This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] slow computer after infection

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

computer has been slow since recent malware/trojan infection. I currently use AVG,Spy bot, and Ad-aware.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:08:06 AM, on 5/13/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\WinZip\WZQKPICK.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\hp\kbd\kbd.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\TaskControl\TaskControl.exe
C:\Program Files (x86)\PokerStars\PokerStars.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Audacity\audacity.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\TrendMicro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~2\Google\GOOGLE~4\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1ca7c492b772bb8) (gupdate1ca7c492b772bb8) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 13886 bytes
Hello there, kaudu

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

1. All tools MUST be run from the executable. (.exe)
With Admin Rights (Right click, choose "Run as Administrator")


Multiple AntiVirus Running

I see you have more than one Anti-Virus program installed, ( AVG 9 ) and ( McAfee ).

While this may seem like greater protection, it can cause problems including slowdowns, system hangs or even crashes. This can happen if both AntiVirus applications attempt to access the same file at the same time. This may cause the applications to interfere with each other, or cause the system to lock up. It can also be a drain on system resources, making a machine run slower than it should.

Any reason why you installed AVG? Did your McAfee expire?

Any antivirus program must be removed via add/remove program.
For any program that doesn't have an add/remove entry, you will have to do this:

Re-install the program -> Reboot -> Uninstall


1. Download the removal tool from here: http://download.mcafee.com/products/licens…atches/MCPR.exe
2. Click Save and save the file to a folder on your computer.
3. Navigate to the folder where the file was saved.
4. Double-click MCPR.exe to run the removal tool.
Vista Note: Right click MCPR.EXE and choose "Run as administrator"
The McAfee product will be fully removed when the system is restarted.

——

AVG has a removal tool which should also be run if you choose to uninstall it

http://www.avg.com/download-tools

Choose the 64bit remover

Run it according to the instructions.

===================================================

Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.(If exist)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555


Note : Do not worry if you are unable to find any of these entries, continue with the ones that you discovered. Now close all windows other than HijackThis, then click Fix checked. Close HijackThis.

===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
I prefer AVG because the Mcaffe on this computer is just a scan plus, but it seems to be lower in quality. Is AVG bad or should I just make sure I have 1 virus program?
Also the GMER rootkit scanner first 8 boxes were unchecked ,and grayed out. I ran a scan but there was no log information. I screencaped at the bottom of second post.




Here are my logs:

OLT.txt

OTL logfile created on: 5/15/2010 1:02:12 AM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Paul\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 585.12 Gb Total Space | 539.48 Gb Free Space | 92.20% Space Free | Partition Type: NTFS
Drive D: | 11.05 Gb Total Space | 1.47 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Paul
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Paul\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Winamp\winampa.exe ()
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Users\Paul\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WLSetupSvc) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 06:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) – C:\Windows\SysNative\DRIVERS\Lbd.sys (Lavasoft AB)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (CAXHWBS3) – C:\Windows\SysNative\DRIVERS\CAXHWBS3.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iastor.sys (Intel Corporation)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (mdmxsdk) – C:\Windows\SysWOW64\mdmxsdk.dll (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems: {f035aa18-ee32-4e6e-81d2-57e32867f8a7}:1.17
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}:0.7.23
FF - prefs.js..extensions.enabledItems: {8ea9957e-2953-402f-80e0-bceb5f169d6f}:0.5.3
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: avg@igeared:4.002.023.004
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:3.6.6.117
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_us&p;="

FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/05/15 00:44:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/17 18:56:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/17 18:56:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/02 18:08:47 | 000,000,000 | —D | M]

[2009/12/12 23:42:28 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2010/05/15 00:50:52 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions
[2010/04/28 06:10:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/24 02:39:57 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/04/24 02:39:57 | 000,000,000 | —D | M] (XHTML Mobile Profile) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{8ea9957e-2953-402f-80e0-bceb5f169d6f}
[2009/12/24 12:14:39 | 000,000,000 | —D | M] (Web Developer) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/04/24 02:39:57 | 000,000,000 | —D | M] (wmlbrowser) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}
[2010/04/24 02:39:56 | 000,000,000 | —D | M] (EWOQ Mobile Setup extension) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{f035aa18-ee32-4e6e-81d2-57e32867f8a7}
[2010/04/20 15:42:33 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/12/12 23:42:17 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files (x86)\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/04/20 15:42:33 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/20 15:41:52 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/05/08 07:14:22 | 000,393,089 | R— | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13577 more lines…
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll File not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WPCUMI] C:\Windows\SysNative\WpcUmi.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [POEngine] File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe ()
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [POEngine5] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\Google\GOOGLE~4\GOEC62~1.DLL) - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 20:06:38 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 20:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/15 00:56:54 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2010/05/15 00:36:05 | 001,316,632 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Users\Paul\Desktop\avgremoverx64.exe
[2010/05/14 23:15:24 | 000,000,000 | —D | C] – C:\Users\Paul\Desktop\Booking Summary and Important Voyage Information_files
[2010/05/13 00:04:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/12 13:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrendMicro
[2010/05/09 04:44:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft ATS
[2010/05/09 01:39:06 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\wvytommjy
[2010/05/07 20:10:54 | 000,000,000 | —D | C] – C:\Users\Paul\Desktop\misc
[2010/05/04 03:46:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\CalculatemPro
[2010/05/03 21:22:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\PostgreSQL
[2010/05/03 21:20:47 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/05/03 21:20:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerTracker 3
[2010/05/03 21:06:56 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\uTorrent
[2010/05/03 20:11:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\APB
[2010/05/03 14:32:45 | 000,000,000 | —D | C] – C:\poker
[2010/05/03 14:28:01 | 000,000,000 | —D | C] – C:\ProgramData\80ckVB
[2010/05/03 04:15:36 | 000,000,000 | —D | C] – C:\WACKPDOT
[2010/05/02 23:04:59 | 000,000,000 | —D | C] – C:\Users\Paul\PokerOffice
[2010/05/02 23:03:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerOffice5
[2010/05/01 18:07:05 | 000,000,000 | R-SD | C] – C:\Users\Paul\Documents\My Stationery
[2010/04/30 17:07:22 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\SecondLife
[2010/04/30 17:07:22 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\SecondLife
[2010/04/29 09:56:43 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\WinZip
[2010/04/24 22:55:37 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\Paltalk
[2010/04/24 01:17:04 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\PokerStars
[2010/04/24 01:16:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerStars
[2010/04/22 00:52:11 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\cache
[2010/04/20 15:51:26 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/20 15:42:27 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/04/20 15:42:27 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/04/20 15:42:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/04/20 15:42:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/04/19 02:46:41 | 000,000,000 | —D | C] – C:\Programs
[2010/04/17 19:16:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPL MPEG Decoder
[2010/04/17 19:11:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Elecard
[2010/04/17 18:55:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared

========== Files - Modified Within 30 Days ==========

[2010/05/15 01:03:00 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{86A9DA65-4EF8-46D0-9BBF-5849B730D1C4}.job
[2010/05/15 01:01:16 | 007,340,032 | -HS- | M] () – C:\Users\Paul\NTUSER.DAT
[2010/05/15 00:56:56 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2010/05/15 00:51:59 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/15 00:51:59 | 000,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/15 00:51:59 | 000,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/15 00:48:52 | 000,000,880 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/05/15 00:46:36 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/15 00:46:28 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/15 00:46:28 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/15 00:46:24 | 000,000,770 | —- | M] () – C:\Windows\tasks\McAfee Cleanup.job
[2010/05/15 00:46:24 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/15 00:46:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/15 00:45:14 | 000,524,288 | -HS- | M] () – C:\Users\Paul\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/05/15 00:45:14 | 000,065,536 | -HS- | M] () – C:\Users\Paul\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/05/15 00:45:13 | 003,666,749 | -H– | M] () – C:\Users\Paul\AppData\Local\IconCache.db
[2010/05/15 00:44:12 | 001,374,664 | —- | M] () – C:\Users\Paul\Desktop\MCPR.exe
[2010/05/15 00:36:07 | 001,316,632 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Users\Paul\Desktop\avgremoverx64.exe
[2010/05/15 00:31:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/15 00:22:37 | 000,387,353 | —- | M] () – C:\Users\Paul\Desktop\slow computer after infection.mht
[2010/05/14 23:15:24 | 000,017,517 | —- | M] () – C:\Users\Paul\Desktop\Booking Summary and Important Voyage Information.htm
[2010/05/14 14:14:10 | 000,000,000 | —- | M] () – C:\Users\Paul\AppData\Local\prvlcl.dat
[2010/05/14 13:54:51 | 000,000,416 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{E4D864AA-8B8E-4802-86FC-97E740712199}.job
[2010/05/14 12:58:22 | 016,995,372 | —- | M] () – C:\Users\Paul\Desktop\skyzoo wale.wav
[2010/05/14 12:51:42 | 022,431,788 | —- | M] () – C:\Users\Paul\Desktop\kanye drake lupe.wav
[2010/05/13 00:52:34 | 000,001,958 | —- | M] () – C:\Users\Paul\Desktop\HiJackThis.lnk
[2010/05/13 00:51:55 | 001,402,880 | —- | M] () – C:\Users\Paul\Desktop\HiJackThis.msi
[2010/05/13 00:19:33 | 000,359,929 | —- | M] () – C:\Users\Paul\Desktop\dds.scr
[2010/05/12 12:42:02 | 024,269,866 | —- | M] () – C:\Users\Paul\Desktop\eminem 1.wav
[2010/05/12 12:35:18 | 019,538,988 | —- | M] () – C:\Users\Paul\Desktop\kid cudi 1.wav
[2010/05/12 08:15:09 | 019,357,602 | —- | M] () – C:\Users\Paul\Desktop\Opie May 10_01.asf.mp3
[2010/05/12 08:12:56 | 019,357,824 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_04.asf.mp3
[2010/05/12 07:38:12 | 019,358,020 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_03.asf.mp3
[2010/05/12 06:56:34 | 019,352,796 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_02.asf.mp3
[2010/05/12 06:18:00 | 019,359,872 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_01.asf.mp3
[2010/05/12 06:02:58 | 019,382,471 | —- | M] () – C:\Users\Paul\Desktop\Opie May 12_01.asf.mp3
[2010/05/12 04:58:21 | 019,368,260 | —- | M] () – C:\Users\Paul\Desktop\Opie May 12_02.asf.mp3
[2010/05/10 20:00:00 | 000,000,558 | —- | M] () – C:\Windows\tasks\Norton Internet Security - Run Full System Scan - owner.job
[2010/05/09 04:46:00 | 003,473,408 | —- | M] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/05/09 04:46:00 | 000,262,144 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/05/09 04:46:00 | 000,065,536 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/05/09 04:41:43 | 000,402,352 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/05/09 04:08:30 | 000,000,566 | —- | M] () – C:\Users\Paul\Desktop\backup.reg
[2010/05/08 07:14:22 | 000,393,089 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2010/04/30 10:49:04 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010/04/29 04:25:57 | 000,392,729 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20100508-071422.backup
[2010/04/29 03:52:28 | 000,000,732 | —- | M] () – C:\Users\Paul\AppData\Local\d3d9caps64.dat
[2010/04/26 01:06:24 | 000,050,688 | —- | M] () – C:\Users\Paul\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/20 15:41:51 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/04/20 15:41:51 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/04/20 15:41:51 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/04/20 15:41:51 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/04/17 18:56:19 | 000,185,920 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2010/04/17 18:56:02 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2010/04/17 18:56:02 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2010/04/17 18:55:21 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll

========== Files Created - No Company Name ==========

[2010/05/15 00:44:38 | 000,000,770 | —- | C] () – C:\Windows\tasks\McAfee Cleanup.job
[2010/05/15 00:44:09 | 001,374,664 | —- | C] () – C:\Users\Paul\Desktop\MCPR.exe
[2010/05/15 00:22:28 | 000,387,353 | —- | C] () – C:\Users\Paul\Desktop\slow computer after infection.mht
[2010/05/14 23:15:23 | 000,017,517 | —- | C] () – C:\Users\Paul\Desktop\Booking Summary and Important Voyage Information.htm
[2010/05/14 12:58:22 | 016,995,372 | —- | C] () – C:\Users\Paul\Desktop\skyzoo wale.wav
[2010/05/14 12:51:41 | 022,431,788 | —- | C] () – C:\Users\Paul\Desktop\kanye drake lupe.wav
[2010/05/13 00:52:34 | 000,001,958 | —- | C] () – C:\Users\Paul\Desktop\HiJackThis.lnk
[2010/05/13 00:51:53 | 001,402,880 | —- | C] () – C:\Users\Paul\Desktop\HiJackThis.msi
[2010/05/13 00:19:19 | 000,359,929 | —- | C] () – C:\Users\Paul\Desktop\dds.scr
[2010/05/12 12:41:50 | 024,269,866 | —- | C] () – C:\Users\Paul\Desktop\eminem 1.wav
[2010/05/12 12:35:14 | 019,538,988 | —- | C] () – C:\Users\Paul\Desktop\kid cudi 1.wav
[2010/05/12 08:15:03 | 019,357,602 | —- | C] () – C:\Users\Paul\Desktop\Opie May 10_01.asf.mp3
[2010/05/12 08:12:51 | 019,357,824 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_04.asf.mp3
[2010/05/12 06:56:34 | 019,358,020 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_03.asf.mp3
[2010/05/12 06:56:26 | 019,352,796 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_02.asf.mp3
[2010/05/12 06:17:36 | 019,359,872 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_01.asf.mp3
[2010/05/12 04:58:21 | 019,368,260 | —- | C] () – C:\Users\Paul\Desktop\Opie May 12_02.asf.mp3
[2010/05/12 04:58:12 | 019,382,471 | —- | C] () – C:\Users\Paul\Desktop\Opie May 12_01.asf.mp3
[2010/05/09 04:45:01 | 003,473,408 | —- | C] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/05/09 04:45:01 | 000,262,144 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/05/09 04:45:01 | 000,065,536 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/05/09 04:08:30 | 000,000,566 | —- | C] () – C:\Users\Paul\Desktop\backup.reg
[2010/04/14 17:02:31 | 000,000,268 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/01/19 01:39:43 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2009/12/12 20:28:24 | 000,007,680 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009/12/12 20:28:24 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/11/26 10:56:35 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/11/26 10:55:54 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/01/25 18:24:05 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2008/05/28 10:30:00 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/05/28 10:30:00 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 19:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/02/22 08:17:50 | 000,000,071 | —- | C] () – C:\Windows\pn.ini
[2007/02/22 08:17:50 | 000,000,051 | —- | C] () – C:\Windows\pr.ini

========== LOP Check ==========

[2010/03/26 18:20:30 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Audacity
[2009/12/21 20:45:43 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Coby
[2010/04/28 19:11:48 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Coby Media Manager
[2010/01/19 01:39:20 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\GetRightToGo
[2010/01/24 08:08:05 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Octoshape
[2010/04/25 14:40:13 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Paltalk
[2010/01/12 19:41:25 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Safer Networking
[2010/04/30 17:10:22 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\SecondLife
[2010/05/03 22:27:44 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\uTorrent
[2009/12/15 15:06:24 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Windows Live Writer
[2008/09/29 11:02:20 | 000,000,266 | —- | M] () – C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2010/05/15 00:45:17 | 000,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/05/15 01:03:00 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{86A9DA65-4EF8-46D0-9BBF-5849B730D1C4}.job
[2010/05/14 13:54:51 | 000,000,416 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{E4D864AA-8B8E-4802-86FC-97E740712199}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/20 19:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 19:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/20 19:46:50 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/04/11 00:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2007/07/12 16:35:02 | 000,305,176 | —- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\Driver\IaStor.sys
[2007/07/12 09:35:44 | 000,381,976 | —- | M] (Intel Corporation) MD5=CEB53BB804B41C52AB0782505C8E2994 – C:\hp\DRIVERS\Intel_RAID\iastor.sys
[2007/07/12 16:35:44 | 000,381,976 | —- | M] (Intel Corporation) MD5=CEB53BB804B41C52AB0782505C8E2994 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/20 19:46:59 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/20 19:51:03 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 00:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 19:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/20 19:46:54 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 19:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 19:49:49 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 00:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8CEFE51A
< End of report >
Extras.txt

OTL Extras logfile created on: 5/15/2010 1:02:12 AM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Paul\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 585.12 Gb Total Space | 539.48 Gb Free Space | 92.20% Space Free | Partition Type: NTFS
Drive D: | 11.05 Gb Total Space | 1.47 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Paul
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 82 7F 36 6B A2 80 CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0177B0F9-E739-4DC5-BEDE-0FEAAA46DB15}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{09D77252-F8EF-4AF5-91BE-CFEACAC20401}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0CA388EA-04E2-46CD-8886-5A43DDD126A8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{0E94BF5D-9C2D-4563-A766-FD3D02A815BE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0FC88DD4-977F-4781-8246-302C640B3D54}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{11780298-FDDF-4C5F-8E64-AC1901C13B37}" = lport=2869 | protocol=6 | dir=in | app=system |
"{157CEC90-2BE0-4E93-A536-44B815AAEE2D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{1A3C03BA-7617-479D-A104-8E6F3EC00CEB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1F5AAD08-1062-4BE3-A2F9-CBA936B6F0BD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2053CE57-3296-4F65-B45E-9CDA58705107}" = lport=2869 | protocol=6 | dir=in | app=system |
"{21549E2D-4F11-4641-8AED-DFC04EE5BD60}" = rport=445 | protocol=6 | dir=out | app=system |
"{2A905435-C7EC-4C11-931D-CB288AFBEF38}" = lport=138 | protocol=17 | dir=in | app=system |
"{2C6D8C79-0819-4405-B37C-5CD20D5C54E8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{315C0DC0-B1DA-4DE0-A983-B9EEB4A5335A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3815828A-6447-467E-A71E-DD410DD2D8D9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{397F0AA4-D5E9-4004-B46C-701A6AF9BA3A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3FB07CB6-B812-4691-8259-2FB0827D1FA7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{40CF1C37-E019-4E01-9187-AAAF2801549A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{58F3EB76-E099-456E-B432-A20A1A4738BA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{69EC5A3B-5014-44D6-9D8B-8E05C1C494A4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6E2513AD-FBD0-47E6-93DF-D230603349D1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6ED50A1A-55B9-4020-B754-847BCF63E5CD}" = rport=139 | protocol=6 | dir=out | app=system |
"{6F2F8C47-6812-461B-A727-D9B60A194568}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{743A3543-10AF-43EA-90B6-21F8801EAABC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7F91693B-DFBB-4BB0-9CB2-A516A062FF27}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{81F6D3C7-E0FA-4108-BD41-4BBAC83264D8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{835D68F9-94BF-4072-BC54-D1165BDA935D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{882089B8-5571-4CBD-AA0F-2DA79E213BA9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{90C0872B-2368-4E7B-92E4-5AA3D4335836}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{936EF3F8-5659-4937-A89D-8B50F912A016}" = rport=138 | protocol=17 | dir=out | app=system |
"{96A6642D-A825-412F-B283-8A4FAA1AE8DD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9923D5DD-77D4-4EBB-976E-C16EF8784F4C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A147EA11-B9A0-43F5-8AA8-4FB05FBCD80A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A185C7FF-78DA-4C0C-8AF9-52B475774485}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A2413976-9220-4528-8B0E-66E919174D29}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A2CB6F74-43CD-49AD-AF7E-60B31375979C}" = lport=139 | protocol=6 | dir=in | app=system |
"{A87C175C-E75A-41C2-B2B0-9387DDD19B40}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AFA28EB3-78FC-4DA0-A6B7-BF865840B705}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BB6DFC69-5F53-4396-8F59-217182BF23AA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C2CAA814-1E40-4600-8881-2CBAA54D83A2}" = lport=445 | protocol=6 | dir=in | app=system |
"{C4D9D752-D11C-4617-B100-E08248324B2C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C9BF0912-B031-4D94-A2BC-90E6BD94F00C}" = lport=137 | protocol=17 | dir=in | app=system |
"{CB60BA90-3D85-4FF0-8B65-FBE060D707B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D0939D71-4ECB-43BC-BF5A-6453D4ACB60B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D2618CB5-AC96-453D-B105-619027B9DA6C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D67D0279-A771-46C4-A3A1-FF6E2973DA8F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D6B358E3-E92A-4E5F-9376-3F730B931E04}" = lport=2869 | protocol=6 | dir=in | app=system |
"{ECE14B40-D971-4368-8012-9FDBDA0CE6DD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F25A64A8-4BD5-440B-BBA1-B48ABBEED1DE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FB0462CF-0DFF-4311-9E38-FB7AE98C233B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FD7525BA-43EC-470D-93FA-7B998B1FD291}" = rport=137 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00C4D836-A69E-450B-B7B3-5A4835655486}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{00DB03EC-6E54-40C4-B977-1E3C9D6F777D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{0A56BCE4-CB51-445F-9FD3-81E94A211064}" = dir=in | app=c:\program files (x86)\avg\avg9\avgupd.exe |
"{0C36C0CF-AEDB-4810-AFCD-1ADD3E5BECD3}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{0E105B9D-BFDF-4ADF-8C4B-B1FED65BDF9A}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{1226D4ED-78B6-46E3-B850-3DD2B1199AF5}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{20560C73-6802-4A9C-B8FE-B2EE1AE3863C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{21AFB549-93C7-4B0C-B4BF-A376F7153E15}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{231F3369-2643-45F1-B931-C3EAAB846AFE}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{2656FC0A-3CCC-4C4F-8B72-B9BADD35A365}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{266BF68A-928D-48F8-A991-FAEA7766F300}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{2B61B45E-171C-4095-A277-F21B47224220}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{30D8B338-B8DB-4226-9CD6-EBE5DB49A7D3}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{3101D181-B835-4BF2-81E7-D7A5B75949B7}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{338CFBC1-1B4A-4F45-9557-F7215205AF3B}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{3B72CC40-943D-4DD5-B374-71437E715692}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{3EC2D88F-1CB4-45A4-A335-6DA7C590C2B2}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{40E31AB0-1F3C-4642-A745-4E5F9D935F99}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{48995762-5CEA-4566-B827-AC25435A7FC3}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{490AD9C3-672F-417C-B6E2-6F907256D5CD}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{506CAE6B-AFB9-44F1-924F-47ACDF85EE3A}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{5AE3889C-2E5D-46FA-866C-660ED4C5E3C2}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{5EA43C65-5B8E-48D7-A3C9-ADBC84768AC4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{61587697-22F3-426B-8298-03FF9E34EAF4}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{639BD199-4C66-42A2-B11A-32FC17544DDD}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{66F8B7B2-9CE1-4E18-94E6-807E60FDE2C8}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{6A018FEB-3DD1-4337-9C0A-C2C4CC584A29}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6AC6F999-B778-4439-8338-CA4BD5E1570E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{6CF8B9AE-7557-40EC-BFF8-079D22F84C42}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{70BB8598-9480-4E9C-B289-BB9ED9A104E4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{724810C6-73E5-4C03-846B-F621C8CB151F}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{72D61322-3EF8-45C6-A95C-66B9D2DE4BD5}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{7888D537-93F8-46F5-840D-6F473C837491}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{78906618-C091-48B0-8DEA-6F675B8E7CD3}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{79595381-387A-454A-8E9E-22C87FEA58B9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{83FEFA4D-09E1-458F-A127-02CF470E9783}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{8798EBED-DED1-479C-9F77-2D463EF64347}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{87A9422F-3881-417B-B965-5AC68DBF928F}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{8835C43E-DDC4-411B-BA65-97EFE9D1BEFB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8EC1BB3E-D9A4-431D-9410-58338D2EC070}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{8FCCE6E2-E1B6-4468-86A8-0E23D7B88DB2}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{94B983FE-BD62-44C4-980F-433BC5AC8F5F}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{9B025E68-CD17-4B07-8B28-B697B8D83E19}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{9EEB75BF-050A-47D6-993D-7EF522CF4521}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{A09D9D90-A164-4639-BD4F-C69D7947E203}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{AA02424B-3AD3-40F3-AF80-6681D77F9880}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{B07BCB7F-DDDB-46F3-BCA7-10B60425E5A3}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{B3176761-6D33-4B30-9B54-6332EFE1CBC2}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{BB0C79C1-4103-49E3-9569-764128ABA806}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{BCBB8109-F35A-4735-8F32-3005BBDEF330}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{BCC3509E-DE38-4863-8450-D05C32744728}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{BEBBE36E-4119-4520-8D22-F097FBF5E557}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{C6C50F30-008B-434C-AECA-5E0AF933E86E}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{D94FE3B5-BEE2-4E87-AC89-91160440ED7A}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{E13FB70D-5E83-4BC4-9B98-85CDF50B5B9B}" = dir=in | app=c:\program files (x86)\avg\avg9\avgnsa.exe |
"{E2D902CD-E0F2-404D-9EDE-C74537125407}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{E6F6CB47-36AD-4843-95E3-27E701C217E1}" = dir=in | app=c:\program files (x86)\windows live\messenger\livecall.exe |
"{F9D14E00-F3BA-4AE9-BEA9-896E9D02CE27}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{FC952EE3-34A7-41ED-AF38-79C6F02FB403}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{FE7DBA50-8416-4BC6-B09A-E694F930C924}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"TCP Query User{23935F08-BD67-415D-A411-B27B11AED33A}C:\program files (x86)\java\jre1.6.0_01\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre1.6.0_01\bin\javaw.exe |
"TCP Query User{CB850C56-AB0B-4EC6-AE23-D8663F4B725E}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{CD2E006E-28F4-40A4-B741-CC113A2F643D}C:\nexon\combat arms\engine.exe" = protocol=6 | dir=in | app=c:\nexon\combat arms\engine.exe |
"UDP Query User{174DBC4C-4A12-40F0-8E0F-AE7BB8283E19}C:\nexon\combat arms\engine.exe" = protocol=17 | dir=in | app=c:\nexon\combat arms\engine.exe |
"UDP Query User{1E11D74A-7720-4BF6-A047-EDEDEA5BF2A7}C:\program files (x86)\java\jre1.6.0_01\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre1.6.0_01\bin\javaw.exe |
"UDP Query User{B7B76F51-F414-49B6-B2BD-5FA1A74C33A7}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{282E5AB2-8E47-4571-B6FA-6B512555B557}" = HP Photosmart.All-In-One Driver Software 8.0 .A
"{52D530AD-5CCA-48dc-B6F0-6D14652B0291}" = AIO_CDA_ToolboxIni64
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{A7D48BF6-8ED8-4B91-8267-34CDE7807D05}_is1" = HP Demo
"{B0EFB716-085B-4564-8060-212E41F5CE50}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"CNXT_MODEM_PCI_HSF" = PCIe Soft Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"OfficeTrial" = Microsoft Office Home and Student 60 day trial

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{004C5DA2-2051-4D25-94BA-51CF810C91EB}" = LightScribe System Software 1.12.37.1
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{305D4B08-5807-4475-B1C8-D54685534864}" = LightScribeTemplateLabeler
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44F5A980-8A6B-4aca-8D85-EFCE5D67D379}" = AIO_CDA_ProductContext
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8215BC09-2CDF-4A40-9481-95E40E7F2DDA}" = Lionbridge Task Control
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC388C78-2619-452C-BFBE-FABCC3194387}" = Microsoft Office Live Meeting 2007
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF1C9345-B53D-4110-BFBF-A0DD83AEAB83}" = AIO_CDA_Software
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C8E95BF5-C07F-4D98-BB42-F58FC98BC03E}" = Google Apps
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}" = WinZip 14.0
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E0810CC2-4B5B-4439-B1D0-452306AF2D64}" = HP Active Support Library
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FAA9B753-45CE-4581-876C-55D97939B631}" = C6100
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"Audacity_is1" = Audacity 1.2.6
"Calculatem Pro_is1" = Calculatem Pro
"CoC" = Call of Combat
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ffdshow_is1" = ffdshow [rev 1523] [2007-10-09]
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"PartyPoker" = PartyPoker
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"PokerStars" = PokerStars
"RealPlayer 12.0" = RealPlayer
"Winamp" = Winamp
"Windows Live Toolbar" = Windows Live Toolbar
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"PokerOffice5" = PokerOffice 5 (remove only)

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Attachments:

Try disabling TeaTimer and then run GMER again.

Disabling TeaTimer

Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once we are done with it.
  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and click OK any prompts.
  • Restart your computer.
Hi,

Is AVG bad or should I just make sure I have 1 virus program?

AVG is good but when you have two different AV's installed together in a machine would cause some internal conflicts between them. Since you said you prefer to have AVG, I strongly urge you to uninstall McAfee and then see if you still feel the slowness.

===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [POEngine] File not found
    O4 - HKCU..\Run: [POEngine5] File not found
    
    :Files
    C:\Windows\tasks\Norton Internet Security - Run Full System Scan - owner.job
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.

===================================================

Kaspersky Online Scanner in IE

I recommend you to leave your computer on for the whole night as the scanning will take longer than you expected.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Please go to Kaspersky website and click on Kaspersky Online Scanner to perform an online scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

    [external image: Posted Image]
  • Please post this log in your next reply.

**Note

For clearer guidance, here's the animated tutorial :-

Click here

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan. Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

===================================================

On your next reply please post :
OTL log
MBAM log
Kaspersky report

Good Day!
Ok here are the 3 logs .

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4104

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

5/15/2010 2:02:17 PM
mbam-log-2010-05-15 (14-02-17).txt

Scan type: Quick scan
Objects scanned: 160270
Time elapsed: 5 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






OTL=============================================================================
====================================================================


All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\POEngine deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\POEngine5 deleted successfully.
========== FILES ==========
C:\Windows\tasks\Norton Internet Security - Run Full System Scan - owner.job moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 23883403 bytes
->Temporary Internet Files folder emptied: 62334068 bytes
->Java cache emptied: 61950 bytes
->Flash cache emptied: 20624 bytes

User: guest1
->Temporary Internet Files folder emptied: 81920 bytes

User: guest1.owner-PC
->Temp folder emptied: 326667 bytes
->Temporary Internet Files folder emptied: 20080043 bytes
->Flash cache emptied: 42425 bytes

User: owner
->Temp folder emptied: 73424369 bytes
->Temporary Internet Files folder emptied: 10507422 bytes
->Java cache emptied: 1412537 bytes
->Google Chrome cache emptied: 6138516 bytes
->Flash cache emptied: 15863 bytes

User: Paul
->Temp folder emptied: 89255277 bytes
->Temporary Internet Files folder emptied: 970299926 bytes
->Java cache emptied: 80006 bytes
->FireFox cache emptied: 83582121 bytes
->Google Chrome cache emptied: 22553300 bytes
->Flash cache emptied: 348187 bytes

User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 147010 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,302.00 mb


OTL by OldTimer - Version 3.2.4.1 log created on 05152010_131527

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Please post a fresh OTL log in your next reply. This time just run it again without having to copy/paste the custom scans command. Have you performed an uninstallation on McAfee? Any signs of improvement after doing so?
Yeah it's been running smoother since I started only using AVG.



OTL logfile created on: 5/16/2010 3:10:34 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Users\Paul\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 53.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 585.12 Gb Total Space | 540.26 Gb Free Space | 92.33% Space Free | Partition Type: NTFS
Drive D: | 11.05 Gb Total Space | 1.47 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Paul
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Paul\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Google\Update\1.2.183.23\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files (x86)\Winamp\winampa.exe ()
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Users\Paul\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WLSetupSvc) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 06:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\Drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\Drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\Drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\DRIVERS\Lbd.sys (Lavasoft AB)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (CAXHWBS3) – C:\Windows\SysNative\DRIVERS\CAXHWBS3.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DP) – C:\Windows\SysNative\DRIVERS\CAX_DP.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iastor.sys (Intel Corporation)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (mdmxsdk) – C:\Windows\SysWOW64\mdmxsdk.dll (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cndt
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems: {f035aa18-ee32-4e6e-81d2-57e32867f8a7}:1.17
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}:0.7.23
FF - prefs.js..extensions.enabledItems: {8ea9957e-2953-402f-80e0-bceb5f169d6f}:0.5.3
FF - prefs.js..extensions.enabledItems: avg@igeared:4.504.019.002
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_us&p;="

FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/05/16 13:02:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/17 18:56:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/05/16 13:00:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/17 18:56:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/02 18:08:47 | 000,000,000 | —D | M]

[2009/12/12 23:42:28 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2010/05/16 13:06:48 | 000,000,000 | —D | M] – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions
[2010/04/28 06:10:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/24 02:39:57 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/04/24 02:39:57 | 000,000,000 | —D | M] (XHTML Mobile Profile) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{8ea9957e-2953-402f-80e0-bceb5f169d6f}
[2009/12/24 12:14:39 | 000,000,000 | —D | M] (Web Developer) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/04/24 02:39:57 | 000,000,000 | —D | M] (wmlbrowser) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}
[2010/04/24 02:39:56 | 000,000,000 | —D | M] (EWOQ Mobile Setup extension) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\qm6p2zs2.default\extensions\{f035aa18-ee32-4e6e-81d2-57e32867f8a7}
[2010/04/20 15:42:33 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/12/12 23:42:17 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files (x86)\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/04/20 15:42:33 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/20 15:41:52 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/05/08 07:14:22 | 000,393,089 | R— | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13577 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~2\COMMON~1\SYMANT~1\IDS\IPSBHO.dll File not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WPCUMI] C:\Windows\SysNative\WpcUmi.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe ()
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Value error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/05/16 13:02:42 | 000,012,976 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/05/16 13:02:40 | 000,317,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/05/16 13:02:35 | 000,269,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/05/16 13:02:33 | 000,035,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/05/16 13:02:33 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010/05/15 14:09:02 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/05/15 13:54:27 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\Malwarebytes
[2010/05/15 13:54:05 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/15 13:54:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/15 13:54:02 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/15 13:54:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/05/15 13:52:56 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Users\Paul\Desktop\mbam-setup-1.46.exe
[2010/05/15 13:15:27 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/15 13:12:20 | 000,000,000 | —D | C] – C:\Users\Paul\Desktop\slow_computer_after_infection_t112034_files
[2010/05/15 01:56:57 | 000,000,000 | —D | C] – C:\Users\Paul\CD95F661A5C444F5A6AAECDD91C240BC.TMP
[2010/05/15 00:56:54 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2010/05/15 00:36:05 | 001,316,632 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Users\Paul\Desktop\avgremoverx64.exe
[2010/05/14 23:15:24 | 000,000,000 | —D | C] – C:\Users\Paul\Desktop\Booking Summary and Important Voyage Information_files
[2010/05/13 00:04:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/05/12 13:21:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\TrendMicro
[2010/05/09 04:44:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft ATS
[2010/05/09 01:39:06 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\wvytommjy
[2010/05/07 20:10:54 | 000,000,000 | —D | C] – C:\Users\Paul\Desktop\misc
[2010/05/04 03:46:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\CalculatemPro
[2010/05/03 21:22:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\PostgreSQL
[2010/05/03 21:20:47 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/05/03 21:20:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerTracker 3
[2010/05/03 21:06:56 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\uTorrent
[2010/05/03 20:11:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\APB
[2010/05/03 14:32:45 | 000,000,000 | —D | C] – C:\poker
[2010/05/03 14:28:01 | 000,000,000 | —D | C] – C:\ProgramData\80ckVB
[2010/05/03 04:15:36 | 000,000,000 | —D | C] – C:\WACKPDOT
[2010/05/02 23:03:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerOffice5
[2010/05/01 18:07:05 | 000,000,000 | R-SD | C] – C:\Users\Paul\Documents\My Stationery
[2010/04/30 17:07:22 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\SecondLife
[2010/04/30 17:07:22 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\SecondLife
[2010/04/29 09:56:43 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\WinZip
[2010/04/24 22:55:37 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Roaming\Paltalk
[2010/04/24 01:17:04 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\PokerStars
[2010/04/24 01:16:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\PokerStars
[2010/04/22 00:52:11 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\cache
[2010/04/20 15:51:26 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/20 15:42:27 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/04/20 15:42:27 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/04/20 15:42:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/04/20 15:42:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/04/19 02:46:41 | 000,000,000 | —D | C] – C:\Programs
[2010/04/17 19:16:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPL MPEG Decoder
[2010/04/17 19:11:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Elecard
[2010/04/17 18:55:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[1 C:\Users\Paul\*.tmp files -> C:\Users\Paul\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/16 15:13:00 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{86A9DA65-4EF8-46D0-9BBF-5849B730D1C4}.job
[2010/05/16 15:10:35 | 007,340,032 | -HS- | M] () – C:\Users\Paul\NTUSER.DAT
[2010/05/16 14:31:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/16 14:22:50 | 000,000,416 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{E4D864AA-8B8E-4802-86FC-97E740712199}.job
[2010/05/16 14:03:43 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/16 14:03:43 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/16 13:55:47 | 000,000,000 | —- | M] () – C:\Users\Paul\AppData\Local\prvlcl.dat
[2010/05/16 13:02:44 | 000,001,651 | —- | M] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/05/16 13:02:43 | 000,012,976 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/05/16 13:02:42 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/05/16 13:02:35 | 000,269,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/05/16 13:02:35 | 000,035,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/05/16 13:02:33 | 060,047,216 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/05/16 13:02:33 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/05/16 12:47:10 | 000,000,880 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2010/05/16 12:45:33 | 000,018,746 | —- | M] () – C:\Users\Paul\Desktop\homer-simpson-brain-mri.jpg
[2010/05/15 22:31:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/15 14:09:05 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/15 14:09:05 | 000,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/15 14:09:05 | 000,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/15 14:03:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/15 14:03:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/15 14:02:57 | 000,524,288 | -HS- | M] () – C:\Users\Paul\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/05/15 14:02:57 | 000,065,536 | -HS- | M] () – C:\Users\Paul\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/05/15 14:02:56 | 003,645,853 | -H– | M] () – C:\Users\Paul\AppData\Local\IconCache.db
[2010/05/15 13:54:08 | 000,000,810 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/15 13:53:00 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Users\Paul\Desktop\mbam-setup-1.46.exe
[2010/05/15 13:12:20 | 000,211,847 | —- | M] () – C:\Users\Paul\Desktop\slow_computer_after_infection_t112034.html
[2010/05/15 10:25:05 | 000,521,683 | —- | M] () – C:\Users\Paul\Desktop\CoolThing.png
[2010/05/15 09:14:04 | 000,002,719 | —- | M] () – C:\Users\Paul\Desktop\donk.jpg
[2010/05/15 09:13:02 | 000,011,761 | —- | M] () – C:\Users\Paul\Desktop\Kuper_Donkey-cards.jpg
[2010/05/15 02:04:53 | 000,065,515 | —- | M] () – C:\Users\Paul\Desktop\screen cap.jpg
[2010/05/15 01:57:15 | 000,001,987 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/05/15 01:44:26 | 000,284,915 | —- | M] () – C:\Users\Paul\Desktop\gmer.zip
[2010/05/15 00:56:56 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2010/05/15 00:46:24 | 000,000,770 | —- | M] () – C:\Windows\tasks\McAfee Cleanup.job
[2010/05/15 00:44:12 | 001,374,664 | —- | M] () – C:\Users\Paul\Desktop\MCPR.exe
[2010/05/15 00:36:07 | 001,316,632 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Users\Paul\Desktop\avgremoverx64.exe
[2010/05/15 00:22:37 | 000,387,353 | —- | M] () – C:\Users\Paul\Desktop\slow computer after infection.mht
[2010/05/14 23:15:24 | 000,017,517 | —- | M] () – C:\Users\Paul\Desktop\Booking Summary and Important Voyage Information.htm
[2010/05/14 12:58:22 | 016,995,372 | —- | M] () – C:\Users\Paul\Desktop\skyzoo wale.wav
[2010/05/14 12:51:42 | 022,431,788 | —- | M] () – C:\Users\Paul\Desktop\kanye drake lupe.wav
[2010/05/13 00:52:34 | 000,001,958 | —- | M] () – C:\Users\Paul\Desktop\HiJackThis.lnk
[2010/05/13 00:51:55 | 001,402,880 | —- | M] () – C:\Users\Paul\Desktop\HiJackThis.msi
[2010/05/13 00:19:33 | 000,359,929 | —- | M] () – C:\Users\Paul\Desktop\dds.scr
[2010/05/12 12:42:02 | 024,269,866 | —- | M] () – C:\Users\Paul\Desktop\eminem 1.wav
[2010/05/12 12:35:18 | 019,538,988 | —- | M] () – C:\Users\Paul\Desktop\kid cudi 1.wav
[2010/05/12 08:15:09 | 019,357,602 | —- | M] () – C:\Users\Paul\Desktop\Opie May 10_01.asf.mp3
[2010/05/12 08:12:56 | 019,357,824 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_04.asf.mp3
[2010/05/12 07:38:12 | 019,358,020 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_03.asf.mp3
[2010/05/12 06:56:34 | 019,352,796 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_02.asf.mp3
[2010/05/12 06:18:00 | 019,359,872 | —- | M] () – C:\Users\Paul\Desktop\Opie May 11_01.asf.mp3
[2010/05/12 06:02:58 | 019,382,471 | —- | M] () – C:\Users\Paul\Desktop\Opie May 12_01.asf.mp3
[2010/05/12 04:58:21 | 019,368,260 | —- | M] () – C:\Users\Paul\Desktop\Opie May 12_02.asf.mp3
[2010/05/09 04:46:00 | 003,473,408 | —- | M] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/05/09 04:46:00 | 000,262,144 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/05/09 04:46:00 | 000,065,536 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/05/09 04:41:43 | 000,402,352 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/05/09 04:08:30 | 000,000,566 | —- | M] () – C:\Users\Paul\Desktop\backup.reg
[2010/05/08 07:14:22 | 000,393,089 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2010/04/30 10:49:04 | 000,015,880 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/29 04:25:57 | 000,392,729 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts.20100508-071422.backup
[2010/04/29 03:52:28 | 000,000,732 | —- | M] () – C:\Users\Paul\AppData\Local\d3d9caps64.dat
[2010/04/26 01:06:24 | 000,050,688 | —- | M] () – C:\Users\Paul\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/20 15:41:51 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/04/20 15:41:51 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/04/20 15:41:51 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/04/20 15:41:51 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/04/17 18:56:19 | 000,185,920 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2010/04/17 18:56:02 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2010/04/17 18:56:02 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2010/04/17 18:55:21 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[1 C:\Users\Paul\*.tmp files -> C:\Users\Paul\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/16 13:02:44 | 000,001,651 | —- | C] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/05/16 13:02:33 | 060,047,216 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/05/16 13:02:33 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/05/16 12:45:18 | 000,018,746 | —- | C] () – C:\Users\Paul\Desktop\homer-simpson-brain-mri.jpg
[2010/05/15 13:54:08 | 000,000,810 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/15 13:12:18 | 000,211,847 | —- | C] () – C:\Users\Paul\Desktop\slow_computer_after_infection_t112034.html
[2010/05/15 10:25:02 | 000,521,683 | —- | C] () – C:\Users\Paul\Desktop\CoolThing.png
[2010/05/15 09:14:04 | 000,002,719 | —- | C] () – C:\Users\Paul\Desktop\donk.jpg
[2010/05/15 09:13:02 | 000,011,761 | —- | C] () – C:\Users\Paul\Desktop\Kuper_Donkey-cards.jpg
[2010/05/15 02:04:53 | 000,065,515 | —- | C] () – C:\Users\Paul\Desktop\screen cap.jpg
[2010/05/15 01:57:15 | 000,001,987 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/05/15 01:17:57 | 000,284,915 | —- | C] () – C:\Users\Paul\Desktop\gmer.zip
[2010/05/15 00:44:38 | 000,000,770 | —- | C] () – C:\Windows\tasks\McAfee Cleanup.job
[2010/05/15 00:44:09 | 001,374,664 | —- | C] () – C:\Users\Paul\Desktop\MCPR.exe
[2010/05/15 00:22:28 | 000,387,353 | —- | C] () – C:\Users\Paul\Desktop\slow computer after infection.mht
[2010/05/14 23:15:23 | 000,017,517 | —- | C] () – C:\Users\Paul\Desktop\Booking Summary and Important Voyage Information.htm
[2010/05/14 12:58:22 | 016,995,372 | —- | C] () – C:\Users\Paul\Desktop\skyzoo wale.wav
[2010/05/14 12:51:41 | 022,431,788 | —- | C] () – C:\Users\Paul\Desktop\kanye drake lupe.wav
[2010/05/13 00:52:34 | 000,001,958 | —- | C] () – C:\Users\Paul\Desktop\HiJackThis.lnk
[2010/05/13 00:51:53 | 001,402,880 | —- | C] () – C:\Users\Paul\Desktop\HiJackThis.msi
[2010/05/13 00:19:19 | 000,359,929 | —- | C] () – C:\Users\Paul\Desktop\dds.scr
[2010/05/12 12:41:50 | 024,269,866 | —- | C] () – C:\Users\Paul\Desktop\eminem 1.wav
[2010/05/12 12:35:14 | 019,538,988 | —- | C] () – C:\Users\Paul\Desktop\kid cudi 1.wav
[2010/05/12 08:15:03 | 019,357,602 | —- | C] () – C:\Users\Paul\Desktop\Opie May 10_01.asf.mp3
[2010/05/12 08:12:51 | 019,357,824 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_04.asf.mp3
[2010/05/12 06:56:34 | 019,358,020 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_03.asf.mp3
[2010/05/12 06:56:26 | 019,352,796 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_02.asf.mp3
[2010/05/12 06:17:36 | 019,359,872 | —- | C] () – C:\Users\Paul\Desktop\Opie May 11_01.asf.mp3
[2010/05/12 04:58:21 | 019,368,260 | —- | C] () – C:\Users\Paul\Desktop\Opie May 12_02.asf.mp3
[2010/05/12 04:58:12 | 019,382,471 | —- | C] () – C:\Users\Paul\Desktop\Opie May 12_01.asf.mp3
[2010/05/09 04:45:01 | 003,473,408 | —- | C] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/05/09 04:45:01 | 000,262,144 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/05/09 04:45:01 | 000,065,536 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/05/09 04:08:30 | 000,000,566 | —- | C] () – C:\Users\Paul\Desktop\backup.reg
[2010/04/14 17:02:31 | 000,000,268 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/01/19 01:39:43 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2009/12/12 20:28:24 | 000,007,680 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009/12/12 20:28:24 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/11/26 10:56:35 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/11/26 10:55:54 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/01/25 18:24:05 | 000,000,126 | —- | C] () – C:\Windows\QUICKEN.INI
[2008/05/28 10:30:00 | 000,327,680 | —- | C] () – C:\Windows\SysWow64\pythoncom25.dll
[2008/05/28 10:30:00 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 19:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/02/22 08:17:50 | 000,000,071 | —- | C] () – C:\Windows\pn.ini
[2007/02/22 08:17:50 | 000,000,051 | —- | C] () – C:\Windows\pr.ini

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:8CEFE51A
< End of report >
Hi,

Your log appears to be clean. :)

And it seems like the presence of 2 different AVs are the cause.

Please remember to re-enable your TeaTimer back to active status.


===================================================

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================
Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:

1. Create a new Restore Point
  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.
.
2. Clear your existing system restore points except for the new clean restore point you just created:
  • Go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up
  • This will remove all restore points except the new one you just created.

===================================================

Here are some tips to reduce the potential for spyware infection in the future:
  • Make your Internet Explorer More Secure
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab.
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.

      • Change the Download signed ActiveX controls to Prompt.
      • Change the Download unsigned ActiveX controls to Disable.
      • Change the Initialise and script ActiveX controls not marked as safe to Disable.
      • Change the Installation of desktop items to Prompt.
      • Change the Launching programs and files in an IFRAME to Prompt.
      • Change the Navigate sub-frames across different domains to Prompt.
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.


    Here are some tips to reduce the potential for spyware infection in the future:

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Consider a custom hosts file such as MVPS HOSTS - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
    For information on how to download and install, please read this tutorial by WinHelp2002
    Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article:
How I got
Infected in the First Place



Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI