This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] i'm infected.... ;__;.... help me!

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was stupid and downloaded some software, that I'm fairly certain installed malicious stuff on my computer. Strange happenings have been about! I know something's wrong. Programs crashing out of the blue, laggs, and just over all feels slower. Any help would be appreciated, THX.
Hello eros1 and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.

Hello eros1 and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.


OK! Thank you for your help, I very much appreciate it. I will wait for your response.
Hello eros1

Please run the following scans so we can see what is going on. If you encounter any difficulties, come back and let me know.


(Note: For Wondows 7 Users, please right-click on the tool icons and choose "Run As Administrator" to run the required tools).


  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then Right click on the OTL.exe icon and select "Run as administrator" to run the program.
    • When OTL opens, underneath "Output" (at the top) select "Standard Output".
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click on the GMER.exe and select "Run as Administrator". If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


In your next reply please post the OTL logs and the GMER log.
OTL logfile created on: 5/21/2010 3:15:01 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Tito\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 79.00% Memory free
11.00 Gb Paging File | 10.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.54 Gb Total Space | 556.69 Gb Free Space | 81.44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC
Current User Name: Tito
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/21 15:11:16 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Tito\Desktop\OTL.exe
PRC - [2010/04/29 15:39:34 | 000,304,464 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/04/12 17:46:36 | 001,135,912 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/04/06 14:44:14 | 000,247,856 | —- | M] () – C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
PRC - [2010/03/31 19:24:08 | 000,194,608 | —- | M] () – C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
PRC - [2009/10/20 20:39:28 | 000,340,456 | —- | M] (Kaspersky Lab) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
PRC - [2009/07/03 20:47:12 | 000,240,160 | —- | M] (Acer) – C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
PRC - [2009/06/04 08:04:50 | 001,150,496 | —- | M] (Acer Incorporated) – C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (SafeList) ==========

MOD - [2010/05/21 15:11:16 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Tito\Desktop\OTL.exe
MOD - [2009/07/13 20:15:07 | 000,486,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009/07/13 20:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 20:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/05/12 21:46:13 | 001,038,088 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64)
SRV:64bit: - [2010/05/08 04:32:23 | 001,255,736 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV:64bit: - [2010/05/01 20:10:56 | 000,044,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\themeservice.dll – (Themes)
SRV:64bit: - [2010/02/26 11:28:40 | 005,017,600 | —- | M] (Native Instruments GmbH) [Auto | Running] – C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe – (NIHardwareService)
SRV:64bit: - [2009/07/13 20:41:59 | 000,229,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wwansvc.dll – (WwanSvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,202,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbiosrvc.dll – (WbioSrvc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,163,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\umpo.dll – (Power)
SRV:64bit: - [2009/07/13 20:41:54 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sppuinotify.dll – (sppuinotify)
SRV:64bit: - [2009/07/13 20:41:54 | 000,029,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\sensrsvc.dll – (SensrSvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\pnrpsvc.dll – (PNRPsvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,327,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\pnrpsvc.dll – (p2pimsvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,187,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\provsvc.dll – (HomeGroupProvider)
SRV:64bit: - [2009/07/13 20:41:53 | 000,067,072 | —- | M] (Microsoft Corporation) [Unknown | Running] – C:\Windows\SysNative\RpcEpMap.dll – (RpcEptMapper)
SRV:64bit: - [2009/07/13 20:41:53 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\pnrpauto.dll – (PNRPAutoReg)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 20:41:18 | 000,231,936 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\ListSvc.dll – (HomeGroupListener)
SRV:64bit: - [2009/07/13 20:40:54 | 001,127,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FntCache.dll – (FontCache)
SRV:64bit: - [2009/07/13 20:40:28 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\dhcpcore.dll – (Dhcp)
SRV:64bit: - [2009/07/13 20:40:28 | 000,291,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\defragsvc.dll – (defragsvc)
SRV:64bit: - [2009/07/13 20:40:13 | 000,083,968 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\bthserv.dll – (bthserv)
SRV:64bit: - [2009/07/13 20:40:10 | 000,100,864 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\SysNative\bdesvc.dll – (BDESVC)
SRV:64bit: - [2009/07/13 20:40:05 | 000,114,688 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AxInstSv.dll – (AxInstSV)
SRV:64bit: - [2009/07/13 20:40:01 | 000,032,256 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appidsvc.dll – (AppIDSvc)
SRV:64bit: - [2009/07/13 20:39:51 | 001,503,744 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wbengine.exe – (wbengine)
SRV:64bit: - [2009/07/13 20:39:28 | 003,524,608 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysNative\sppsvc.exe – (sppsvc)
SRV:64bit: - [2009/07/13 20:39:11 | 000,689,152 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\FXSSVC.exe – (Fax)
SRV:64bit: - [2009/07/03 20:47:12 | 000,240,160 | —- | M] (Acer) [Auto | Running] – C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe – (Updater Service)
SRV:64bit: - [2009/04/19 10:34:48 | 000,625,184 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM))
SRV:64bit: - [2009/04/19 10:34:48 | 000,207,904 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2010/05/12 21:46:06 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/04/29 15:39:34 | 000,304,464 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2010/04/08 22:34:25 | 000,000,000 | —D | M] [On_Demand | Stopped] – C:\Windows\Vss – (VSS)
SRV - [2010/04/06 14:44:46 | 000,057,640 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.exe – (HssTrayService)
SRV - [2010/04/06 14:44:14 | 000,247,856 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe – (HotspotShieldService)
SRV - [2010/03/31 19:24:08 | 000,194,608 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe – (HssWd)
SRV - [2010/03/18 17:23:04 | 000,044,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe – (aspnet_state)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/12/11 18:47:44 | 000,036,352 | —- | M] () [On_Demand | Stopped] – C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe – (OpenVPNService)
SRV - [2009/10/20 20:39:28 | 000,340,456 | —- | M] (Kaspersky Lab) [Auto | Running] – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe – (AVP)
SRV - [2009/07/13 22:20:14 | 000,000,000 | —D | M] [Unknown | Stopped] – C:\Windows\SysWOW64\Msdtc – (MSDTC)
SRV - [2009/07/13 20:16:12 | 000,165,376 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysWOW64\provsvc.dll – (HomeGroupProvider)
SRV - [2009/07/13 20:15:11 | 000,253,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\dhcpcore.dll – (Dhcp)
SRV - [2009/07/13 15:30:11 | 000,061,056 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2009/06/10 15:39:58 | 000,089,920 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2009/06/04 08:04:50 | 001,150,496 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe – (Greg_Service)
SRV - [2008/11/09 15:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2010/04/16 23:06:43 | 000,353,296 | —- | M] (Kaspersky Lab) [File_System | System | Running] – C:\Windows\SysNative\drivers\klif.sys – (KLIF)
DRV:64bit: - [2009/12/11 18:48:04 | 000,031,232 | —- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\tap0901.sys – (tap0901)
DRV:64bit: - [2009/12/11 05:29:27 | 000,153,160 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ksecpkg.sys – (KSecPkg)
DRV:64bit: - [2009/11/22 03:46:24 | 000,086,584 | —- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\adfs.sys – (adfs)
DRV:64bit: - [2009/11/12 16:42:18 | 000,037,888 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\taphss.sys – (taphss)
DRV:64bit: - [2009/10/14 21:18:38 | 000,040,464 | —- | M] (Kaspersky Lab) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\klbg.sys – (KLBG)
DRV:64bit: - [2009/10/02 19:39:32 | 000,021,008 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\klmouflt.sys – (klmouflt)
DRV:64bit: - [2009/09/26 01:20:38 | 000,223,448 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\fvevol.sys – (fvevol)
DRV:64bit: - [2009/09/14 14:46:42 | 000,027,152 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\SysNative\drivers\klim6.sys – (KLIM6)
DRV:64bit: - [2009/09/01 15:29:56 | 000,157,712 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\SysNative\drivers\kl1.sys – (kl1)
DRV:64bit: - [2009/07/13 20:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 20:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:48:04 | 000,014,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hwpolicy.sys – (hwpolicy)
DRV:64bit: - [2009/07/13 20:47:49 | 000,055,376 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fsdepends.sys – (FsDepends)
DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 20:45:56 | 000,022,096 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wimmount.sys – (WIMMount)
DRV:64bit: - [2009/07/13 20:45:55 | 000,217,680 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vhdmp.sys – (vhdmp)
DRV:64bit: - [2009/07/13 20:45:55 | 000,036,432 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\vdrvroot.sys – (vdrvroot)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 20:45:46 | 000,214,096 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\rdyboost.sys – (rdyboost)
DRV:64bit: - [2009/07/13 20:45:45 | 000,050,768 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\pcw.sys – (pcw)
DRV:64bit: - [2009/07/13 20:43:14 | 000,460,504 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\cng.sys – (CNG)
DRV:64bit: - [2009/07/13 19:17:46 | 000,024,064 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpbus.sys – (rdpbus)
DRV:64bit: - [2009/07/13 19:16:35 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\RDPREFMP.sys – (RDPREFMP)
DRV:64bit: - [2009/07/13 19:10:24 | 000,060,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\agilevpn.sys – (RasAgileVpn) WAN Miniport (IKEv2)
DRV:64bit: - [2009/07/13 19:09:26 | 000,012,800 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\wfplwf.sys – (WfpLwf)
DRV:64bit: - [2009/07/13 19:08:13 | 000,035,328 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ndiscap.sys – (NdisCap)
DRV:64bit: - [2009/07/13 19:07:21 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vwifibus.sys – (vwifibus)
DRV:64bit: - [2009/07/13 19:07:13 | 000,227,840 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\1394ohci.sys – (1394ohci)
DRV:64bit: - [2009/07/13 19:07:00 | 000,350,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HdAudio.sys – (HdAudAddService)
DRV:64bit: - [2009/07/13 19:06:52 | 000,009,728 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\umpass.sys – (UmPass)
DRV:64bit: - [2009/07/13 19:06:28 | 000,040,448 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\winusb.sys – (WinUsb)
DRV:64bit: - [2009/07/13 19:06:24 | 000,008,192 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mshidkmdf.sys – (mshidkmdf)
DRV:64bit: - [2009/07/13 19:05:37 | 000,112,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WUDFPf.sys – (WudfPf)
DRV:64bit: - [2009/07/13 19:02:08 | 000,015,360 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\MTConfig.sys – (MTConfig)
DRV:64bit: - [2009/07/13 19:00:34 | 000,038,912 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CompositeBus.sys – (CompositeBus)
DRV:64bit: - [2009/07/13 19:00:13 | 000,006,656 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\beep.sys – (Beep)
DRV:64bit: - [2009/07/13 18:52:39 | 000,061,440 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\appid.sys – (AppID)
DRV:64bit: - [2009/07/13 18:50:17 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] – C:\Windows\SysNative\drivers\scfilter.sys – (scfilter)
DRV:64bit: - [2009/07/13 18:37:18 | 000,040,448 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\discache.sys – (discache)
DRV:64bit: - [2009/07/13 18:31:06 | 000,026,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hidbatt.sys – (HidBatt)
DRV:64bit: - [2009/07/13 18:31:03 | 000,017,664 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\CmBatt.sys – (CmBatt)
DRV:64bit: - [2009/07/13 18:27:17 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\acpipmi.sys – (AcpiPmi)
DRV:64bit: - [2009/07/13 18:19:25 | 000,060,928 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\amdppm.sys – (AmdPPM)
DRV:64bit: - [2009/06/10 15:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nvm62x64.sys – (NVENETFD)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/04/30 00:06:58 | 000,339,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvmf6264.sys – (NVNET)
DRV:64bit: - [2008/03/13 02:46:00 | 000,027,136 | —- | M] (ManyCam LLC.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ManyCam_x64.sys – (ManyCam)
DRV:64bit: - [2007/06/28 12:47:14 | 000,173,056 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nmwcdx64.sys – (nmwcdx64)
DRV - [2009/11/22 03:46:24 | 000,073,312 | —- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\adfs.sys – (adfs)
DRV - [2009/08/14 08:45:24 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/08/14 08:45:24 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2009/07/13 20:16:19 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\winusb.dll – (WinUsb)
DRV - [2009/07/13 20:16:02 | 000,014,336 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\Windows\SysWOW64\netbios.dll – (NetBIOS)
DRV - [2009/06/10 16:28:14 | 000,001,088 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\wbem\mpsdrv.mof – (mpsdrv)
DRV - [2009/06/10 16:15:18 | 000,003,066 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysWOW64\wbem\tcpip.mof – (Tcpip)
DRV - [2007/02/07 13:27:46 | 000,014,104 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | Boot | Running] – C:\Windows\SysWOW64\speedfan.sys – (speedfan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…25v105r4761s273
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…25v105r4761s273
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…25v105r4761s273
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe41}:1.0.9
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.8
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: [removed]:[removed].7
FF - prefs.js..extensions.enabledItems: StrataBuddy@ReduxTeam:0.6.2
FF - prefs.js..extensions.enabledItems: [removed]:9.0.0.736
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ea848344-1e6a-43e9-9cf8-301358888a43}:0.1.5
FF - prefs.js..network.proxy.http: "89.108.70.205"
FF - prefs.js..network.proxy.http_port: 8080


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/25 18:55:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/12 09:40:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/04/25 18:55:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/05/12 09:40:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010/04/16 22:34:27 | 000,000,000 | —D | M]

[2009/11/20 17:08:22 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\mozilla\Extensions
[2010/05/20 21:51:59 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions
[2010/04/17 00:14:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{05e38d80-09c1-11dd-bd0b-0800200c9a66}
[2010/04/08 22:33:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe41}
[2010/04/15 04:42:41 | 000,000,000 | —D | M] (Stylish) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/04/30 18:37:06 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/04/13 02:17:25 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/04/15 04:52:46 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/04/16 23:52:42 | 000,000,000 | —D | M] (Purity) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{ea848344-1e6a-43e9-9cf8-301358888a43}
[2010/04/15 09:31:22 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\[removed]
[2010/04/15 09:31:44 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\[removed]
[2010/04/16 02:13:32 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\StrataBuddy@ReduxTeam
[2010/04/16 23:52:42 | 000,000,000 | —D | M] (No name found) – C:\Users\Tito\AppData\Roaming\mozilla\Firefox\Profiles\b5yrdreg.default\extensions\{ea848344-1e6a-43e9-9cf8-301358888a43}\chrome\mozapps\extensions
[2010/03/06 18:33:13 | 000,001,196 | —- | M] () – C:\Users\Tito\AppData\Roaming\Mozilla\FireFox\Profiles\b5yrdreg.default\searchplugins\winamp-search.xml
[2010/05/12 09:40:50 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/12 09:40:50 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/16 22:34:57 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/13 17:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/05/12 23:23:16 | 000,000,154 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll (Kaspersky Lab)
O2:64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\hssie\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - Startup: C:\Users\Tito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\sbhook64.dll (Kaspersky Lab)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\kloehk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\sbhook.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll (Kaspersky Lab)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{159454be-d949-11de-9532-002511569a70}\Shell - "" = AutoRun
O33 - MountPoints2\{159454be-d949-11de-9532-002511569a70}\Shell\AutoRun\command - "" = J:\LaunchU3.exe – File not found
O33 - MountPoints2\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\Shell\AutoRun\command - "" = D:\.\AutorunX\AutorunX.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2009/07/13 22:20:14 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs:64bit: Themes - C:\Windows\SysNative\themeservice.dll (Microsoft Corporation)
NetSvcs:64bit: BDESVC - C:\Windows\SysNative\bdesvc.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias.dll (Microsoft Corporation)
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/05/21 15:11:13 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Tito\Desktop\OTL.exe
[2010/05/19 23:43:39 | 000,000,000 | —D | C] – C:\Users\Tito\AppData\Roaming\DivX
[2010/05/19 23:43:14 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/05/19 23:41:08 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/05/19 21:35:58 | 000,000,000 | —D | C] – C:\Users\Tito\AppData\Roaming\Macromedia
[2010/05/18 20:44:11 | 000,000,000 | —D | C] – C:\Users\Tito\AppData\Roaming\Media Player Classic
[2010/05/18 20:35:37 | 000,000,000 | —D | C] – C:\Users\Tito\AppData\Roaming\Template
[2010/05/18 20:09:34 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2010/05/18 20:09:33 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2010/05/18 20:09:33 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2010/05/18 20:09:31 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2010/05/18 20:09:31 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2010/05/18 20:09:30 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2010/05/18 20:09:29 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2010/05/18 20:09:29 | 001,846,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_41.dll
[2010/05/18 20:09:29 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2010/05/18 20:09:29 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_41.dll
[2010/05/18 20:09:26 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2010/05/18 20:09:26 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2010/05/18 20:09:24 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2010/05/18 20:09:24 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2010/05/18 20:09:24 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2010/05/18 20:09:24 | 000,069,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2010/05/18 20:09:23 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2010/05/18 20:09:23 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2010/05/18 20:09:22 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2010/05/18 20:09:22 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2010/05/18 20:09:21 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2010/05/18 20:09:21 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2010/05/18 20:09:21 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2010/05/18 20:09:21 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2010/05/18 20:09:19 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2010/05/18 20:09:19 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2010/05/18 20:09:18 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2010/05/18 20:09:18 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2010/05/18 20:09:18 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2010/05/18 20:09:18 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2010/05/18 20:09:17 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2010/05/18 20:09:17 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2010/05/18 20:09:15 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2010/05/18 20:09:15 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2010/05/18 20:09:14 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2010/05/18 20:09:14 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2010/05/18 20:09:14 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2010/05/18 20:09:14 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2010/05/18 20:09:12 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2010/05/18 20:09:12 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2010/05/18 20:09:12 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2010/05/18 20:09:12 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2010/05/18 20:09:12 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2010/05/18 20:09:12 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2010/05/18 20:09:09 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2010/05/18 20:09:09 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2010/05/18 20:09:09 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2010/05/18 20:09:09 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2010/05/18 20:09:09 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2010/05/18 20:09:09 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2010/05/18 20:09:08 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2010/05/18 20:09:08 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2010/05/18 20:09:08 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2010/05/18 20:09:08 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2010/05/18 20:09:08 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2010/05/18 20:09:08 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2010/05/18 20:09:08 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2010/05/18 20:09:08 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2010/05/18 20:09:07 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2010/05/18 20:09:07 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2010/05/18 20:09:07 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2010/05/18 20:09:07 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2010/05/18 20:09:07 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2010/05/18 20:03:48 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2010/05/18 20:03:48 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2010/05/18 20:03:48 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2010/05/18 20:03:47 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2010/05/18 20:03:47 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2010/05/18 20:03:47 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2010/05/18 20:03:47 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2010/05/18 20:03:46 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2010/05/18 20:03:46 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2010/05/18 20:03:45 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2010/05/18 20:03:45 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2010/05/18 20:03:43 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2010/05/18 20:03:43 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2010/05/18 20:03:43 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2010/05/18 20:03:43 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2010/05/18 20:03:42 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2010/05/18 20:03:42 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2010/05/18 20:03:41 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2010/05/18 20:03:41 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2010/05/18 20:03:40 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2010/05/18 20:03:40 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2010/05/18 20:03:40 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2010/05/18 20:03:40 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2010/05/18 20:03:40 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2010/05/18 20:03:40 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2010/05/18 20:03:39 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2010/05/18 20:03:39 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2010/05/18 20:03:39 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2010/05/18 20:03:39 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2010/05/18 20:03:39 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2010/05/18 20:03:39 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2010/05/18 20:03:39 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2010/05/18 20:03:39 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2010/05/18 20:03:38 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2010/05/18 20:03:38 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2010/05/18 20:03:37 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2010/05/18 20:03:37 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2010/05/18 20:03:36 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2010/05/18 20:03:36 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2010/05/18 20:03:36 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2010/05/18 20:03:36 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2010/05/18 20:03:36 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2010/05/18 20:03:36 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2010/05/18 20:03:35 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2010/05/18 20:03:35 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2010/05/18 20:03:34 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2010/05/18 20:03:34 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2010/05/18 20:03:34 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2010/05/18 20:03:34 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2010/05/18 20:03:33 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2010/05/18 20:03:33 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2010/05/18 20:03:33 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2010/05/18 20:03:33 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2010/05/18 20:03:33 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2010/05/18 20:03:33 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2010/05/18 20:03:33 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2010/05/18 20:03:32 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2010/05/18 20:03:32 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2010/05/18 20:03:32 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2010/05/18 20:03:32 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2010/05/18 20:03:31 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2010/05/18 20:03:31 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2010/05/18 20:03:31 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2010/05/18 20:03:31 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2010/05/18 20:03:30 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2010/05/18 20:03:30 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2010/05/18 20:03:27 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2010/05/18 20:03:27 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2010/05/18 20:03:26 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2010/05/18 20:03:26 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2010/05/18 20:03:26 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2010/05/18 20:03:26 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2010/05/18 20:03:26 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2010/05/18 20:03:26 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2010/05/18 20:03:25 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2010/05/18 20:03:25 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2010/05/18 20:03:25 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2010/05/18 20:03:25 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2010/05/18 20:03:24 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2010/05/18 20:03:24 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2010/05/18 20:03:23 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2010/05/18 20:03:23 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2010/05/18 20:03:22 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2010/05/18 20:03:22 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2010/05/18 19:58:08 | 000,000,000 | -H-D | C] – C:\Windows\msdownld.tmp
[2010/05/18 19:58:01 | 000,000,000 | —D | C] – C:\Windows\SysWow64\directx
[2010/05/18 16:40:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Combined Community Codec Pack
[2010/05/15 19:50:51 | 000,000,000 | R–D | C] – C:\Backup
[2010/05/15 19:34:53 | 000,000,000 | —D | C] – C:\IMAGES_TMP_DIR
[2010/05/15 14:49:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\EASEUS
[2010/05/14 02:05:09 | 000,000,000 | —D | C] – C:\Users\Tito\AppData\Roaming\cYo
[2010/05/14 02:05:09 | 000,000,000 | —D | C] – C:\Users\Tito\AppData\Local\cYo
[2010/05/14 01:56:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/05/14 01:02:09 | 000,000,000 | —D | C] – C:\Program Files\ComicRack
[2010/05/14 00:50:49 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010/05/14 00:50:49 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/05/14 00:50:49 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/05/14 00:50:49 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/05/14 00:50:49 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/05/14 00:50:49 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010/05/14 00:50:48 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010/05/14 00:50:48 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/05/12 21:46:13 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Macrovision Shared
[2010/05/12 21:46:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Macrovision Shared
[2010/05/12 12:46:21 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2010/05/12 09:40:48 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/05/12 09:40:48 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/05/12 09:40:48 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/05/12 09:40:48 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/05/11 18:06:33 | 000,465,472 | —- | C] (usb-audio.de) – C:\Windows\SysNative\drivers\pgusbwdm.sys
[2010/05/11 18:06:33 | 000,049,728 | —- | C] (usb-audio.de) – C:\Windows\SysNative\drivers\pgusbmm3.sys
[2010/05/08 15:00:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Haali
[2010/05/08 15:00:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\CoreCodec
[2010/05/08 04:32:25 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2010/05/08 04:32:25 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2010/05/06 12:55:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenVPN
[2010/05/06 12:14:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\UltraVPN
[2010/05/05 08:06:37 | 000,000,000 | —D | C] – C:\ProgramData\regid.1986-12.com.adobe
[2010/05/03 17:48:03 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2010/05/01 02:35:34 | 000,000,000 | -H-D | C] – C:\ProgramData\{47803536-1938-4D3F-86D6-F4876B645542}
[2010/05/01 02:35:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Native Instruments
[2010/05/01 02:35:10 | 000,000,000 | -H-D | C] – C:\ProgramData\{20EFD19B-675C-417B-A498-B0161D72FF88}
[2010/05/01 02:34:47 | 000,000,000 | -H-D | C] – C:\ProgramData\{B5F0C192-874D-49A8-88D7-8431E3714756}
[2010/04/30 20:18:55 | 000,000,000 | —D | C] – C:\Users\Tito\Documents\Native Instruments
[2010/04/30 20:18:02 | 000,000,000 | —D | C] – C:\Program Files\Native Instruments
[2010/04/30 20:18:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Native Instruments
[2010/04/28 23:18:58 | 000,000,000 | —D | C] – C:\ProgramData\Native Instruments
[2010/04/28 02:19:11 | 000,223,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fvevol.sys
[2010/04/28 02:19:09 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2010/04/28 02:19:09 | 000,153,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ksecpkg.sys
[2010/04/26 17:04:42 | 000,353,592 | —- | C] (DivX, Inc.) – C:\Windows\SysWow64\DivXControlPanelApplet.cpl
[2010/04/26 14:14:43 | 000,000,000 | –SD | C] – C:\Windows\SysWow64\Microsoft
[2010/04/23 20:51:20 | 000,000,000 | —D | C] – C:\Users\Tito\Documents\VirtualDJ
[2010/04/23 20:51:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\VirtualDJ
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/21 15:22:46 | 003,932,160 | -HS- | M] () – C:\Users\Tito\ntuser.dat
[2010/05/21 15:14:37 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/21 15:14:37 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/21 15:14:26 | 000,778,150 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/05/21 15:14:26 | 000,659,580 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/05/21 15:14:26 | 000,120,508 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/05/21 15:11:16 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Tito\Desktop\OTL.exe
[2010/05/21 15:07:10 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/21 15:07:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/21 15:07:05 | 335,044,607 | -HS- | M] () – C:\hiberfil.sys
[2010/05/21 04:19:41 | 004,635,135 | -H– | M] () – C:\Users\Tito\AppData\Local\IconCache.db
[2010/05/21 01:22:43 | 000,002,223 | —- | M] () – C:\Users\Tito\Desktop\Media Player Classic - Home Cinema.lnk
[2010/05/20 04:47:55 | 000,524,288 | -HS- | M] () – C:\Users\Tito\ntuser.dat{1d71083f-6378-11df-bbb2-002511569a70}.TMContainer00000000000000000002.regtrans-ms
[2010/05/20 04:47:55 | 000,524,288 | -HS- | M] () – C:\Users\Tito\ntuser.dat{1d71083f-6378-11df-bbb2-002511569a70}.TMContainer00000000000000000001.regtrans-ms
[2010/05/20 04:47:55 | 000,065,536 | -HS- | M] () – C:\Users\Tito\ntuser.dat{1d71083f-6378-11df-bbb2-002511569a70}.TM.blf
[2010/05/19 23:44:01 | 000,001,614 | —- | M] () – C:\Users\Tito\Desktop\DivX Movies.lnk
[2010/05/19 23:43:35 | 000,001,085 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/05/19 23:43:10 | 000,001,125 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2010/05/19 19:44:33 | 000,007,607 | —- | M] () – C:\Users\Tito\AppData\Local\Resmon.ResmonCfg
[2010/05/18 19:36:07 | 000,000,917 | —- | M] () – C:\Users\Tito\AppData\Roaming\coreavc.ini
[2010/05/16 01:07:00 | 000,000,849 | —- | M] () – C:\Users\Public\Desktop\ComicRack.lnk
[2010/05/16 00:04:30 | 000,035,048 | —- | M] () – C:\Windows\temp.bmp
[2010/05/14 02:08:07 | 000,006,114 | —- | M] () – C:\Users\Tito\Documents\CCLEANER.reg
[2010/05/14 02:01:31 | 000,771,962 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/13 10:18:23 | 004,907,616 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/05/12 22:54:24 | 000,082,256 | —- | M] () – C:\Users\Tito\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/11 18:03:41 | 000,465,472 | —- | M] (usb-audio.de) – C:\Windows\SysNative\drivers\pgusbwdm.sys
[2010/05/11 18:03:32 | 000,049,728 | —- | M] (usb-audio.de) – C:\Windows\SysNative\drivers\pgusbmm3.sys
[2010/05/10 10:29:50 | 1073,741,823 | —- | M] () – C:\Users\Tito\Documents\crypt4
[2010/05/09 07:59:19 | 000,001,456 | —- | M] () – C:\Users\Tito\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/05/06 12:56:25 | 000,001,098 | —- | M] () – C:\Users\Tito\Desktop\OpenVPN GUI.lnk
[2010/05/06 12:28:36 | 000,001,091 | —- | M] () – C:\Users\Tito\Desktop\UltraVPN.lnk
[2010/05/06 03:55:37 | 000,000,132 | —- | M] () – C:\Users\Tito\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2010/05/05 02:36:24 | 000,149,773 | —- | M] () – C:\Windows\SysNative\drivers\klin.dat
[2010/05/05 02:36:24 | 000,106,765 | —- | M] () – C:\Windows\SysNative\drivers\klick.dat
[2010/05/01 20:11:01 | 000,332,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2010/05/01 20:10:58 | 002,851,328 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\themeui.dll
[2010/05/01 20:10:56 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\themeservice.dll
[2010/05/01 05:37:07 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2010/05/01 05:36:55 | 000,002,691 | —- | M] () – C:\Users\Tito\Documents\DJ.rtf
[2010/05/01 02:35:31 | 000,000,999 | —- | M] () – C:\Users\Public\Desktop\Traktor.lnk
[2010/05/01 02:35:09 | 000,001,103 | —- | M] () – C:\Users\Public\Desktop\Controller Editor.lnk
[2010/05/01 02:34:46 | 000,001,068 | —- | M] () – C:\Users\Public\Desktop\Service Center.lnk
[2010/04/30 20:08:09 | 000,001,858 | —- | M] () – C:\Users\Tito\Desktop\CCleaner.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/29 00:57:34 | 000,001,111 | —- | M] () – C:\Users\Tito\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2010/04/26 17:04:42 | 000,353,592 | —- | M] (DivX, Inc.) – C:\Windows\SysWow64\DivXControlPanelApplet.cpl
[2010/04/26 14:13:10 | 001,374,664 | —- | M] () – C:\Users\Tito\Desktop\MCPR.exe
[2010/04/23 20:51:24 | 000,001,022 | —- | M] () – C:\Users\Tito\Desktop\Virtual DJ Trial.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/21 01:22:43 | 000,002,223 | —- | C] () – C:\Users\Tito\Desktop\Media Player Classic - Home Cinema.lnk
[2010/05/19 23:43:35 | 000,001,085 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/05/19 23:43:10 | 000,001,125 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2010/05/19 21:24:31 | 000,524,288 | -HS- | C] () – C:\Users\Tito\ntuser.dat{1d71083f-6378-11df-bbb2-002511569a70}.TMContainer00000000000000000002.regtrans-ms
[2010/05/19 21:24:31 | 000,524,288 | -HS- | C] () – C:\Users\Tito\ntuser.dat{1d71083f-6378-11df-bbb2-002511569a70}.TMContainer00000000000000000001.regtrans-ms
[2010/05/19 21:24:31 | 000,065,536 | -HS- | C] () – C:\Users\Tito\ntuser.dat{1d71083f-6378-11df-bbb2-002511569a70}.TM.blf
[2010/05/14 02:01:29 | 000,771,962 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/05/14 01:02:10 | 000,000,849 | —- | C] () – C:\Users\Public\Desktop\ComicRack.lnk
[2010/05/10 10:28:48 | 1073,741,823 | —- | C] () – C:\Users\Tito\Documents\crypt4
[2010/05/09 06:03:27 | 000,000,917 | —- | C] () – C:\Users\Tito\AppData\Roaming\coreavc.ini
[2010/05/08 10:36:30 | 000,001,456 | —- | C] () – C:\Users\Tito\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/05/06 12:56:25 | 000,001,098 | —- | C] () – C:\Users\Tito\Desktop\OpenVPN GUI.lnk
[2010/05/06 12:14:38 | 000,001,091 | —- | C] () – C:\Users\Tito\Desktop\UltraVPN.lnk
[2010/05/06 11:23:15 | 000,047,104 | -HS- | C] () – C:\Users\Tito\AppData\Roaming\Thumbs.db
[2010/05/06 00:19:57 | 000,000,132 | —- | C] () – C:\Users\Tito\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2010/05/01 05:36:55 | 000,002,691 | —- | C] () – C:\Users\Tito\Documents\DJ.rtf
[2010/05/01 02:35:31 | 000,000,999 | —- | C] () – C:\Users\Public\Desktop\Traktor.lnk
[2010/05/01 02:34:46 | 000,001,068 | —- | C] () – C:\Users\Public\Desktop\Service Center.lnk
[2010/04/30 20:18:17 | 000,001,103 | —- | C] () – C:\Users\Public\Desktop\Controller Editor.lnk
[2010/04/26 14:13:09 | 001,374,664 | —- | C] () – C:\Users\Tito\Desktop\MCPR.exe
[2010/04/23 20:51:24 | 000,001,022 | —- | C] () – C:\Users\Tito\Desktop\Virtual DJ Trial.lnk
[2010/03/16 13:07:24 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2009/12/06 14:03:01 | 000,000,112 | —- | C] () – C:\Windows\wininit.ini
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/05/14 02:05:09 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\cYo
[2010/05/19 21:18:26 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\Rainmeter
[2010/05/18 20:35:37 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\Template
[2010/02/28 17:42:03 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\Tific
[2010/05/21 04:19:42 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\uTorrent
[2010/02/09 17:30:21 | 000,000,000 | —D | M] – C:\Users\Tito\AppData\Roaming\WebcamMax
[2010/05/05 01:38:52 | 000,032,582 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 20:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 20:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 20:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 20:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 20:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 20:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 20:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 20:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/13 20:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 20:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 20:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 20:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 20:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 20:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 20:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 20:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 20:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 20:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 20:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 20:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 20:15:50 | 001,386,496 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\msvbvm60.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
< End of report >


OTL Extras logfile created on: 5/21/2010 3:15:01 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Users\Tito\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 79.00% Memory free
11.00 Gb Paging File | 10.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.54 Gb Total Space | 556.69 Gb Free Space | 81.44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC
Current User Name: Tito
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2AAC4085-DCBF-417B-AEBD-182197839240}" = Native Instruments Traktor
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"ComicRack" = ComicRack v0.9.123
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v1.3.1906.0
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = eMachines Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"ASIO4ALL" = ASIO4ALL
"ATT-PRT22" = ATT-PRT22
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combined Community Codec Pack BETA_is1" = Combined Community Codec Pack BETA 2010-05-09
"CoreAVC Professional Edition" = CoreAVC Professional Edition (remove only)
"DivX Setup.divx.com" = DivX Setup
"eMachines Registration" = eMachines Registration
"eMachines Welcome Center" = Welcome Center
"FL Studio 9" = FL Studio 9
"Guitar Pro 5_is1" = Guitar Pro 5.2
"HaaliMkx" = Haali Media Splitter
"HotspotShield" = Hotspot Shield 1.41
"Identity Card" = Identity Card
"IL Download Manager" = IL Download Manager
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"mIRC" = mIRC
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Pro-53" = Native Instruments Pro-53
"Native Instruments Service Center" = Native Instruments Service Center
"Native Instruments Traktor" = Native Instruments Traktor
"ObjectDock Plus" = ObjectDock Plus
"OpenVPN" = OpenVPN 2.1.1
"PoiZone" = PoiZone
"Rainmeter" = Rainmeter (remove only)
"reFX Nexus_is1" = reFX Nexus VSTi RTAS v2.2.0
"Sawer" = Sawer
"SpeedFan" = SpeedFan (remove only)
"Toxic Biohazard" = Toxic Biohazard
"uTorrent" = µTorrent
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"VLC media player" = VLC media player 1.0.5
"WebcamMax" = WebcamMax
"Win7 Taskbar" = Win7 Taskbar v1.13
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/11/2010 3:54:21 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x00034230 Faulting process
id: 0x96c Faulting application start time: 0x01caf143b88fb100 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: fd192950-5d36-11df-a141-002511569a70

Error - 5/11/2010 3:58:05 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x00033185 Faulting process
id: 0x2d0 Faulting application start time: 0x01caf143cc8d1f80 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 82a52650-5d37-11df-a141-002511569a70

Error - 5/11/2010 6:44:28 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x00033df9 Faulting process
id: 0x67c Faulting application start time: 0x01caf1557c28e134 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: c10bd4a4-5d4e-11df-a141-002511569a70

Error - 5/11/2010 6:50:37 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x00034230 Faulting process
id: 0x664 Faulting application start time: 0x01caf15b97113054 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 9d5b84f4-5d4f-11df-a141-002511569a70

Error - 5/11/2010 7:12:50 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x0003317f Faulting process
id: 0x11e8 Faulting application start time: 0x01caf15f6689b95c Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: b785debc-5d52-11df-a141-002511569a70

Error - 5/11/2010 7:15:39 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x0003317f Faulting process
id: 0x460 Faulting application start time: 0x01caf15f930f6ddc Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 1c897954-5d53-11df-a141-002511569a70

Error - 5/11/2010 7:18:16 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x0003317f Faulting process
id: 0x5bc Faulting application start time: 0x01caf15fe290bf14 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 79b84d44-5d53-11df-a141-002511569a70

Error - 5/11/2010 7:19:24 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x00034230 Faulting process
id: 0x2e8 Faulting application start time: 0x01caf1605e4ff9e4 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: a2cafb14-5d53-11df-a141-002511569a70

Error - 5/11/2010 7:19:47 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: ntdll.dll, version: 6.1.7600.16385, time
stamp: 0x4a5bdb3b Exception code: 0xc0000005 Fault offset: 0x00033915 Faulting process
id: 0x200 Faulting application start time: 0x01caf1606dbd4184 Faulting application
path: C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: b0031334-5d53-11df-a141-002511569a70

Error - 5/11/2010 7:20:06 PM | Computer Name = PC | Source = Application Error | ID = 1000
Description = Faulting application name: nspn125.exe, version: 1.2.5.8382, time
stamp: 0x4ba0fa7c Faulting module name: nspn125.exe, version: 1.2.5.8382, time stamp:
0x4ba0fa7c Exception code: 0x40000015 Fault offset: 0x0047e994 Faulting process id:
0x1318 Faulting application start time: 0x01caf16077501f64 Faulting application path:
C:\Program Files\Native Instruments\Traktor\nspn125.exe Faulting module path: C:\Program
Files\Native Instruments\Traktor\nspn125.exe Report Id: bbd559c4-5d53-11df-a141-002511569a70

[ System Events ]
Error - 5/14/2010 3:34:46 AM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 5/14/2010 5:44:50 AM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 5/14/2010 3:21:55 PM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 5/15/2010 1:02:18 PM | Computer Name = PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR8.

Error - 5/15/2010 1:02:19 PM | Computer Name = PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR8.

Error - 5/15/2010 1:02:20 PM | Computer Name = PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk6\DR8.

Error - 5/15/2010 5:27:39 PM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 5/15/2010 5:33:02 PM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 5/15/2010 7:04:42 PM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 5/17/2010 4:01:28 AM | Computer Name = PC | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.


< End of report >
i don't think the Gmer scan ran properly, because something strange happened when I opened Gmer. I couldn't tick some of the boxes that were ticked in the picture, it just wouldn't let me. Here's a screen shot of what i mean:


[external image: Posted Image]

I ran the scan anyway, and when it finished it said no changes were made. When i pressed the save button a blank Log was saved.
Hello eros1

Thank you for the logs.

Please work your way through the following steps:

  • P2P Programs:

    • P2P programs are a major source of Malware infections.
    • From your log I see you have UTorrent. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on the "Windows Orb" (bottom left hand corner of your screen), then on "Computer" and then on the "Uninstall or Change a Program" tab.
    • A list of currently installed programs will be displayed.
    • Find the "UTorrent" program, click on it once and then click on the "Uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
      O4 - HKCU..\Run: [AdobeBridge] File not found
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
      O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
      O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O33 - MountPoints2\{159454be-d949-11de-9532-002511569a70}\Shell - "" = AutoRun
      O33 - MountPoints2\{159454be-d949-11de-9532-002511569a70}\Shell\AutoRun\command - "" = J:\LaunchU3.exe – File not found
      O33 - MountPoints2\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\Shell - "" = AutoRun
      O33 - MountPoints2\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\Shell\AutoRun\command - "" = D:\.\AutorunX\AutorunX.exe – File not found
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • MalwareBytes AntiMalware:


    • I can see that you have MalwareBytes AntiMalware installed.
    • Open the program and click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • GMER:


    • Are you able to run GMER now?

    Please provide the OTL log, the MBAM log and the GMER log (if you are able to run it) in your next reply.
All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully. Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ deleted successfully. File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A9007C0-4076-11D3-8789-0000F8105754}\ deleted successfully. File {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found. File {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ deleted successfully. File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{159454be-d949-11de-9532-002511569a70}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{159454be-d949-11de-9532-002511569a70}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{159454be-d949-11de-9532-002511569a70}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{159454be-d949-11de-9532-002511569a70}\ not found. File J:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5aff0e4d-93fc-11de-88e4-806e6f6e6963}\ not found. File D:\.\AutorunX\AutorunX.exe not found. C:\Windows\msdownld.tmp folder deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 41620 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: My-PC User: Public User: Tito ->Temp folder emptied: 3119600 bytes ->Temporary Internet Files folder emptied: 776095 bytes ->Java cache emptied: 73077668 bytes ->FireFox cache emptied: 67843189 bytes ->Flash cache emptied: 10245 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 55328 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 802072743 bytes Total Files Cleaned = 903.00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: My-PC User: Public User: Tito ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.5.0 log created on 05232010_202809 Files\Folders moved on Reboot… C:\Users\Tito\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4135 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 5/23/2010 9:46:27 PM mbam-log-2010-05-23 (21-46-27).txt Scan type: Full scan (C:\|) Objects scanned: 252763 Time elapsed: 1 hour(s), 13 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I was unable to run Gmer.
Hello eros1

My apologies for the delay.

Thank you for the logs.

Please work your way through the following steps. If you encounter any difficulties, come back and let me know.


  • Please run the following scan


    NOTES:
  • Before performing this online scan you must open your Internet Browser as Administrator. To do this, Right Click on your Internet Browser icon and select "Run as Administrator".
  • Once the scan is complete and you have saved the log produced, close your browser.
  • For all other browsing, open your browser by left clicking in the normal way.


  • Scan your system with Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use.
  • Click the "Start" button.
  • Now click the "Install" button.
  • Click "Start". The scanner engine will initialise and update.
  • Do Not place a check mark in the box beside "Remove found threats".
  • Click the "Scan" button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Also, please describe how your machine is behaving now. Are you still experiencing problems?
ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.7600.16385 (win7_rtm.090713-1255) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=e195e5fe78f5054fb718a1bcb56e0227 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-05-27 09:41:55 # local_time=2010-05-27 04:41:55 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1280 16777215 100 0 2589639 2589639 0 0 # compatibility_mode=5893 16776573 100 94 0 26529937 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=145824 # found=2 # cleaned=0 # scan_time=10028 C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application 00000000000000000000000000000000 I C:\Windows\Temp\hss_update.exe a variant of Win32/HotSpotShield application 00000000000000000000000000000000 I It's still acting funny; I experience times where my computer feels slow. When I'm using an application, or when I'm just browsing around; things seem like they take longer to load/open. I believe my computer is more than capable of handling these tasks with ease, and it did, but now for some reason it feels different.
Hello eros1

yes it's still acting funny


Thank you for letting me know. The ESET Online Scan you performed flagged two files that need our attention. Please work your way through the following steps:


  • Please open OTL


  • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    
    :Files
    C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
    C:\Windows\Temp\hss_update.exe
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]

  • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
  • Allow the program to run unhindered.
  • Your machine will re-start itself. This is normal.
  • A log will be created after your machine reboots.

Please post the contents of the log in your next reply, and let me know how your machine is behaving now.
All processes killed ========== OTL ========== No active process named explorer.exe was found! ========== FILES ========== C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe moved successfully. File\Folder C:\Windows\Temp\hss_update.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 353858 bytes ->Temporary Internet Files folder emptied: 57609 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: My-PC User: Public User: Tito ->Temp folder emptied: 2312773 bytes ->Temporary Internet Files folder emptied: 368998 bytes ->Java cache emptied: 1275417 bytes ->FireFox cache emptied: 80806015 bytes ->Flash cache emptied: 3138 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 56144 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 1406013879 bytes Total Files Cleaned = 1,422.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Default User: Default User User: My-PC User: Public User: Tito ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.5.0 log created on 06012010_102532 Files\Folders moved on Reboot… C:\Users\Tito\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… I'd say it's runny pretty ok
Hello eros1

I'd say it's runny pretty ok

Thats great news :)

Please work your way through the following steps:

  • Removal of Tools


    • You no longer need OTL or GMER. Please delete them from your system.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.


  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
I thank you for your help, jontom! There is one last question i have; it concerns previous threads I've made. Is there a way i can go about deleting said threads?
Hello eros1

Is there a way i can go about deleting said threads

I am not authorised to edit or delete any posts that are made on this forum. If you want a thread completely deleted, my advice would be to contact a forum Moderator or Administrator, providing them with a link to the thread(s) in question and the reason(s) why you would like them deleted.

I thank you for your help, jontom!

You are Very Welcome :)
Best wishes
JonTom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI