AM
mbam-log-2010-04-18 (09-40-11).txt

Scan type: Quick scan
Objects scanned: 103671
Time elapsed: 1 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{61db4be0-39a6-4dce-86c4-3f8e0929a80f}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Following router reconfiguration:

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3993

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

18/04/2010 10:14:58 AM
mbam-log-2010-04-18 (10-14-58).txt

Scan type: Quick scan
Objects scanned: 103385
Time elapsed: 1 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Regards,

Slim375
Hi Slim375

It looks as if that did the trick. Unless you have any other issues, we can now clean up by removing the tools we have used.


Uninstall OTL
• Double-click OTL.exe
• Click the CleanUp! button.
• Select Yes when the Begin cleanup Process? prompt appears.
• If you are prompted to reboot during the cleanup, select Yes.
• The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.


MBAM can be uninstalled via control panel, add/remove but it is a useful tool to keep. I would suggest that you keep this and run it at least once a month.


Create a Restore Point

You need to clean your restore points and set a new one. Please go here for directions on how to do this. You need to turn System Protection off to delete all old restore points, reboot and then turn System Protection back on to create a new restore point.


Clear all your temporary files.

Download ATF Cleaner

To use ATF Cleaner:

Double-click ATF-Cleaner.exe (on your desktop) to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

For Technical Support, double-click the e-mail address located at the bottom of each menu


Windows updates

Check that your operating system is kept up-to-date: much malware uses the vulnerabilities in non-patched operating systems.

See here for information.


Preventing Infections in the Future

Please have a look at the following links and suggestions:• So How did I get infected?
• Miekies' prevention suggestions
• Hardening Windows Security - Part 1 & Part 2


• Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a multitude of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
The large majority of infection arises through Peer to Peer file-sharing and/or programs that are not updated regularly with the latest security patches.

You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Follow the above guidelines and your potential for being infected again will be reduced dramatically.

If you have no more questions or problems, please let me know and we will close this topic.

Regards

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI