This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojan.DNSChanger

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been having trouble with this for a while and am unable to update my Windows 7. I ran Malwarebytes and tried to delete it, but it always comes back. Here's both my Malwarebytes log and my Hijack this log, so I hope you guys can help me with this problem. If anyone can also tell me how to avoid this problem in the future, it would be appreciated.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4073

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

5/12/2010 11:27:50 PM
mbam-log-2010-05-12 (23-27-50).txt

Scan type: Quick scan
Objects scanned: 115960
Time elapsed: 2 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e1d0932f-cc5f-4a57-a043-39c0a4e7e901}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:24:16 PM, on 5/12/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 7957 bytes
Hello I_M_NEWB and welcome to What the Tech! I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any colored text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    netsvcs
    %systemroot%\system32\drivers\*.sys /90
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and include them in your next post.
Please include the following in your next post:
  • OTL and Extras logs
Thanks for the help RPMcMurphy. I'll be relying on you to help me solve this.

OTL Extras logfile created on: 5/13/2010 6:14:14 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = D:\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 69.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 558.82 Gb Total Space | 434.40 Gb Free Space | 77.74% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 192.78 Gb Free Space | 20.70% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 298.09 Gb Total Space | 279.28 Gb Free Space | 93.69% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 2.45 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 1.84 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive M: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TRI-PC
Current User Name: Tri
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E96FD88-FF86-25BB-112E-804C2F1B1128}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{B71779A7-9931-A01C-FE36-26D30133B3A1}" = ccc-utility64
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.15
"Defraggler" = Defraggler
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F52FBBC-D076-9A9A-5A0F-FFC6D46361B0}" = Catalyst Control Center Graphics Previews Common
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{186FC6A7-3E47-67AB-BF01-B2D86A1FA34B}" = CCC Help Thai
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1E132C9D-042E-E68D-9A85-5273085FBF75}" = Catalyst Control Center Graphics Full Existing
"{1FF713E1-FE5E-4AD0-9C8C-B2E877846B45}" = Catalyst Control Center - Branding
"{20071984-5EB1-4881-8EDB-082532ACEC6D}" = Heroes of Might and Magic V
"{269FC1B2-92D3-1AA7-CC2E-E3BFB141ED08}" = Catalyst Control Center Graphics Light
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 20
"{2E094936-B6D2-67FC-9680-7D83FD9722EA}" = CCC Help Chinese Standard
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{41F1BC2D-182A-706D-B48D-F88B097CAA3C}" = CCC Help Chinese Traditional
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A3E4DFA-6AC2-8E80-AF5C-DF34CC97FEA5}" = Catalyst Control Center HydraVision Full
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5F837C12-F45A-ADC7-DF59-3CF43C228226}" = ccc-core-static
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77082BFF-AFC4-CDFD-26C1-79AD8CCC9452}" = CCC Help Korean
"{785740DF-DC05-F730-4309-09DDC7848A40}" = Catalyst Control Center Graphics Full New
"{7B68D39D-C167-DA59-587A-5143B0FF3458}" = Catalyst Control Center InstallProxy
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86925C00-AB04-17B3-D9FB-373943F39DE0}" = Catalyst Control Center Core Implementation
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{96173BCD-08AC-57B1-FCE3-E7A9018BE585}" = Catalyst Control Center Localization All
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2D4D657-DAA4-4C68-B01E-11736C1D8C0D}" = Unigine Heaven Benchmark v1.0
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{D222C5F9-C8A4-A32F-8A58-EFAF7178F5ED}" = CCC Help Japanese
"{D42E3F13-E45C-33A1-7FBF-FB84419858E1}" = Catalyst Control Center Graphics Previews Vista
"{DCEBE43A-834D-67B5-306E-E95E9180D5B7}" = CCC Help English
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Flash Movie Player" = Flash Movie Player 1.5
"JDownloader" = JDownloader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"PowerISO" = PowerISO
"RealPlayer 12.0" = RealPlayer
"Sanitarium_is1" = Sanitarium
"Sengoku Rance English_is1" = Sengoku Rance English v1.01
"Steam App 20900" = The Witcher: Enhanced Edition
"Steam App 23310" = The Last Remnant
"Steam App 240" = Counter-Strike: Source
"Steam App 41500" = Torchlight
"Tears to Tiara" = Tears to Tiara
"The Witcher - FCR & Flash Mod_is1" = FCR v1.1 final or Flash Mod v1.01
"The Witcher - Scabbard Mod_is1" = Scabbar Mod ver 1.02
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.5
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Sansa Updater" = Sansa Updater

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/21/2010 10:05:43 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/23/2010 9:12:18 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/26/2010 1:40:15 AM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 4/27/2010 6:34:00 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 5/1/2010 5:18:53 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 5/3/2010 9:29:10 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 5/4/2010 5:31:43 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 5/5/2010 1:34:57 PM | Computer Name = Tri-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 5/6/2010 3:53:38 PM | Computer Name = Tri-PC | Source = MsiInstaller | ID = 11935
Description =

Error - 5/6/2010 4:03:08 PM | Computer Name = Tri-PC | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

[ System Events ]
Error - 5/12/2010 5:45:30 PM | Computer Name = Tri-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 5/12/2010 5:46:18 PM | Computer Name = Tri-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 5/12/2010 5:46:18 PM | Computer Name = Tri-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 5/12/2010 9:26:33 PM | Computer Name = Tri-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/12/2010 9:26:33 PM | Computer Name = Tri-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 5/12/2010 9:26:34 PM | Computer Name = Tri-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:25:25 PM on ?5/?12/?2010 was unexpected.

Error - 5/12/2010 9:31:43 PM | Computer Name = Tri-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 5/12/2010 9:31:43 PM | Computer Name = Tri-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 5/13/2010 6:53:57 PM | Computer Name = Tri-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/13/2010 6:53:57 PM | Computer Name = Tri-PC | Source = atikmdag | ID = 43029
Description = Display is not active


< End of report >

OTL logfile created on: 5/13/2010 6:14:14 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = D:\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 69.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 558.82 Gb Total Space | 434.40 Gb Free Space | 77.74% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 192.78 Gb Free Space | 20.70% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 298.09 Gb Total Space | 279.28 Gb Free Space | 93.69% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 2.45 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 1.84 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive M: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TRI-PC
Current User Name: Tri
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - D:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - D:\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wbem\wmiutils.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\vbscript.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wbemcomn.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wbem\wbemdisp.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wbem\wbemsvc.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wbem\wbemprox.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\sxs.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\RpcRtRemote.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\ntdsapi.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\wbem\fastprox.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (VSS) – C:\Windows\Vss [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (cpuz132) – C:\Windows\SysNative\drivers\cpuz132_x64.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (CSC) – C:\Windows\CSC [2009/11/12 00:49:06 | 000,000,000 | —D | M]
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 83 BD 3F 93 57 ED CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "cheapassgamer.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: {6dd0bdba-0a02-429e-b595-87a7dfdca7a1}:0.7.7
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: [removed]:0.5.2010043001
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.7.4
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: {f701c26a-479a-4724-b4f1-870db12f063c}:1.4.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/05/12 20:26:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/10 17:15:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/03 00:39:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/04/20 23:21:33 | 000,000,000 | —D | M]

[2009/11/11 23:02:22 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Extensions
[2010/05/13 01:23:14 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions
[2009/12/08 15:10:28 | 000,000,000 | —D | M] (Session Manager) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2010/02/19 11:05:51 | 000,000,000 | —D | M] (Linkification) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010/05/13 01:23:14 | 000,000,000 | —D | M] (GameFOX) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{6dd0bdba-0a02-429e-b595-87a7dfdca7a1}
[2010/05/04 00:13:58 | 000,000,000 | —D | M] (NoScript) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/11/11 23:38:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/04/09 22:53:19 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/01/26 15:25:33 | 000,000,000 | —D | M] (Text-to-Image) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{f701c26a-479a-4724-b4f1-870db12f063c}
[2010/05/06 14:15:13 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\[removed]
[2010/05/13 17:53:54 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/19 12:46:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2009/11/14 15:02:07 | 000,000,988 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 www.alcohol-soft.com
O1 - Hosts: 127.0.0.1 images.alcohol-soft.com
O1 - Hosts: 127.0.0.1 trial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 alcohol-soft.com
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive) - K:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2006/04/05 12:38:16 | 000,050,534 | R— | M] () - K:\AutoRun.ico – [ UDF ]
O32 - AutoRun File - [2006/04/19 17:20:48 | 000,000,000 | R–D | M] - K:\Autorun – [ UDF ]
O32 - AutoRun File - [2003/03/14 07:03:15 | 000,000,047 | R— | M] () - K:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2006/10/29 21:19:10 | 000,000,225 | R— | M] () - L:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005/04/05 01:33:44 | 000,049,152 | R— | M] () - M:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2003/08/20 00:25:27 | 000,000,044 | R— | M] () - M:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\Shell\AutoRun\command - "" = J:\Setup.exe – File not found
O33 - MountPoints2\{d89decb6-24ef-11df-b361-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d89decb6-24ef-11df-b361-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\Shell - "" = AutoRun
O33 - MountPoints2\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\Shell\AutoRun\command - "" = I:\autorun.exe – File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\autorun.exe – File not found
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autorun.exe – File not found
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\autorun.exe – File not found
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\autorun.exe – File not found
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\AutoRun.exe – [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive)
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (アリスソフト)
O33 - MountPoints2\L\Shell\directx\command - "" = L:\DirectX\DirectXInstallSelector.exe – [2001/11/26 02:18:02 | 000,045,056 | R— | M] (アリスソフト)
O33 - MountPoints2\L\Shell\setup\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (アリスソフト)
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe – [2005/04/05 01:33:44 | 000,049,152 | R— | M] ()
O33 - MountPoints2\N\Shell - "" = AutoRun
O33 - MountPoints2\N\Shell\AutoRun\command - "" = N:\AUTORUN.EXE – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2009/07/13 22:20:14 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:64bit: Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:64bit: BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias.dll (Microsoft Corporation)
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 90 Days ==========

[2010/05/12 23:22:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/12 23:10:32 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/05/12 22:54:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\JDownloader
[2010/05/12 21:53:23 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\dvdcss
[2010/05/06 15:18:09 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2010/05/06 15:03:17 | 000,069,152 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/05/06 15:03:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/05/06 15:02:57 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/05/06 15:02:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010/05/06 14:53:43 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/06 14:37:19 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/05/05 17:46:32 | 000,000,000 | —D | C] – C:\Users\Tri\Desktop\New folder
[2010/05/04 23:00:41 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\Malwarebytes
[2010/05/04 23:00:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/04 23:00:35 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 23:00:34 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/04 23:00:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/04/04 21:27:51 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\vlc
[2010/04/02 01:00:45 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/02 01:00:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/03/30 23:47:50 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\dBpoweramp
[2010/03/17 23:46:01 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\Ventrilo
[2010/03/17 23:45:57 | 000,000,000 | —D | C] – C:\Program Files\Ventrilo
[2010/03/17 08:07:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Coupons
[2010/03/16 14:18:15 | 000,012,976 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/03/15 05:58:09 | 000,098,304 | —- | C] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt.dll
[2010/03/15 05:54:27 | 000,000,000 | —D | C] – C:\Program Files\Ubisoft
[2010/03/15 05:54:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010/03/15 05:52:45 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010/03/14 22:24:03 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\SanDisk
[2010/03/13 15:14:17 | 000,000,000 | —D | C] – C:\Users\Tri\Documents\The Witcher
[2010/03/13 15:14:17 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Local\The Witcher
[2010/03/13 15:13:07 | 000,000,000 | —D | C] – C:\Users\Public\Documents\The Witcher
[2010/03/10 17:16:13 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Local\Real
[2010/03/10 17:15:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2010/03/07 00:43:10 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\AccurateRip
[2010/03/07 00:43:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Illustrate
[2010/03/04 19:17:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/03/04 19:17:31 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/03/04 03:38:16 | 000,000,000 | —D | C] – C:\Program Files\Leaf
[2010/03/02 13:18:51 | 000,000,000 | —D | C] – C:\Program Files\Defraggler
[2010/03/02 13:18:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/03/02 13:14:23 | 000,019,432 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\SysNative\drivers\cpuz132_x64.sys
[2010/03/02 13:14:23 | 000,000,000 | —D | C] – C:\Program Files\CPUID
[2010/02/26 00:26:02 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2010/02/23 02:48:43 | 000,000,000 | —D | C] – C:\Users\Tri\Unigine Heaven
[2010/02/23 02:48:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unigine

========== Files - Modified Within 90 Days ==========

[2010/05/13 18:14:28 | 003,145,728 | -HS- | M] () – C:\Users\Tri\NTUSER.DAT
[2010/05/13 18:01:08 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/13 18:01:08 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/13 17:59:28 | 059,957,768 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/05/13 17:58:13 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/13 17:58:13 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/13 17:58:13 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/13 17:54:04 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/13 17:53:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/13 17:53:55 | 529,068,031 | -HS- | M] () – C:\hiberfil.sys
[2010/05/13 03:33:49 | 001,665,805 | -H– | M] () – C:\Users\Tri\AppData\Local\IconCache.db
[2010/05/13 03:11:33 | 000,018,353 | —- | M] () – C:\Users\Tri\Documents\Dogs Don't Bite When a Growl Will Do.docx
[2010/05/12 21:00:37 | 000,016,033 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 6.docx
[2010/05/12 17:22:50 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/05/06 15:03:00 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/05/06 03:41:46 | 000,015,998 | —- | M] () – C:\Users\Tri\Documents\Works Cited for Psych Final.docx
[2010/05/06 03:40:57 | 000,020,579 | —- | M] () – C:\Users\Tri\Documents\Psych Final.docx
[2010/05/04 14:33:32 | 027,450,288 | —- | M] () – C:\Users\Tri\Desktop\DSCN0392.AVI
[2010/05/04 02:28:17 | 000,025,508 | —- | M] () – C:\Users\Tri\Documents\cc_20100504_022801.reg
[2010/05/04 02:07:39 | 000,018,845 | —- | M] () – C:\Users\Tri\Documents\Person Psych.docx
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/24 20:19:03 | 000,235,620 | —- | M] () – C:\Users\Tri\AppData\Local\prvlcl.dat
[2010/04/22 01:55:54 | 000,015,489 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 5.docx
[2010/04/20 23:21:33 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/08 02:43:10 | 000,015,372 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 4.docx
[2010/03/25 08:36:36 | 000,017,432 | —- | M] () – C:\Users\Tri\Documents\Chapter 6 Social Psych.docx
[2010/03/17 23:45:57 | 000,000,917 | —- | M] () – C:\Users\Tri\Desktop\Ventrilo.lnk
[2010/03/17 23:45:57 | 000,000,262 | —- | M] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/03/16 14:18:15 | 000,035,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/03/16 14:18:15 | 000,012,976 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/03/16 14:17:59 | 000,269,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/03/15 05:58:09 | 000,098,304 | —- | M] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt.dll
[2010/03/11 04:04:31 | 000,019,177 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 3.docx
[2010/03/10 17:15:14 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/03/07 00:43:08 | 000,010,105 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/03/07 00:43:07 | 002,857,336 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/03/07 00:43:07 | 000,033,846 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.bmp
[2010/03/07 00:43:07 | 000,014,645 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/03/07 00:42:57 | 000,033,846 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010/02/16 02:59:43 | 000,017,968 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 2.docx

========== Files Created - No Company Name ==========

[2010/05/12 21:55:03 | 000,018,353 | —- | C] () – C:\Users\Tri\Documents\Dogs Don't Bite When a Growl Will Do.docx
[2010/05/12 19:26:59 | 000,016,033 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 6.docx
[2010/05/06 15:03:00 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/05/06 02:47:48 | 000,015,998 | —- | C] () – C:\Users\Tri\Documents\Works Cited for Psych Final.docx
[2010/05/05 15:36:27 | 000,020,579 | —- | C] () – C:\Users\Tri\Documents\Psych Final.docx
[2010/05/04 15:40:13 | 027,450,288 | —- | C] () – C:\Users\Tri\Desktop\DSCN0392.AVI
[2010/05/04 02:28:04 | 000,025,508 | —- | C] () – C:\Users\Tri\Documents\cc_20100504_022801.reg
[2010/05/04 00:47:28 | 000,018,845 | —- | C] () – C:\Users\Tri\Documents\Person Psych.docx
[2010/04/30 22:36:14 | 000,040,075 | —- | C] () – C:\Users\Tri\Desktop\onestop.mid
[2010/04/22 01:55:54 | 000,015,489 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 5.docx
[2010/04/06 02:15:59 | 000,015,372 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 4.docx
[2010/03/23 00:51:32 | 000,017,432 | —- | C] () – C:\Users\Tri\Documents\Chapter 6 Social Psych.docx
[2010/03/17 23:45:57 | 000,000,917 | —- | C] () – C:\Users\Tri\Desktop\Ventrilo.lnk
[2010/03/17 23:45:57 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/03/11 01:12:37 | 000,019,177 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 3.docx
[2010/03/07 00:43:08 | 000,033,846 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.bmp
[2010/03/07 00:43:08 | 000,010,105 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/03/07 00:43:07 | 002,857,336 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/03/07 00:43:07 | 000,033,846 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010/03/07 00:43:07 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll

========== LOP Check ==========

[2010/02/02 22:01:44 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Acronis
[2009/11/26 17:31:20 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\DAEMON Tools Lite
[2010/03/30 23:47:50 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\dBpoweramp
[2009/12/26 22:51:16 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\runic games
[2010/03/14 22:24:03 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\SanDisk
[2010/05/13 01:51:08 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\uTorrent
[2010/02/18 19:43:06 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys

< %SYSTEMDRIVE%\*.exe >
[2008/04/11 09:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
< End of report >
Hello,

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
    O33 - MountPoints2\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\Shell\AutoRun\command - "" = J:\Setup.exe – File not found
    O33 - MountPoints2\{d89decb6-24ef-11df-b361-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{d89decb6-24ef-11df-b361-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
    O33 - MountPoints2\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\Shell - "" = AutoRun
    O33 - MountPoints2\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\Shell\AutoRun\command - "" = I:\autorun.exe – File not found
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\autorun.exe – File not found
    O33 - MountPoints2\E\Shell - "" = AutoRun
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe – File not found
    O33 - MountPoints2\H\Shell - "" = AutoRun
    O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autorun.exe – File not found
    O33 - MountPoints2\I\Shell - "" = AutoRun
    O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\autorun.exe – File not found
    O33 - MountPoints2\J\Shell - "" = AutoRun
    O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\autorun.exe – File not found
    O33 - MountPoints2\K\Shell - "" = AutoRun
    O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\AutoRun.exe – [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive)
    O33 - MountPoints2\L\Shell - "" = AutoRun
    O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (??????)
    O33 - MountPoints2\L\Shell\directx\command - "" = L:\DirectX\DirectXInstallSelector.exe – [2001/11/26 02:18:02 | 000,045,056 | R— | M] (??????)
    O33 - MountPoints2\L\Shell\setup\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (??????)
    O33 - MountPoints2\M\Shell - "" = AutoRun
    O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe – [2005/04/05 01:33:44 | 000,049,152 | R— | M] ()
    O33 - MountPoints2\N\Shell - "" = AutoRun
    O33 - MountPoints2\N\Shell\AutoRun\command - "" = N:\AUTORUN.EXE – File not found
    [2010/05/06 14:37:19 | 000,000,000 | —D | C] – C:\32788R22FWJFW
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • OTL Fix log
  • MBAM log
  • Kaspersky log
All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges not found.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ac71ad3-cf4f-11de-9723-806e6f6e6963}\ not found.
File J:\Setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d89decb6-24ef-11df-b361-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d89decb6-24ef-11df-b361-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d89decb6-24ef-11df-b361-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d89decb6-24ef-11df-b361-806e6f6e6963}\ not found.
File E:\setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc9cbe79-dad7-11de-af28-00248cfc83fc}\ not found.
File I:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found.
File D:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
File E:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
File F:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\ not found.
File H:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I\ not found.
File I:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\J\ not found.
File J:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found.
File move failed. K:\AutoRun.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ not found.
File move failed. L:\als_inst.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ not found.
File move failed. L:\DirectX\DirectXInstallSelector.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\L\ not found.
File move failed. L:\als_inst.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\M\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\M\ not found.
File move failed. M:\AutoRun.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\N\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\N\ not found.
File N:\AUTORUN.EXE not found.
C:\32788R22FWJFW\N_ folder moved successfully.
C:\32788R22FWJFW\License folder moved successfully.
C:\32788R22FWJFW\EN-US folder moved successfully.
C:\32788R22FWJFW folder moved successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 41620 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Tri
->Flash cache emptied: 48450 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Tri
->Temp folder emptied: 46368846 bytes
->Temporary Internet Files folder emptied: 27850853 bytes
->Java cache emptied: 45594624 bytes
->FireFox cache emptied: 93914868 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 74260 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 204.00 mb


OTL by OldTimer - Version 3.2.4.1 log created on 05142010_175824

Files\Folders moved on Reboot…
File\Folder K:\AutoRun.exe not found!
File\Folder L:\als_inst.exe not found!
File\Folder L:\DirectX\DirectXInstallSelector.exe not found!
File\Folder M:\AutoRun.exe not found!
C:\Users\Tri\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4103

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

5/14/2010 5:54:23 PM
mbam-log-2010-05-14 (17-54-23).txt

Scan type: Quick scan
Objects scanned: 116625
Time elapsed: 2 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e1d0932f-cc5f-4a57-a043-39c0a4e7e901}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

The program is starting. Please wait…
Updates source is selected: http://www.kaspersky.com
File download: packages/kos-extras.jar
null

null
Updates source is selected: http://downloads1.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads1.kaspersky-labs.com
Updates source is selected: ftp://downloads4.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: ftp://downloads2.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: ftp://downloads5.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: http://downloads5.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads5.kaspersky-labs.com
Updates source is selected: http://downloads3.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads3.kaspersky-labs.com
Updates source is selected: ftp://downloads3.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: http://downloads4.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads4.kaspersky-labs.com
Updates source is selected: ftp://downloads1.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: http://downloads2.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads2.kaspersky-labs.com

0 [ERROR: Connection to updates source cannot be established]
Hi,

Please run this for me and post the log:

🖼Click to load external image (Posted Image) Double click on OTL to open it
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of that file.
OTL logfile created on: 5/14/2010 9:06:30 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Tri\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 69.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 558.82 Gb Total Space | 434.41 Gb Free Space | 77.74% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 175.22 Gb Free Space | 18.81% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 298.09 Gb Total Space | 278.72 Gb Free Space | 93.50% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 2.45 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 1.84 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive M: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TRI-PC
Current User Name: Tri
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Tri\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcfgex.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - C:\Users\Tri\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (VSS) – C:\Windows\Vss [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (cpuz132) – C:\Windows\SysNative\drivers\cpuz132_x64.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (CSC) – C:\Windows\CSC [2009/11/12 00:49:06 | 000,000,000 | —D | M]
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C BC 58 C0 C5 F3 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "cheapassgamer.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: {6dd0bdba-0a02-429e-b595-87a7dfdca7a1}:0.7.7
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: [removed]:0.5.2010043001
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.7.4
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: {f701c26a-479a-4724-b4f1-870db12f063c}:1.4.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/05/12 20:26:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/10 17:15:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/03 00:39:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/04/20 23:21:33 | 000,000,000 | —D | M]

[2009/11/11 23:02:22 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Extensions
[2010/05/14 19:12:48 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions
[2009/12/08 15:10:28 | 000,000,000 | —D | M] (Session Manager) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2010/02/19 11:05:51 | 000,000,000 | —D | M] (Linkification) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010/05/13 01:23:14 | 000,000,000 | —D | M] (GameFOX) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{6dd0bdba-0a02-429e-b595-87a7dfdca7a1}
[2010/05/04 00:13:58 | 000,000,000 | —D | M] (NoScript) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/11/11 23:38:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/04/09 22:53:19 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/01/26 15:25:33 | 000,000,000 | —D | M] (Text-to-Image) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{f701c26a-479a-4724-b4f1-870db12f063c}
[2010/05/06 14:15:13 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\[removed]
[2010/05/13 17:53:54 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/19 12:46:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2009/11/14 15:02:07 | 000,000,988 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 www.alcohol-soft.com
O1 - Hosts: 127.0.0.1 images.alcohol-soft.com
O1 - Hosts: 127.0.0.1 trial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 alcohol-soft.com
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive) - K:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2006/04/05 12:38:16 | 000,050,534 | R— | M] () - K:\AutoRun.ico – [ UDF ]
O32 - AutoRun File - [2006/04/19 17:20:48 | 000,000,000 | R–D | M] - K:\Autorun – [ UDF ]
O32 - AutoRun File - [2003/03/14 07:03:15 | 000,000,047 | R— | M] () - K:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2006/10/29 21:19:10 | 000,000,225 | R— | M] () - L:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005/04/05 01:33:44 | 000,049,152 | R— | M] () - M:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2003/08/20 00:25:27 | 000,000,044 | R— | M] () - M:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\AutoRun.exe – [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive)
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (アリスソフト)
O33 - MountPoints2\L\Shell\directx\command - "" = L:\DirectX\DirectXInstallSelector.exe – [2001/11/26 02:18:02 | 000,045,056 | R— | M] (アリスソフト)
O33 - MountPoints2\L\Shell\setup\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (アリスソフト)
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe – [2005/04/05 01:33:44 | 000,049,152 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/05/14 17:58:24 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/14 17:57:49 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Tri\Desktop\OTL.exe
[2010/05/12 23:22:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/12 23:10:32 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/05/12 22:54:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\JDownloader
[2010/05/12 21:53:23 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\dvdcss
[2010/05/06 15:18:09 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2010/05/06 15:03:17 | 000,069,152 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/05/06 15:03:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/05/06 15:02:57 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/05/06 15:02:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010/05/06 14:53:43 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/05 17:46:32 | 000,000,000 | —D | C] – C:\Users\Tri\Desktop\New folder
[2010/05/04 23:00:41 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\Malwarebytes
[2010/05/04 23:00:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/04 23:00:35 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 23:00:34 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/04 23:00:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/04/04 21:27:51 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\vlc
[2010/04/02 01:00:45 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/02 01:00:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/03/30 23:47:50 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\dBpoweramp
[2010/03/17 23:46:01 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\Ventrilo
[2010/03/17 23:45:57 | 000,000,000 | —D | C] – C:\Program Files\Ventrilo
[2010/03/17 08:07:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Coupons
[2010/03/16 14:18:15 | 000,012,976 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/03/15 05:58:09 | 000,098,304 | —- | C] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt.dll
[2010/03/15 05:54:27 | 000,000,000 | —D | C] – C:\Program Files\Ubisoft
[2010/03/15 05:54:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010/03/15 05:52:45 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010/03/14 22:24:03 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\SanDisk
[2010/03/13 15:14:17 | 000,000,000 | —D | C] – C:\Users\Tri\Documents\The Witcher
[2010/03/13 15:14:17 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Local\The Witcher
[2010/03/13 15:13:07 | 000,000,000 | —D | C] – C:\Users\Public\Documents\The Witcher
[2010/03/10 17:16:13 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Local\Real
[2010/03/10 17:15:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2010/03/07 00:43:10 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\AccurateRip
[2010/03/07 00:43:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Illustrate
[2010/03/04 19:17:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/03/04 19:17:31 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/03/04 03:38:16 | 000,000,000 | —D | C] – C:\Program Files\Leaf
[2010/03/02 13:18:51 | 000,000,000 | —D | C] – C:\Program Files\Defraggler
[2010/03/02 13:18:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/03/02 13:14:23 | 000,019,432 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\SysNative\drivers\cpuz132_x64.sys
[2010/03/02 13:14:23 | 000,000,000 | —D | C] – C:\Program Files\CPUID
[2010/02/26 00:26:02 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2010/02/23 02:48:43 | 000,000,000 | —D | C] – C:\Users\Tri\Unigine Heaven
[2010/02/23 02:48:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unigine

========== Files - Modified Within 90 Days ==========

[2010/05/14 21:06:51 | 003,145,728 | -HS- | M] () – C:\Users\Tri\NTUSER.DAT
[2010/05/14 18:07:02 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/14 18:07:02 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/14 18:04:02 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/14 18:04:02 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/14 18:04:02 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/14 17:59:54 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/14 17:59:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/14 17:59:49 | 529,068,031 | -HS- | M] () – C:\hiberfil.sys
[2010/05/14 17:58:48 | 001,670,439 | -H– | M] () – C:\Users\Tri\AppData\Local\IconCache.db
[2010/05/14 17:11:57 | 059,999,323 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/05/13 23:06:33 | 000,334,152 | —- | M] () – C:\Users\Tri\AppData\Local\prvlcl.dat
[2010/05/13 18:10:42 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Tri\Desktop\OTL.exe
[2010/05/13 03:11:33 | 000,018,353 | —- | M] () – C:\Users\Tri\Documents\Dogs Don't Bite When a Growl Will Do.docx
[2010/05/12 21:00:37 | 000,016,033 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 6.docx
[2010/05/12 17:22:50 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/05/06 15:03:00 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/05/06 03:41:46 | 000,015,998 | —- | M] () – C:\Users\Tri\Documents\Works Cited for Psych Final.docx
[2010/05/06 03:40:57 | 000,020,579 | —- | M] () – C:\Users\Tri\Documents\Psych Final.docx
[2010/05/04 14:33:32 | 027,450,288 | —- | M] () – C:\Users\Tri\Desktop\DSCN0392.AVI
[2010/05/04 02:28:17 | 000,025,508 | —- | M] () – C:\Users\Tri\Documents\cc_20100504_022801.reg
[2010/05/04 02:07:39 | 000,018,845 | —- | M] () – C:\Users\Tri\Documents\Person Psych.docx
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/22 01:55:54 | 000,015,489 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 5.docx
[2010/04/20 23:21:33 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/08 02:43:10 | 000,015,372 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 4.docx
[2010/03/25 08:36:36 | 000,017,432 | —- | M] () – C:\Users\Tri\Documents\Chapter 6 Social Psych.docx
[2010/03/17 23:45:57 | 000,000,917 | —- | M] () – C:\Users\Tri\Desktop\Ventrilo.lnk
[2010/03/17 23:45:57 | 000,000,262 | —- | M] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/03/16 14:18:15 | 000,035,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/03/16 14:18:15 | 000,012,976 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/03/16 14:17:59 | 000,269,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/03/15 05:58:09 | 000,098,304 | —- | M] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt.dll
[2010/03/11 04:04:31 | 000,019,177 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 3.docx
[2010/03/10 17:15:14 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/03/07 00:43:08 | 000,010,105 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/03/07 00:43:07 | 002,857,336 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/03/07 00:43:07 | 000,033,846 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.bmp
[2010/03/07 00:43:07 | 000,014,645 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/03/07 00:42:57 | 000,033,846 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010/02/16 02:59:43 | 000,017,968 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 2.docx

========== Files Created - No Company Name ==========

[2010/05/12 21:55:03 | 000,018,353 | —- | C] () – C:\Users\Tri\Documents\Dogs Don't Bite When a Growl Will Do.docx
[2010/05/12 19:26:59 | 000,016,033 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 6.docx
[2010/05/06 15:03:00 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/05/06 02:47:48 | 000,015,998 | —- | C] () – C:\Users\Tri\Documents\Works Cited for Psych Final.docx
[2010/05/05 15:36:27 | 000,020,579 | —- | C] () – C:\Users\Tri\Documents\Psych Final.docx
[2010/05/04 15:40:13 | 027,450,288 | —- | C] () – C:\Users\Tri\Desktop\DSCN0392.AVI
[2010/05/04 02:28:04 | 000,025,508 | —- | C] () – C:\Users\Tri\Documents\cc_20100504_022801.reg
[2010/05/04 00:47:28 | 000,018,845 | —- | C] () – C:\Users\Tri\Documents\Person Psych.docx
[2010/04/30 22:36:14 | 000,040,075 | —- | C] () – C:\Users\Tri\Desktop\onestop.mid
[2010/04/22 01:55:54 | 000,015,489 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 5.docx
[2010/04/06 02:15:59 | 000,015,372 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 4.docx
[2010/03/23 00:51:32 | 000,017,432 | —- | C] () – C:\Users\Tri\Documents\Chapter 6 Social Psych.docx
[2010/03/17 23:45:57 | 000,000,917 | —- | C] () – C:\Users\Tri\Desktop\Ventrilo.lnk
[2010/03/17 23:45:57 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/03/11 01:12:37 | 000,019,177 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 3.docx
[2010/03/07 00:43:08 | 000,033,846 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.bmp
[2010/03/07 00:43:08 | 000,010,105 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/03/07 00:43:07 | 002,857,336 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/03/07 00:43:07 | 000,033,846 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010/03/07 00:43:07 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll

========== LOP Check ==========

[2010/02/02 22:01:44 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Acronis
[2009/11/26 17:31:20 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\DAEMON Tools Lite
[2010/03/30 23:47:50 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\dBpoweramp
[2009/12/26 22:51:16 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\runic games
[2010/03/14 22:24:03 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\SanDisk
[2010/05/13 01:51:08 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\uTorrent
[2010/02/18 19:43:06 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
OK, thanks. I've got to call it a night , but I"ll have fresh instructions for you tomorrow morning. Thanks for you patience.
Hello,

I believe the malware has changed the DNS server settings in your router. Read these instructions carefully, they are different this time:

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
  • Disconnect your computer from the router
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Do a hard reset (back to factory defaults) on your router. Usually there is a small button to push on the back of the router, but check you router's documentation to be sure. When you set it back up change the default admin login and password. Only after you've reset the router, hook the PC back up to it and try the Kaspersky scan again.
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Tri\Desktop\cmd.bat deleted successfully.
C:\Users\Tri\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: Tri
->Flash cache emptied: 1084 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Tri
->Temp folder emptied: 38428907 bytes
->Temporary Internet Files folder emptied: 3937810 bytes
->Java cache emptied: 128094 bytes
->FireFox cache emptied: 92989677 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 66964 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 129.00 mb


OTL by OldTimer - Version 3.2.4.1 log created on 05162010_173328

Files\Folders moved on Reboot…
C:\Users\Tri\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…





I'm still getting the connection cannot be established. Would it be better to drop AVG for Kaspersky?

The program is starting. Please wait…
Updates source is selected: http://www.kaspersky.com
File download: packages/kos-bin-winnt-redist.jar
File download: packages/kos-bin-winnt-engine.jar
File download: packages/kos-bin-winnt.jar
File download: packages/kos-extras.jar
null

null
Updates source is selected: ftp://downloads3.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: ftp://downloads4.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: http://downloads3.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads3.kaspersky-labs.com
Updates source is selected: ftp://downloads5.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: http://downloads1.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads1.kaspersky-labs.com
Updates source is selected: http://downloads2.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads2.kaspersky-labs.com
Updates source is selected: http://downloads5.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads5.kaspersky-labs.com
Updates source is selected: ftp://downloads1.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: ftp://downloads2.kaspersky-labs.com/
File download: index/master.xml.klz
Updates source is selected: http://downloads4.kaspersky-labs.com/
File download: index/master.xml.klz
Connection to updates source cannot be established: downloads4.kaspersky-labs.com

0 [ERROR: Connection to updates source cannot be established]
Don't change any programs until we get this sorted out. Please open your router's configuration page and check the DNS server settings. Let me know what they are.

🖼Click to load external image (Posted Image) Double click on OTL to open it
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of that file.
Please include the following in your next post:
  • The DNS settings from your router
  • A new OTL log
Do you mean the Router Status or the Dynamic DNS? That's all that comes up when I pull up my router settings.

Setup Wizard
Setup
Basic Settings
Wireless Settings
Content Filtering
Logs
Block Sites
Block Services
Schedule
E-mail
Maintenance
Router Status
Attached Devices
Backup Settings
Set Password
Router Upgrade
Advanced
Wireless Settings
Port Forwarding / Port Triggering
WAN Setup
LAN IP Setup
Dynamic DNS
Static Routes
Remote Management
UPnP


OTL logfile created on: 5/16/2010 7:45:09 PM - Run 3
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Tri\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 69.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 558.82 Gb Total Space | 434.38 Gb Free Space | 77.73% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 156.45 Gb Free Space | 16.80% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 298.09 Gb Total Space | 278.72 Gb Free Space | 93.50% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 2.45 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive L: | 1.84 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive M: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: TRI-PC
Current User Name: Tri
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Tri\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Java\jre6\bin\jp2launcher.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - C:\Users\Tri\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WatAdminSvc) – C:\Windows\SysNative\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WwanSvc) – C:\Windows\SysNative\wwansvc.dll (Microsoft Corporation)
SRV:64bit: - (WbioSrvc) – C:\Windows\SysNative\wbiosrvc.dll (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (Power) – C:\Windows\SysNative\umpo.dll (Microsoft Corporation)
SRV:64bit: - (Themes) – C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
SRV:64bit: - (sppuinotify) – C:\Windows\SysNative\sppuinotify.dll (Microsoft Corporation)
SRV:64bit: - (SensrSvc) – C:\Windows\SysNative\sensrsvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (PNRPsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (p2pimsvc) – C:\Windows\SysNative\pnrpsvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupProvider) – C:\Windows\SysNative\provsvc.dll (Microsoft Corporation)
SRV:64bit: - (RpcEptMapper) – C:\Windows\SysNative\RpcEpMap.dll (Microsoft Corporation)
SRV:64bit: - (PNRPAutoReg) – C:\Windows\SysNative\pnrpauto.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (HomeGroupListener) – C:\Windows\SysNative\ListSvc.dll (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (Dhcp) – C:\Windows\SysNative\dhcpcore.dll (Microsoft Corporation)
SRV:64bit: - (defragsvc) – C:\Windows\SysNative\defragsvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (bthserv) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:64bit: - (BDESVC) – C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
SRV:64bit: - (AxInstSV) – C:\Windows\SysNative\AxInstSv.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AppIDSvc) – C:\Windows\SysNative\appidsvc.dll (Microsoft Corporation)
SRV:64bit: - (wbengine) – C:\Windows\SysNative\wbengine.exe (Microsoft Corporation)
SRV:64bit: - (sppsvc) – C:\Windows\SysNative\sppsvc.exe (Microsoft Corporation)
SRV:64bit: - (Fax) – C:\Windows\SysNative\FXSSVC.exe (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (VSS) – C:\Windows\Vss [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2009/07/13 22:20:14 | 000,000,000 | —D | M]
SRV - (HomeGroupProvider) – C:\Windows\SysWOW64\provsvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\SysWOW64\dhcpcore.dll (Microsoft Corporation)
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (SCDEmu) – C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (KSecPkg) – C:\Windows\SysNative\drivers\ksecpkg.sys (Microsoft Corporation)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (hwpolicy) – C:\Windows\SysNative\drivers\hwpolicy.sys (Microsoft Corporation)
DRV:64bit: - (FsDepends) – C:\Windows\SysNative\drivers\fsdepends.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (WIMMount) – C:\Windows\SysNative\drivers\wimmount.sys (Microsoft Corporation)
DRV:64bit: - (vhdmp) – C:\Windows\SysNative\drivers\vhdmp.sys (Microsoft Corporation)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (vdrvroot) – C:\Windows\SysNative\drivers\vdrvroot.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (rdyboost) – C:\Windows\SysNative\drivers\rdyboost.sys (Microsoft Corporation)
DRV:64bit: - (pcw) – C:\Windows\SysNative\drivers\pcw.sys (Microsoft Corporation)
DRV:64bit: - (CNG) – C:\Windows\SysNative\drivers\cng.sys (Microsoft Corporation)
DRV:64bit: - (fvevol) – C:\Windows\SysNative\drivers\fvevol.sys (Microsoft Corporation)
DRV:64bit: - (rdpbus) – C:\Windows\SysNative\drivers\rdpbus.sys (Microsoft Corporation)
DRV:64bit: - (RDPREFMP) – C:\Windows\SysNative\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV:64bit: - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\SysNative\drivers\agilevpn.sys (Microsoft Corporation)
DRV:64bit: - (WfpLwf) – C:\Windows\SysNative\drivers\wfplwf.sys (Microsoft Corporation)
DRV:64bit: - (NdisCap) – C:\Windows\SysNative\drivers\ndiscap.sys (Microsoft Corporation)
DRV:64bit: - (vwifibus) – C:\Windows\SysNative\drivers\vwifibus.sys (Microsoft Corporation)
DRV:64bit: - (1394ohci) – C:\Windows\SysNative\drivers\1394ohci.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (UmPass) – C:\Windows\SysNative\drivers\umpass.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV:64bit: - (WinUsb) – C:\Windows\SysNative\drivers\winusb.sys (Microsoft Corporation)
DRV:64bit: - (mshidkmdf) – C:\Windows\SysNative\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV:64bit: - (WudfPf) – C:\Windows\SysNative\drivers\WUDFPf.sys (Microsoft Corporation)
DRV:64bit: - (MTConfig) – C:\Windows\SysNative\drivers\MTConfig.sys (Microsoft Corporation)
DRV:64bit: - (CompositeBus) – C:\Windows\SysNative\drivers\CompositeBus.sys (Microsoft Corporation)
DRV:64bit: - (Beep) – C:\Windows\SysNative\drivers\beep.sys (Microsoft Corporation)
DRV:64bit: - (AppID) – C:\Windows\SysNative\drivers\appid.sys (Microsoft Corporation)
DRV:64bit: - (scfilter) – C:\Windows\SysNative\drivers\scfilter.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (discache) – C:\Windows\SysNative\drivers\discache.sys (Microsoft Corporation)
DRV:64bit: - (HidBatt) – C:\Windows\SysNative\drivers\hidbatt.sys (Microsoft Corporation)
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\drivers\CmBatt.sys (Microsoft Corporation)
DRV:64bit: - (AcpiPmi) – C:\Windows\SysNative\drivers\acpipmi.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (AmdPPM) – C:\Windows\SysNative\drivers\amdppm.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (cpuz132) – C:\Windows\SysNative\drivers\cpuz132_x64.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (CSC) – C:\Windows\CSC [2009/11/12 00:49:06 | 000,000,000 | —D | M]
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\SysWOW64\winusb.dll (Microsoft Corporation)
DRV - (NetBIOS) – C:\Windows\SysWOW64\netbios.dll (Microsoft Corporation)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C BC 58 C0 C5 F3 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "cheapassgamer.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: {6dd0bdba-0a02-429e-b595-87a7dfdca7a1}:0.7.7
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: [removed]:0.5.2010043001
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.7.4
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: {f701c26a-479a-4724-b4f1-870db12f063c}:1.4.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/05/12 20:26:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/10 17:15:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/03 00:39:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/04/20 23:21:33 | 000,000,000 | —D | M]

[2009/11/11 23:02:22 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Extensions
[2010/05/16 19:41:38 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions
[2009/12/08 15:10:28 | 000,000,000 | —D | M] (Session Manager) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}
[2010/02/19 11:05:51 | 000,000,000 | —D | M] (Linkification) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010/05/13 01:23:14 | 000,000,000 | —D | M] (GameFOX) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{6dd0bdba-0a02-429e-b595-87a7dfdca7a1}
[2010/05/04 00:13:58 | 000,000,000 | —D | M] (NoScript) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/11/11 23:38:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/04/09 22:53:19 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/01/26 15:25:33 | 000,000,000 | —D | M] (Text-to-Image) – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\{f701c26a-479a-4724-b4f1-870db12f063c}
[2010/05/06 14:15:13 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Mozilla\Firefox\Profiles\s4n0d8wr.default\extensions\[removed]
[2010/05/13 17:53:54 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/19 12:46:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2009/11/14 15:02:07 | 000,000,988 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 www.alcohol-soft.com
O1 - Hosts: 127.0.0.1 images.alcohol-soft.com
O1 - Hosts: 127.0.0.1 trial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 alcohol-soft.com
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Tri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive) - K:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2006/04/05 12:38:16 | 000,050,534 | R— | M] () - K:\AutoRun.ico – [ UDF ]
O32 - AutoRun File - [2006/04/19 17:20:48 | 000,000,000 | R–D | M] - K:\Autorun – [ UDF ]
O32 - AutoRun File - [2003/03/14 07:03:15 | 000,000,047 | R— | M] () - K:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2006/10/29 21:19:10 | 000,000,225 | R— | M] () - L:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005/04/05 01:33:44 | 000,049,152 | R— | M] () - M:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2003/08/20 00:25:27 | 000,000,044 | R— | M] () - M:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\AutoRun.exe – [2006/04/11 11:15:11 | 000,323,584 | R— | M] (Nival Interactive)
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (アリスソフト)
O33 - MountPoints2\L\Shell\directx\command - "" = L:\DirectX\DirectXInstallSelector.exe – [2001/11/26 02:18:02 | 000,045,056 | R— | M] (アリスソフト)
O33 - MountPoints2\L\Shell\setup\command - "" = L:\als_inst.exe – [2006/06/26 00:33:46 | 000,163,840 | R— | M] (アリスソフト)
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe – [2005/04/05 01:33:44 | 000,049,152 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/05/14 17:58:24 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/14 17:57:49 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Tri\Desktop\OTL.exe
[2010/05/12 23:22:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/12 23:10:32 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/05/12 22:54:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\JDownloader
[2010/05/12 21:53:23 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\dvdcss
[2010/05/06 15:18:09 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2010/05/06 15:03:17 | 000,069,152 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2010/05/06 15:03:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/05/06 15:02:57 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/05/06 15:02:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2010/05/06 14:53:43 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/05 17:46:32 | 000,000,000 | —D | C] – C:\Users\Tri\Desktop\New folder
[2010/05/04 23:00:41 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\Malwarebytes
[2010/05/04 23:00:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/04 23:00:35 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 23:00:34 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/04 23:00:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/04/04 21:27:51 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\vlc
[2010/04/02 01:00:45 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/02 01:00:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/03/30 23:47:50 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\dBpoweramp
[2010/03/17 23:46:01 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\Ventrilo
[2010/03/17 23:45:57 | 000,000,000 | —D | C] – C:\Program Files\Ventrilo
[2010/03/17 08:07:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Coupons
[2010/03/16 14:18:15 | 000,012,976 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/03/15 05:58:09 | 000,098,304 | —- | C] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt.dll
[2010/03/15 05:54:27 | 000,000,000 | —D | C] – C:\Program Files\Ubisoft
[2010/03/15 05:54:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2010/03/15 05:52:45 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2010/03/14 22:24:03 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\SanDisk
[2010/03/13 15:14:17 | 000,000,000 | —D | C] – C:\Users\Tri\Documents\The Witcher
[2010/03/13 15:14:17 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Local\The Witcher
[2010/03/13 15:13:07 | 000,000,000 | —D | C] – C:\Users\Public\Documents\The Witcher
[2010/03/10 17:16:13 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Local\Real
[2010/03/10 17:15:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2010/03/07 00:43:10 | 000,000,000 | —D | C] – C:\Users\Tri\AppData\Roaming\AccurateRip
[2010/03/07 00:43:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Illustrate
[2010/03/04 19:17:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/03/04 19:17:31 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/03/04 03:38:16 | 000,000,000 | —D | C] – C:\Program Files\Leaf
[2010/03/02 13:18:51 | 000,000,000 | —D | C] – C:\Program Files\Defraggler
[2010/03/02 13:18:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\CCleaner
[2010/03/02 13:14:23 | 000,019,432 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\SysNative\drivers\cpuz132_x64.sys
[2010/03/02 13:14:23 | 000,000,000 | —D | C] – C:\Program Files\CPUID
[2010/02/26 00:26:02 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2010/02/23 02:48:43 | 000,000,000 | —D | C] – C:\Users\Tri\Unigine Heaven
[2010/02/23 02:48:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unigine

========== Files - Modified Within 90 Days ==========

[2010/05/16 19:46:06 | 003,145,728 | -HS- | M] () – C:\Users\Tri\NTUSER.DAT
[2010/05/16 17:41:51 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/16 17:41:51 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/16 17:39:09 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/16 17:39:09 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/16 17:39:09 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/16 17:34:57 | 000,000,394 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/05/16 17:34:44 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/16 17:34:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/16 17:34:39 | 529,068,031 | -HS- | M] () – C:\hiberfil.sys
[2010/05/16 17:19:46 | 060,054,673 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/05/16 01:39:17 | 001,680,248 | -H– | M] () – C:\Users\Tri\AppData\Local\IconCache.db
[2010/05/15 15:19:38 | 000,758,268 | —- | M] () – C:\Users\Tri\AppData\Local\prvlcl.dat
[2010/05/13 18:10:42 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Tri\Desktop\OTL.exe
[2010/05/13 03:11:33 | 000,018,353 | —- | M] () – C:\Users\Tri\Documents\Dogs Don't Bite When a Growl Will Do.docx
[2010/05/12 21:00:37 | 000,016,033 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 6.docx
[2010/05/12 17:22:50 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/05/06 15:03:00 | 000,001,142 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/05/06 03:41:46 | 000,015,998 | —- | M] () – C:\Users\Tri\Documents\Works Cited for Psych Final.docx
[2010/05/06 03:40:57 | 000,020,579 | —- | M] () – C:\Users\Tri\Documents\Psych Final.docx
[2010/05/04 14:33:32 | 027,450,288 | —- | M] () – C:\Users\Tri\Desktop\DSCN0392.AVI
[2010/05/04 02:28:17 | 000,025,508 | —- | M] () – C:\Users\Tri\Documents\cc_20100504_022801.reg
[2010/05/04 02:07:39 | 000,018,845 | —- | M] () – C:\Users\Tri\Documents\Person Psych.docx
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/22 01:55:54 | 000,015,489 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 5.docx
[2010/04/20 23:21:33 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/08 02:43:10 | 000,015,372 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 4.docx
[2010/03/25 08:36:36 | 000,017,432 | —- | M] () – C:\Users\Tri\Documents\Chapter 6 Social Psych.docx
[2010/03/17 23:45:57 | 000,000,917 | —- | M] () – C:\Users\Tri\Desktop\Ventrilo.lnk
[2010/03/17 23:45:57 | 000,000,262 | —- | M] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/03/16 14:18:15 | 000,035,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/03/16 14:18:15 | 000,012,976 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/03/16 14:17:59 | 000,269,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/03/15 05:58:09 | 000,098,304 | —- | M] (Sony DADC Austria AG.) – C:\Windows\SysWow64\CmdLineExt.dll
[2010/03/11 04:04:31 | 000,019,177 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 3.docx
[2010/03/10 17:15:14 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/03/07 00:43:08 | 000,010,105 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/03/07 00:43:07 | 002,857,336 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/03/07 00:43:07 | 000,033,846 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.bmp
[2010/03/07 00:43:07 | 000,014,645 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/03/07 00:42:57 | 000,033,846 | —- | M] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010/02/16 02:59:43 | 000,017,968 | —- | M] () – C:\Users\Tri\Documents\Ethics Unit 2.docx

========== Files Created - No Company Name ==========

[2010/05/16 17:34:57 | 000,000,394 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/05/12 21:55:03 | 000,018,353 | —- | C] () – C:\Users\Tri\Documents\Dogs Don't Bite When a Growl Will Do.docx
[2010/05/12 19:26:59 | 000,016,033 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 6.docx
[2010/05/06 15:03:00 | 000,001,142 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/05/06 02:47:48 | 000,015,998 | —- | C] () – C:\Users\Tri\Documents\Works Cited for Psych Final.docx
[2010/05/05 15:36:27 | 000,020,579 | —- | C] () – C:\Users\Tri\Documents\Psych Final.docx
[2010/05/04 15:40:13 | 027,450,288 | —- | C] () – C:\Users\Tri\Desktop\DSCN0392.AVI
[2010/05/04 02:28:04 | 000,025,508 | —- | C] () – C:\Users\Tri\Documents\cc_20100504_022801.reg
[2010/05/04 00:47:28 | 000,018,845 | —- | C] () – C:\Users\Tri\Documents\Person Psych.docx
[2010/04/30 22:36:14 | 000,040,075 | —- | C] () – C:\Users\Tri\Desktop\onestop.mid
[2010/04/22 01:55:54 | 000,015,489 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 5.docx
[2010/04/06 02:15:59 | 000,015,372 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 4.docx
[2010/03/23 00:51:32 | 000,017,432 | —- | C] () – C:\Users\Tri\Documents\Chapter 6 Social Psych.docx
[2010/03/17 23:45:57 | 000,000,917 | —- | C] () – C:\Users\Tri\Desktop\Ventrilo.lnk
[2010/03/17 23:45:57 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/03/11 01:12:37 | 000,019,177 | —- | C] () – C:\Users\Tri\Documents\Ethics Unit 3.docx
[2010/03/07 00:43:08 | 000,033,846 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.bmp
[2010/03/07 00:43:08 | 000,010,105 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2010/03/07 00:43:07 | 002,857,336 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2010/03/07 00:43:07 | 000,033,846 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.bmp
[2010/03/07 00:43:07 | 000,014,645 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll

========== LOP Check ==========

[2010/02/02 22:01:44 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\Acronis
[2009/11/26 17:31:20 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\DAEMON Tools Lite
[2010/03/30 23:47:50 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\dBpoweramp
[2009/12/26 22:51:16 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\runic games
[2010/03/14 22:24:03 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\SanDisk
[2010/05/16 19:17:34 | 000,000,000 | —D | M] – C:\Users\Tri\AppData\Roaming\uTorrent
[2010/05/16 17:34:57 | 000,000,394 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/02/18 19:43:06 | 000,032,586 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


< End of report >
I'm interested in any DNS settings in the router. Please run this for me also:

🖼Click to load external image (Posted Image) Please download GooredFixfrom one of the locations below and save it to your desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI