This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] Having Problems With Malware

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use google chrome. It keeps redirecting my google searches to random websites that have nothing to do with the links in my google searches. I researched this to see if anybody else has been having this problem, and they have, they said it was malware attacking the host files or something? So I used a suggested malware removal program malwarebytes but nothing showed up in the scan. So I need some help, here are the results from the Hijackthis scan, here is the logfile:




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:18:09 AM, on 12/06/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18470)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Users\Oliver\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe
C:\Program Files (x86)\FrostWire\FrostWire.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Oliver\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: CacherBHO - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - C:\Program Files (x86)\Moyea\YouTube FLV Downloader\MoyeaCatcher.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [TSMAgent] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Oliver\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD RAIDXpert (AMD_RAIDXpert) - AMD - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Easy Backup Button Service (HPBtnSrv) - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11205 bytes

Hope someone can help me and I hope I posted this correctly. Tried to follow the directions in the "Are you Infected? Need Help?, Getting Started: How To Get Help" topic to a T.

Thanks

Attachments:

Hello otter and welcome to WhatTheTech. Please follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)a
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • DDS and Attach.txt logs
  • GMER log
Okay I ran the scans DDS came up with something but when I ran the gmer toolkit scan nothing showed up, I did it twice unchecking the file box this time. I saved the tet files but they are empty. It said gmer didn't find any modification or anything like that. Any suggestions? Here is the logfile for the dds report. DDS (Ver_10-03-17.01) - NTFSX64 Run by [removed] at 20:44:46.19 on 12/06/2010 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_16 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.8183.5947 [GMT -5:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\WinZip\WZQKPICK.EXE C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Windows\ehome\ehmsas.exe C:\Windows\ehome\ehsched.exe C:\Windows\ehome\ehRecvr.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\conime.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\SysWOW64\WinMsgBalloonServer.exe C:\Windows\SysWOW64\WinMsgBalloonClient.exe C:\Windows\SysWOW64\BeepApp.exe c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe C:\Program Files (x86)\Safari\Safari.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Oliver\Desktop\dds.scr And attached is the attach.txt
You can skip the GMER scan for now. I need you to repost DDS.txt and Attach.txt though - the DDS.txt log you posted is only a partial log. I need to see the whole thing. Thanks.
My apologies here is the whole thing… DDS (Ver_10-03-17.01) - NTFSX64 Run by [removed] at 20:44:46.19 on 12/06/2010 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_16 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.8183.5947 [GMT -5:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\WinZip\WZQKPICK.EXE C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Windows\ehome\ehmsas.exe C:\Windows\ehome\ehsched.exe C:\Windows\ehome\ehRecvr.exe c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\conime.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\SysWOW64\WinMsgBalloonServer.exe C:\Windows\SysWOW64\WinMsgBalloonClient.exe C:\Windows\SysWOW64\BeepApp.exe c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files (x86)\Hewlett-Packard\KBD\kbd.exe C:\Program Files (x86)\Safari\Safari.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Oliver\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.ask.com?o=14196&l=dis uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=93&bd=Pavilion&pf=cndt mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=93&bd=Pavilion&pf=cndt mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=93&bd=Pavilion&pf=cndt mWinlogon: Userinit=userinit.exe BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\16.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\16.8.0.41\IPSBHO.DLL BHO: CatcherBHO Class: {9b4df450-dcc7-4b07-935d-0cd757a64583} - c:\program files (x86)\moyea\youtube flv downloader\MoyeaCatcher.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn\toolbar\3.0.0552.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files (x86)\msn\toolbar\3.0.0552.0\msneshellx.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\16.8.0.41\coIEPlg.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [HPADVISOR] c:\program files (x86)\hewlett-packard\hp advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Skype] "c:\program files (x86)\skype\phone\Skype.exe" /nosplash /minimized uRun: [WMPNSCFG] c:\program files (x86)\windows media player\WMPNSCFG.exe mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe mRun: [KBD] c:\program files (x86)\hewlett-packard\kbd\KbdStub.EXE mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [HP Health Check Scheduler] c:\program files (x86)\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [UpdateP2GoShortCut] "c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdateLBPShortCut] "c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5" mRun: [UpdatePDIRShortCut] "c:\program files (x86)\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [UpdatePSTShortCut] "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [TSMAgent] "c:\program files (x86)\hewlett-packard\touchsmart\media\TSMAgent.exe" mRun: [CLMLServer for HP TouchSmart] "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\CLMLSvc.exe" mRun: [DVDAgent] "c:\program files (x86)\hewlett-packard\media\dvd\DVDAgent.exe" mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe mRun: [Microsoft Default Manager] "c:\program files (x86)\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [avgnt] "c:\program files (x86)\avira\antivir desktop\avgnt.exe" /min mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files (x86)\winzip\WZQKPICK.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files (x86)\norton internet security\engine\16.8.0.41\CoIEPlg.dll TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun-x64: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ================= FIREFOX =================== FF - ProfilePath - c:\users\oliver\appdata\roaming\mozilla\firefox\profiles\iw5tcj7q.default\ FF - prefs.js: browser.startup.homepage - www.google.ca FF - component: c:\program files (x86)\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll FF - plugin: c:\users\oliver\appdata\local\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\users\oliver\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 ahcix64s;ahcix64s;c:\windows\system32\drivers\ahcix64s.sys [2009-7-13 227856] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1008000.029\SymEFA64.sys [2010-3-14 402992] R1 BHDrvx64;Symantec Heuristics Driver;c:\windows\system32\drivers\nisx64\1008000.029\BHDrvx64.sys [2010-3-14 334384] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1008000.029\cchpx64.sys [2010-3-14 583296] R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20091111.001\IDSviA64.sys [2009-11-20 466992] R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/13 13:27:52];c:\program files (x86)\hewlett-packard\media\dvd\000.fcl [2009-7-13 146928] R2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files (x86)\amd\raidxpert\bin\RAIDXpertService.exe [2008-10-2 122880] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\avira\antivir desktop\sched.exe [2009-11-4 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files (x86)\avira\antivir desktop\avguard.exe [2009-11-4 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-11-4 74880] R2 HPBtnSrv;HP Easy Backup Button Service;c:\program files (x86)\hewlett-packard\hp easy backup\HPBtnSrv.exe [2009-7-13 192512] R2 Norton Internet Security;Norton Internet Security;c:\program files (x86)\norton internet security\engine\16.8.0.41\ccSvcHst.exe [2010-3-14 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-11-3 132656] R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2009-7-13 1686528] R3 netr7364;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\drivers\netr7364.sys [2009-7-13 615424] R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-7-13 26168] S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-11-21 93184] S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-2-2 23536] S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968] S3 US122;US122 Driver;c:\windows\system32\drivers\US122x64.sys [2010-6-2 200320] S3 US122DL;US122 Firmware Downloader;c:\windows\system32\drivers\US122DLx64.sys [2010-6-2 20224] S3 US122WdmService;US122 Wdm Audio;c:\windows\system32\drivers\US122Wdmx64.sys [2010-6-2 62976] S4 hcw85cir;Hauppauge Consumer Infrared Receiver;c:\windows\system32\drivers\hcw85cir.sys [2009-7-13 31232] =============== Created Last 30 ================ 2010-06-13 01:25:58 0 d—–w- c:\windows\system32\EventProviders 2010-06-12 11:02:42 0 d—–w- c:\program files (x86)\Trend Micro 2010-06-12 10:56:42 0 d—–w- c:\users\oliver\appdata\roaming\Malwarebytes 2010-06-12 10:56:33 24664 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-06-12 10:56:33 0 d—–w- c:\programdata\Malwarebytes 2010-06-12 10:56:33 0 d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2010-06-12 10:46:15 0 d—–w- c:\users\oliver\appdata\roaming\QuickScan 2010-06-11 09:41:59 0 d—–w- C:\temp 2010-06-11 09:41:54 0 d—–w- c:\users\oliver\appdata\roaming\Music Editor Free 2010-06-11 09:41:45 113486 —-a-w- c:\windows\syswow64\NCTWMAProfiles.prx 2010-06-11 09:41:44 880640 —-a-w- c:\windows\syswow64\NCTAudioEditor2.dll 2010-06-11 09:41:44 835584 —-a-w- c:\windows\syswow64\NCTAudioCDGrabber2.dll 2010-06-11 09:41:44 602112 —-a-w- c:\windows\syswow64\NCTAudioTransform2.dll 2010-06-11 09:41:44 479232 —-a-w- c:\windows\syswow64\NCTAudioVisualization2.dll 2010-06-11 09:41:44 458752 —-a-w- c:\windows\syswow64\NCTAudioRecord2.dll 2010-06-11 09:41:44 458752 —-a-w- c:\windows\syswow64\NCTAudioPlayer2.dll 2010-06-11 09:41:44 417792 —-a-w- c:\windows\syswow64\NCTTextToAudio2.dll 2010-06-11 09:41:44 348160 —-a-w- c:\windows\syswow64\NCTWMAFile2.dll 2010-06-11 09:41:44 1986560 —-a-w- c:\windows\syswow64\NCTAudioFile2.dll 2010-06-11 09:41:44 1212416 —-a-w- c:\windows\syswow64\NCTAudioInformation2.dll 2010-06-11 09:41:43 0 d—–w- c:\program files (x86)\Music Editor Free 2010-06-11 09:14:41 16 —-a-w- c:\windows\syswow64\w3data.vss 2010-06-11 09:14:41 16 —-a-w- c:\windows\syswow64\msvcsv60.dll 2010-06-11 09:14:41 16 —-a-w- c:\windows\msocreg32.dat 2010-06-11 09:14:19 0 d—–w- c:\users\oliver\appdata\roaming\GetRightToGo 2010-06-08 23:24:43 48128 —-a-w- c:\windows\system32\atmlib.dll 2010-06-08 23:24:43 366080 —-a-w- c:\windows\system32\atmfd.dll 2010-06-08 23:24:43 34304 —-a-w- c:\windows\syswow64\atmlib.dll 2010-06-08 23:24:43 289792 —-a-w- c:\windows\syswow64\atmfd.dll 2010-06-08 23:16:52 84480 —-a-w- c:\windows\system32\asycfilt.dll 2010-06-08 23:16:52 67072 —-a-w- c:\windows\syswow64\asycfilt.dll 2010-06-08 23:12:25 2750976 —-a-w- c:\windows\system32\win32k.sys 2010-06-08 22:47:52 1570816 —-a-w- c:\windows\system32\quartz.dll 2010-06-08 22:47:52 1314816 —-a-w- c:\windows\syswow64\quartz.dll 2010-06-08 05:51:25 56 —ha-w- c:\programdata\ezsidmv.dat 2010-06-08 05:48:31 0 d—–r- c:\program files (x86)\Skype 2010-06-08 05:48:27 0 d—–w- c:\programdata\Skype 2010-06-03 10:14:36 0 d—–w- c:\users\oliver\appdata\roaming\PeerNetworking 2010-06-03 07:03:04 0 d—–w- c:\users\oliver\appdata\roaming\Facebook 2010-06-03 06:00:12 1490 —-a-w- c:\users\oliver\.recently-used.xbel 2010-06-02 09:36:28 0 d—–w- C:\Westwood 2010-06-02 05:59:27 0 d—–w- c:\programdata\Sonoma Wire Works 2010-06-02 05:59:27 0 d—–w- c:\program files (x86)\Vstplugins 2010-06-02 05:59:27 0 d—–w- c:\program files (x86)\IK Multimedia 2010-06-02 05:59:24 0 d—–w- c:\program files (x86)\Sonoma Wire Works 2010-06-02 05:47:19 0 d—–w- c:\users\oliver\Untitled 2010-06-02 05:22:13 62976 —-a-w- c:\windows\system32\drivers\US122Wdmx64.sys 2010-06-02 05:22:13 555008 —-a-w- c:\windows\system32\US122cp.cpl 2010-06-02 05:22:13 223232 —-a-w- c:\windows\system32\U122_A24x64.DLL 2010-06-02 05:22:13 223232 —-a-w- c:\windows\system32\U122_A16x64.DLL 2010-06-02 05:22:13 20224 —-a-w- c:\windows\system32\drivers\US122DLx64.sys 2010-06-02 05:22:13 200320 —-a-w- c:\windows\system32\drivers\US122x64.sys 2010-06-02 05:22:13 172032 —-a-w- c:\windows\syswow64\U122_A24.DLL 2010-06-02 05:22:13 172032 —-a-w- c:\windows\syswow64\U122_A16.DLL 2010-06-02 05:22:12 0 d—–w- c:\program files\US122 2010-06-02 04:58:09 0 d—–w- c:\programdata\WinZip 2010-06-02 01:14:27 442368 —-a-w- c:\windows\system32\winhttp.dll 2010-06-02 01:14:27 378368 —-a-w- c:\windows\syswow64\winhttp.dll 2010-05-31 11:12:29 656384 —-a-w- c:\windows\system32\kerberos.dll 2010-05-31 11:12:28 499712 —-a-w- c:\windows\syswow64\kerberos.dll 2010-05-31 11:12:27 338944 —-a-w- c:\windows\system32\schannel.dll 2010-05-31 11:12:27 270848 —-a-w- c:\windows\syswow64\schannel.dll 2010-05-27 19:51:28 0 d—–w- c:\users\oliver\appdata\roaming\AnvSoft 2010-05-27 19:51:25 0 d—–w- c:\program files (x86)\AnvSoft 2010-05-27 19:45:10 2048 —-a-w- c:\windows\syswow64\tzres.dll 2010-05-27 19:45:10 2048 —-a-w- c:\windows\system32\tzres.dll 2010-05-23 00:49:13 0 d—–w- c:\users\oliver\appdata\roaming\Dropbox 2010-05-18 23:09:18 1420688 —-a-w- c:\windows\system32\drivers\tcpip.sys 2010-05-18 23:09:17 29696 —-a-w- c:\windows\system32\drivers\tunnel.sys 2010-05-18 23:09:17 224256 —-a-w- c:\windows\system32\iphlpsvc.dll 2010-05-18 23:09:04 135168 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-05-18 23:09:03 273920 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2010-05-18 23:09:03 105472 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2010-05-18 23:08:59 4690832 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-05-18 23:08:57 974848 —-a-w- c:\windows\system32\inetcomm.dll 2010-05-18 23:08:56 738304 —-a-w- c:\windows\syswow64\inetcomm.dll 2010-05-18 23:08:52 603648 —-a-w- c:\windows\system32\vbscript.dll 2010-05-18 23:08:52 430080 —-a-w- c:\windows\syswow64\vbscript.dll 2010-05-18 23:08:37 72192 —-a-w- c:\windows\system32\l3codeca.acm 2010-05-18 23:08:37 62464 —-a-w- c:\windows\syswow64\l3codeca.acm 2010-05-18 23:06:05 98304 —-a-w- c:\windows\syswow64\cabview.dll 2010-05-18 23:06:05 104960 —-a-w- c:\windows\system32\cabview.dll 2010-05-18 23:05:09 218112 —-a-w- c:\windows\system32\wintrust.dll 2010-05-18 23:05:09 171520 —-a-w- c:\windows\syswow64\wintrust.dll ==================== Find3M ==================== 2010-06-02 05:22:49 86016 —-a-w- c:\windows\inf\infstor.dat 2010-06-02 05:22:49 51200 —-a-w- c:\windows\inf\infpub.dat 2010-06-02 05:22:48 143360 —-a-w- c:\windows\inf\infstrng.dat 2010-05-12 16:21:16 270208 ——w- c:\windows\system32\MpSigStub.exe 2010-05-08 05:40:14 311296 —-a-w- c:\windows\syswow64\TubeFinder.exe 2010-05-04 19:18:31 1032704 —-a-w- c:\windows\system32\wininet.dll 2010-05-04 19:12:17 86528 —-a-w- c:\windows\system32\ieencode.dll 2010-05-04 18:42:57 833024 —-a-w- c:\windows\syswow64\wininet.dll 2010-05-04 18:42:38 1174528 —-a-w- c:\windows\syswow64\urlmon.dll 2010-05-04 18:41:08 146432 —-a-w- c:\windows\syswow64\occache.dll 2010-05-04 18:39:56 671232 —-a-w- c:\windows\syswow64\mstime.dll 2010-05-04 18:39:32 476672 —-a-w- c:\windows\syswow64\mshtmled.dll 2010-05-04 18:39:32 3586048 —-a-w- c:\windows\syswow64\mshtml.dll 2010-05-04 18:39:31 458240 —-a-w- c:\windows\syswow64\msfeeds.dll 2010-05-04 18:38:18 28160 —-a-w- c:\windows\syswow64\jsproxy.dll 2010-05-04 18:37:46 6069248 —-a-w- c:\windows\syswow64\ieframe.dll 2010-05-04 18:37:46 270848 —-a-w- c:\windows\syswow64\iertutil.dll 2010-05-04 18:37:46 193024 —-a-w- c:\windows\syswow64\iepeers.dll 2010-05-04 18:37:45 78336 —-a-w- c:\windows\syswow64\ieencode.dll 2010-05-04 18:37:45 389120 —-a-w- c:\windows\syswow64\iedkcs32.dll 2010-05-04 18:37:45 380928 —-a-w- c:\windows\syswow64\ieapfltr.dll 2010-05-04 18:37:44 230400 —-a-w- c:\windows\syswow64\ieaksie.dll 2010-05-04 17:27:37 32768 —-a-w- c:\windows\system32\ieUnatt.exe 2010-05-04 16:53:56 26624 —-a-w- c:\windows\syswow64\ieUnatt.exe 2009-07-13 20:25:51 665600 —-a-w- c:\windows\inf\drvindex.dat 2008-01-21 03:21:59 174 –sha-w- c:\program files\desktop.ini 2008-01-21 03:21:59 174 –sha-w- c:\program files (x86)\desktop.ini 2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-07-13 20:29:22 8192 –sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 20:45:53.45 ===============
Hi otter,

I see now you are using a 64-bit OS, thus I'll need another set of logs:

🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    netsvcs
    %systemroot%\system32\drivers\*.sys /90
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and paste them into your next post.
OKAY HERE IS THE FIRST REPORT OTL:

OTL logfile created on: 12/06/2010 9:48:04 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Oliver\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 77.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.75 Gb Total Space | 530.57 Gb Free Space | 77.60% Space Free | Partition Type: NTFS
Drive D: | 14.74 Gb Total Space | 2.08 Gb Free Space | 14.14% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLIVERS-PC
Current User Name: Oliver
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Oliver\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
PRC - C:\Windows\SysWOW64\BeepApp.exe (Promise Technology INC)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe ()
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonClient.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonServer.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Oliver\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (Ati External Event Utility) – C:\Windows\SysNative\Ati2evxx.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Norton Internet Security) – C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe (Symantec Corporation)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AMD_RAIDXpert) – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
SRV - (HPBtnSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 08:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (ccHP) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\ccHPx64.sys ()
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\DRIVERS\avgntflt.sys ()
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS ()
DRV:64bit: - (BHDrvx64) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\BHDrvx64.sys ()
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\SRTSP64.SYS ()
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NISx64\1008000.029\SYMEFA64.SYS ()
DRV:64bit: - (SYMTDI) – C:\Windows\SysNative\Drivers\NISx64\1008000.029\SYMTDI.SYS ()
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\NISx64\1008000.029\SRTSPX64.SYS ()
DRV:64bit: - (SymIM) – C:\Windows\SysNative\DRIVERS\SymIMv.sys ()
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:64bit: - (ahcix64s) – C:\Windows\SysNative\drivers\ahcix64s.sys ()
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys ()
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys ()
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\DRIVERS\usbfilter.sys ()
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\SysNative\DRIVERS\AtiPcie.sys ()
DRV:64bit: - (netr7364) – C:\Windows\SysNative\DRIVERS\netr7364.sys ()
DRV:64bit: - (Avc) – C:\Windows\SysNative\DRIVERS\avc.sys ()
DRV:64bit: - (61883) – C:\Windows\SysNative\DRIVERS\61883.sys ()
DRV:64bit: - (MSDV) – C:\Windows\SysNative\DRIVERS\msdv.sys ()
DRV:64bit: - (US122WdmService) – C:\Windows\SysNative\Drivers\US122Wdmx64.sys ()
DRV:64bit: - (US122DL) – C:\Windows\SysNative\Drivers\US122DLx64.sys ()
DRV:64bit: - (US122) – C:\Windows\SysNative\Drivers\US122x64.sys ()
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091125.032\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091125.032\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\IDSviA64.sys (Symantec Corporation)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/05/06 23:19:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/11/28 17:11:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/11/27 22:14:29 | 000,000,000 | —D | M]

[2009/11/04 00:38:03 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Mozilla\Extensions
[2010/06/12 09:09:48 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\iw5tcj7q.default\extensions
[2010/05/27 14:49:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\iw5tcj7q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/09 15:25:45 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/08 00:48:49 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (CatcherBHO Class) - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - C:\Program Files (x86)\Moyea\YouTube FLV Downloader\MoyeaCatcher.dll (Moyea Software Co., Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [Microsoft Default Manager] c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TSMAgent] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Oliver\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Oliver\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\readit\command - "" = notepad readme.doc
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 22:06:38 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll ()
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll ()
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 22:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/06/12 21:45:40 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Oliver\Desktop\OTL.exe
[2010/06/12 20:25:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2010/06/12 11:38:32 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Apple Computer
[2010/06/12 11:38:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2010/06/12 06:02:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/06/12 05:56:42 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Malwarebytes
[2010/06/12 05:56:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/12 05:56:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/06/12 05:56:33 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/12 05:46:15 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\QuickScan
[2010/06/11 04:41:59 | 000,000,000 | —D | C] – C:\temp
[2010/06/11 04:41:54 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Music Editor Free
[2010/06/11 04:41:44 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\Windows\SysWow64\NCTAudioFile2.dll
[2010/06/11 04:41:44 | 001,212,416 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioInformation2.dll
[2010/06/11 04:41:44 | 000,880,640 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioEditor2.dll
[2010/06/11 04:41:44 | 000,835,584 | —- | C] (NCT) – C:\Windows\SysWow64\NCTAudioCDGrabber2.dll
[2010/06/11 04:41:44 | 000,602,112 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioTransform2.dll
[2010/06/11 04:41:44 | 000,479,232 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioVisualization2.dll
[2010/06/11 04:41:44 | 000,458,752 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioRecord2.dll
[2010/06/11 04:41:44 | 000,458,752 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioPlayer2.dll
[2010/06/11 04:41:44 | 000,417,792 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTTextToAudio2.dll
[2010/06/11 04:41:44 | 000,348,160 | —- | C] (NCT Company Ltd.) – C:\Windows\SysWow64\NCTWMAFile2.dll
[2010/06/11 04:41:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Music Editor Free
[2010/06/11 04:17:00 | 000,000,000 | —D | C] – C:\Users\Oliver\Documents\KRISTAL Media Files
[2010/06/11 04:14:19 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\GetRightToGo
[2010/06/08 00:51:25 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\skypePM
[2010/06/08 00:48:56 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Skype
[2010/06/08 00:48:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/06/08 00:48:31 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2010/06/08 00:48:27 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2010/06/03 05:14:36 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\PeerNetworking
[2010/06/03 02:03:04 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Facebook
[2010/06/02 04:36:28 | 000,000,000 | —D | C] – C:\Westwood
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vstplugins
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\ProgramData\Sonoma Wire Works
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\IK Multimedia
[2010/06/02 00:59:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sonoma Wire Works
[2010/06/02 00:47:19 | 000,000,000 | —D | C] – C:\Users\Oliver\Untitled
[2010/06/02 00:22:13 | 000,172,032 | —- | C] (TASCAM) – C:\Windows\SysWow64\U122_A24.DLL
[2010/06/02 00:22:13 | 000,172,032 | —- | C] (TASCAM) – C:\Windows\SysWow64\U122_A16.DLL
[2010/06/02 00:22:12 | 000,000,000 | —D | C] – C:\Program Files\US122
[2010/06/01 23:58:09 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2010/06/01 23:58:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinZip
[2010/06/01 20:09:31 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Local\Google
[2010/05/27 14:51:47 | 000,000,000 | —D | C] – C:\Users\Oliver\Documents\Any Video Converter
[2010/05/27 14:51:28 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\AnvSoft
[2010/05/27 14:51:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\AnvSoft
[2010/05/22 19:49:13 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Dropbox

========== Files - Modified Within 90 Days ==========

[2010/06/12 21:47:21 | 002,097,152 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT
[2010/06/12 21:45:43 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Oliver\Desktop\OTL.exe
[2010/06/12 20:45:14 | 000,293,376 | —- | M] () – C:\Users\Oliver\Desktop\l5wy89pb.exe
[2010/06/12 20:40:48 | 000,525,824 | —- | M] () – C:\Users\Oliver\Desktop\dds.scr
[2010/06/12 20:21:14 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/12 20:21:14 | 000,599,942 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/12 20:21:14 | 000,105,448 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/12 20:15:20 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/12 20:15:20 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/12 20:15:16 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/12 20:15:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/12 19:49:23 | 532,270,378 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/06/12 12:35:19 | 000,336,952 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/12 11:38:20 | 000,001,866 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/12 11:18:26 | 000,045,568 | —- | M] () – C:\Users\Oliver\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/12 11:08:45 | 000,086,696 | —- | M] () – C:\Users\Oliver\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/06/12 10:31:21 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job
[2010/06/12 06:17:26 | 000,002,561 | —- | M] () – C:\Users\Oliver\Desktop\HiJackThis.lnk
[2010/06/11 04:41:48 | 000,001,734 | —- | M] () – C:\Users\Oliver\Desktop\Music Editor Free.lnk
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\SysWow64\w3data.vss
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\SysWow64\msvcsv60.dll
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\msocreg32.dat
[2010/06/09 15:23:07 | 000,524,288 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/06/09 15:23:07 | 000,065,536 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/06/09 15:23:06 | 006,291,456 | -H– | M] () – C:\Users\Oliver\AppData\Local\IconCache.db
[2010/06/08 00:51:25 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2010/06/08 00:48:32 | 000,001,890 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/06/03 05:14:36 | 000,024,226 | —- | M] () – C:\Users\Oliver\AppData\Roaming\UserTile.png
[2010/06/03 01:00:12 | 000,001,490 | —- | M] () – C:\Users\Oliver\.recently-used.xbel
[2010/06/01 23:58:17 | 000,001,898 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2010/06/01 23:58:17 | 000,001,832 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/05/27 14:51:32 | 000,000,971 | —- | M] () – C:\Users\Oliver\Desktop\Any Video Converter.lnk
[2010/05/26 11:53:52 | 000,048,128 | —- | M] () – C:\Windows\SysNative\atmlib.dll
[2010/05/26 09:56:53 | 000,366,080 | —- | M] () – C:\Windows\SysNative\atmfd.dll
[2010/05/22 19:54:16 | 000,000,958 | —- | M] () – C:\Users\Oliver\Desktop\Free FLV Converter.lnk
[2010/05/08 00:40:14 | 000,311,296 | —- | M] (Koyote Soft - http://www.koyotesoft.com) – C:\Windows\SysWow64\TubeFinder.exe
[2010/05/04 14:18:31 | 001,032,704 | —- | M] () – C:\Windows\SysNative\wininet.dll
[2010/05/04 14:16:22 | 000,208,896 | —- | M] () – C:\Windows\SysNative\occache.dll
[2010/05/04 14:15:02 | 001,129,984 | —- | M] () – C:\Windows\SysNative\mstime.dll
[2010/05/04 14:14:31 | 000,758,784 | —- | M] () – C:\Windows\SysNative\mshtmled.dll
[2010/05/04 14:14:22 | 000,580,608 | —- | M] () – C:\Windows\SysNative\msfeeds.dll
[2010/05/04 14:12:55 | 000,032,256 | —- | M] () – C:\Windows\SysNative\jsproxy.dll
[2010/05/04 14:12:27 | 000,375,296 | —- | M] () – C:\Windows\SysNative\iertutil.dll
[2010/05/04 14:12:27 | 000,249,856 | —- | M] () – C:\Windows\SysNative\iepeers.dll
[2010/05/04 14:12:17 | 000,480,256 | —- | M] () – C:\Windows\SysNative\iedkcs32.dll
[2010/05/04 14:12:17 | 000,086,528 | —- | M] () – C:\Windows\SysNative\ieencode.dll
[2010/05/04 14:12:16 | 000,422,400 | —- | M] () – C:\Windows\SysNative\ieapfltr.dll
[2010/05/04 14:12:16 | 000,267,776 | —- | M] () – C:\Windows\SysNative\ieaksie.dll
[2010/05/04 12:53:47 | 000,485,376 | —- | M] () – C:\Windows\SysNative\html.iec
[2010/05/04 12:27:37 | 000,032,768 | —- | M] () – C:\Windows\SysNative\ieUnatt.exe
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] () – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/16 11:35:10 | 001,570,816 | —- | M] () – C:\Windows\SysNative\quartz.dll
[2010/04/05 11:51:12 | 000,084,480 | —- | M] () – C:\Windows\SysNative\asycfilt.dll

========== Files Created - No Company Name ==========

[2010/06/12 20:45:09 | 000,293,376 | —- | C] () – C:\Users\Oliver\Desktop\l5wy89pb.exe
[2010/06/12 20:40:42 | 000,525,824 | —- | C] () – C:\Users\Oliver\Desktop\dds.scr
[2010/06/12 11:38:20 | 000,001,866 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/12 06:02:42 | 000,002,561 | —- | C] () – C:\Users\Oliver\Desktop\HiJackThis.lnk
[2010/06/12 05:56:33 | 000,024,664 | —- | C] () – C:\Windows\SysNative\drivers\mbam.sys
[2010/06/11 04:41:48 | 000,001,734 | —- | C] () – C:\Users\Oliver\Desktop\Music Editor Free.lnk
[2010/06/11 04:41:45 | 000,113,486 | —- | C] () – C:\Windows\SysWow64\NCTWMAProfiles.prx
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\SysWow64\w3data.vss
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\SysWow64\msvcsv60.dll
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\msocreg32.dat
[2010/06/08 18:26:06 | 005,690,368 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2010/06/08 18:26:04 | 007,006,208 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2010/06/08 18:26:03 | 001,426,944 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2010/06/08 18:26:03 | 001,032,704 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2010/06/08 18:26:03 | 000,208,896 | —- | C] () – C:\Windows\SysNative\occache.dll
[2010/06/08 18:26:01 | 000,758,784 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2010/06/08 18:26:01 | 000,580,608 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2010/06/08 18:26:01 | 000,480,256 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2010/06/08 18:26:01 | 000,422,400 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2010/06/08 18:26:01 | 000,375,296 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2010/06/08 18:26:01 | 000,249,856 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2010/06/08 18:26:00 | 001,383,424 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2010/06/08 18:26:00 | 001,129,984 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2010/06/08 18:26:00 | 000,485,376 | —- | C] () – C:\Windows\SysNative\html.iec
[2010/06/08 18:26:00 | 000,267,776 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2010/06/08 18:26:00 | 000,086,528 | —- | C] () – C:\Windows\SysNative\ieencode.dll
[2010/06/08 18:26:00 | 000,032,768 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2010/06/08 18:26:00 | 000,032,256 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2010/06/08 18:24:43 | 000,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2010/06/08 18:24:43 | 000,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2010/06/08 18:16:52 | 000,084,480 | —- | C] () – C:\Windows\SysNative\asycfilt.dll
[2010/06/08 18:12:25 | 002,750,976 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2010/06/08 17:47:52 | 001,570,816 | —- | C] () – C:\Windows\SysNative\quartz.dll
[2010/06/08 00:51:25 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/06/08 00:48:32 | 000,001,890 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2010/06/03 05:14:36 | 000,024,226 | —- | C] () – C:\Users\Oliver\AppData\Roaming\UserTile.png
[2010/06/03 04:19:38 | 000,000,420 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job
[2010/06/03 01:00:12 | 000,001,490 | —- | C] () – C:\Users\Oliver\.recently-used.xbel
[2010/06/02 00:22:13 | 000,555,008 | —- | C] () – C:\Windows\SysNative\US122cp.cpl
[2010/06/02 00:22:13 | 000,223,232 | —- | C] () – C:\Windows\SysNative\U122_A24x64.DLL
[2010/06/02 00:22:13 | 000,223,232 | —- | C] () – C:\Windows\SysNative\U122_A16x64.DLL
[2010/06/02 00:22:13 | 000,200,320 | —- | C] () – C:\Windows\SysNative\drivers\US122x64.sys
[2010/06/02 00:22:13 | 000,062,976 | —- | C] () – C:\Windows\SysNative\drivers\US122Wdmx64.sys
[2010/06/02 00:22:13 | 000,020,224 | —- | C] () – C:\Windows\SysNative\drivers\US122DLx64.sys
[2010/06/01 23:58:17 | 000,001,898 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2010/06/01 23:58:17 | 000,001,832 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/06/01 20:14:27 | 000,442,368 | —- | C] () – C:\Windows\SysNative\winhttp.dll
[2010/05/31 06:12:29 | 000,656,384 | —- | C] () – C:\Windows\SysNative\kerberos.dll
[2010/05/31 06:12:27 | 000,338,944 | —- | C] () – C:\Windows\SysNative\schannel.dll
[2010/05/27 14:51:32 | 000,000,971 | —- | C] () – C:\Users\Oliver\Desktop\Any Video Converter.lnk
[2010/05/27 14:45:10 | 000,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2010/05/18 18:09:18 | 001,420,688 | —- | C] () – C:\Windows\SysNative\drivers\tcpip.sys
[2010/05/18 18:09:17 | 000,224,256 | —- | C] () – C:\Windows\SysNative\iphlpsvc.dll
[2010/05/18 18:09:17 | 000,029,696 | —- | C] () – C:\Windows\SysNative\drivers\tunnel.sys
[2010/05/18 18:09:04 | 000,135,168 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb.sys
[2010/05/18 18:09:03 | 000,273,920 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb10.sys
[2010/05/18 18:09:03 | 000,105,472 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb20.sys
[2010/05/18 18:08:59 | 004,690,832 | —- | C] () – C:\Windows\SysNative\ntoskrnl.exe
[2010/05/18 18:08:57 | 000,974,848 | —- | C] () – C:\Windows\SysNative\inetcomm.dll
[2010/05/18 18:08:52 | 000,603,648 | —- | C] () – C:\Windows\SysNative\vbscript.dll
[2010/05/18 18:08:37 | 000,072,192 | —- | C] () – C:\Windows\SysNative\l3codeca.acm
[2010/05/18 18:06:05 | 000,104,960 | —- | C] () – C:\Windows\SysNative\cabview.dll
[2010/05/18 18:05:09 | 000,218,112 | —- | C] () – C:\Windows\SysNative\wintrust.dll
[2009/07/13 14:49:27 | 000,354,816 | —- | C] () – C:\Windows\SysWow64\pythoncom26.dll
[2009/07/13 14:49:27 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\pywintypes26.dll
[2009/01/14 16:35:57 | 000,516,096 | —- | C] () – C:\Windows\SysWow64\RegisterDialog.dll
[2008/09/19 04:59:22 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\libxml2.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/05/27 14:51:28 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\AnvSoft
[2010/06/12 12:34:44 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Dropbox
[2010/06/03 02:03:06 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Facebook
[2010/05/27 14:41:38 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\FreeFLVConverter
[2010/06/12 04:01:14 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\FrostWire
[2010/06/11 04:14:48 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\GetRightToGo
[2010/06/03 01:00:12 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\gtk-2.0
[2009/11/28 16:46:49 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Moyea
[2010/06/11 05:08:55 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Music Editor Free
[2009/11/04 01:10:29 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\OpenOffice.org
[2010/06/03 05:14:36 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\PeerNetworking
[2009/09/30 11:25:29 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Publish Providers
[2010/06/12 07:10:41 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\QuickScan
[2010/06/12 05:30:07 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Sony
[2009/10/04 08:12:47 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Sony Creative Software
[2009/09/30 00:22:16 | 000,000,552 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/06/09 15:23:43 | 000,029,754 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/12 10:31:21 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job

========== Purity Check ==========



========== Custom Scans ==========


< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys

< %SYSTEMDRIVE%\*.exe >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
< End of report >
AND HERE IS THE SECOND "EXTRAS":



OTL Extras logfile created on: 12/06/2010 9:48:04 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Oliver\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 77.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.75 Gb Total Space | 530.57 Gb Free Space | 77.60% Space Free | Partition Type: NTFS
Drive D: | 14.74 Gb Total Space | 2.08 Gb Free Space | 14.14% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLIVERS-PC
Current User Name: Oliver
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17695BCB-3887-40C4-8BF7-824E4255F3E4}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{1BB9B6ED-DBC2-4B59-AFFB-1BF484445ADC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{2AC33CF4-522D-4ED7-A3EB-829D134C37B6}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{4639B837-A9D5-46A8-89C4-B01D35E9BC5A}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{4D8F1204-8151-4E2F-9E6D-368EE6B520F5}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{555C946B-D143-4ECD-A741-9147E27955EE}" = protocol=17 | dir=in | app=c:\users\oliver\appdata\roaming\dropbox\bin\dropbox.exe |
"{58F1E3A5-1507-4A4C-A201-ED35371CF007}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{5ED16358-4584-4EE0-961D-39014EEBC36C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{85502E81-CFD5-4B82-88F0-8847C2A048BF}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{97377AAF-0039-4725-88D8-A07B8DEDBB25}" = protocol=6 | dir=in | app=c:\users\oliver\appdata\roaming\dropbox\bin\dropbox.exe |
"{9F23742E-DD3D-4C88-BFB0-211C42C492AD}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{A84BE1BF-43C6-48C9-BE12-30A702B1D4F5}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{BB08CE04-89EE-4AE4-8862-4DB80CB3756D}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{C23027A4-D7AB-4CCB-A2ED-02BF86314085}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C780163F-3883-4C4D-8EE7-45E9A4073796}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{E049B1C6-E924-484F-B95B-EE35EA4DC9CC}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{FAC746E6-41CE-430B-BBD2-7CCFA8234C45}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3E597AC0-C805-7F2C-FF91-6D2EA9368D37}" = ccc-utility64
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{704ABF63-B0B1-446B-9D92-C5D06AFCE7B6}" = PlayReady PC runtime
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}" = HP MediaSmart SmartMenu
"{F31BB194-C04E-4C63-90F8-5FC50E05B6B8}" = Vegas Pro 9.0 (64-bit)
"{F7FF5EB8-E7C8-8096-0C33-A5B30CD2EA4C}" = ATI Catalyst Install Manager
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"US122 Driver_is1" = US122 Driver 3.40

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0295F89F-F698-4101-9A7D-49F407EC2D82}" = HP Active Support Library
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{10133E8F-56BA-9679-B1C9-BDD2A737524D}" = Catalyst Control Center Graphics Light
"{1116E59F-AC01-B06D-024C-95E13490DE43}" = CCC Help Korean
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1CC069FA-1A86-402E-9787-3F04E652C67A}" = HP Support Information
"{1F96599E-619C-1EBD-8BE6-F39A5029D344}" = CCC Help Finnish
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25AEC278-A3E1-13C4-5BE3-95920A6AACB3}" = CCC Help Italian
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{2F2D50D7-C7A4-FAEC-4141-51B3D1DD543D}" = CCC Help Russian
"{30B2C06D-4E04-108F-84E4-DBDB3B7D9340}" = ccc-core-static
"{362C65F7-571F-8396-DF58-A6A8D63444D2}" = CCC Help Swedish
"{365B9E8A-5044-F17C-ABF1-815DF62F4B51}" = CCC Help Spanish
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{444DB7A0-BB94-9942-7215-EF8165F3053B}" = Catalyst Control Center Graphics Full New
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{4D80B6CD-B297-FDE8-985B-05540F73ACDF}" = CCC Help German
"{5A9AB192-3A8F-6386-6CE2-80DC9CF9DCBA}" = Catalyst Control Center Graphics Previews Vista
"{5E39F0CC-4255-66B2-F8D1-FB76C5504C47}" = Catalyst Control Center Graphics Full Existing
"{66206F6F-A212-4FAC-837D-3415AA5698DC}" = Catalyst Control Center - Branding
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67431FA8-4B89-42DD-A68E-30D77F6C8D99}_is1" = HP Easy Backup
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DD2B3B5-FE09-E821-A930-C154DA7F70C0}" = CCC Help Polish
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72CEB52D-E5B8-B94F-0DB1-2E26F68F0394}" = Catalyst Control Center Core Implementation
"{784BEA84-FA66-4B19-BB80-7B545F248AC6}" = HP Total Care Setup
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{88104ACD-31BA-B16E-F151-5F295D215E75}" = CCC Help Danish
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B76B8E9-F773-4B75-A08C-120079EB765E}" = RAIDXpert
"{8C3DC8C3-E569-3A75-753F-C04904776AEA}" = Catalyst Control Center Graphics Previews Common
"{8C657345-C0C0-42F0-2107-43F3F223C99E}" = CCC Help Turkish
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A02FA6E-01D8-451A-F373-767C2F906F21}" = CCC Help Czech
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89170-000B-457D-91F1-53691F85B223}" = Python 2.6.1
"{9F8E53F8-2B04-1CBE-80D2-722D8016BFAC}" = CCC Help French
"{A002C1C4-C17B-6269-66FA-CC113FFE4E89}" = CCC Help Japanese
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A3AB35FA-943E-4799-99DC-46EFD59E998F}" = AMD USB Audio Driver Filter
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AC49682F-CE9E-43D3-1556-95F4C19DCAFC}" = CCC Help Portuguese
"{AE469025-08BA-4B2A-915D-CC7765132419}" = Default Manager
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B84739A3-F943-47E4-95D8-96381EF5AC48}" = HP Customer Experience Enhancements
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{BC07934A-69FF-A886-E4F1-480EA39C43C3}" = CCC Help Dutch
"{BE380C5D-BE4C-08C5-8123-79AC369A8029}" = CCC Help Norwegian
"{C03897FD-8FE2-A7A6-FA75-B0840CB949E0}" = CCC Help Greek
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C79BF5BB-5671-41C0-A028-E9A2097D1AAD}" = Microsoft Live Search Toolbar
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CF3C3096-003A-9FC9-4715-9FC8962E35F3}" = Catalyst Control Center InstallProxy
"{D07A3080-A281-C40D-2E1E-699F98B4F3F7}" = CCC Help Chinese Traditional
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DECD11E6-42D5-3416-AD6B-60A9093CE0CE}" = CCC Help Hungarian
"{DEF45232-204B-12BA-BCAC-105DCF05A399}" = CCC Help English
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EA36F8FF-81C8-2832-F023-3CEB2283E3EB}" = CCC Help Thai
"{EA426461-31AA-4AB3-B15D-EDD748F08394}_is1" = Moyea YouTube FLV Downloader version: 3.1.2.0
"{EADFF891-1161-6EC4-6F0A-7FF1E30F4C57}" = CCC Help Chinese Standard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2E05527-16B4-5855-E3FD-D27A7EE477B4}" = Catalyst Control Center Localization All
"{F827B95C-1BF5-43B4-9E26-CDC596ECE3AE}" = HP Demo
"{FB8E2BF3-74B7-75D5-941D-FBF10395D002}" = Skins
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.5
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Free FLV Converter_is1" = Free FLV Converter V 6.7.8
"FrostWire" = FrostWire 4.18.4
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{8B76B8E9-F773-4B75-A08C-120079EB765E}" = RAIDXpert
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"Music Editor Free" = Music Editor Free
"NIS" = Norton Internet Security
"pywin32-py2.6" = Python 2.6 pywin32-212
"VLC media player" = VLC media player 1.0.3
"WinGimp-2.0_is1" = GIMP 2.6.8

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
otter,

🖼Click to load external image (Posted Image) You have more than one antivirus (AV) program running. Your logs show both Avira and Norton Internet Security running. Running more than one AV program does not offer any more protection and often causes conflicts and slow downs with your computer. Please uninstall either Avira or Norton Internet Security via Control Panel > Add/Remove Programs. Run the removal tool (links below) for whichever app you uninstall also:

Avira Removal Tool
Norton Removal Tool

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (FrostWire) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Malware authors use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
    O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\readit\command - "" = notepad readme.doc
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
  • If you are using a router, disconnect your computer from the router before continuing
  • Click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Do a hard reset (back to factory defaults) on your router. A simple power cycle will not suffice - you must do a hard reset. Usually there is a small button to push with a pin or paperclip on the back of the router, but check your router's documentation to be sure. When you set it back up change the default admin login and password. Once you have reset the router please reconnect your computer.

🖼Click to load external image (Posted Image) Double click on OTL to open it
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of that file.
Please include the following in your next post:
  • OTL Fix log
  • New OTL Scan log
OTL FIX LOG

All processes killed
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
Error: Unable to interpret in the current context!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Oliver\Desktop\cmd.bat deleted successfully.
C:\Users\Oliver\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Oliver
->Flash cache emptied: 51046 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Oliver
->Temp folder emptied: 40100049 bytes
->Temporary Internet Files folder emptied: 63786507 bytes
->Java cache emptied: 36499834 bytes
->FireFox cache emptied: 72305777 bytes
->Apple Safari cache emptied: 352013823 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7049829 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 545.00 mb


OTL by OldTimer - Version 3.2.6.0 log created on 06132010_163007

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\hsperfdata_OLIVERS-PC$\1760 not found!
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YAPET23Q\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QXGYQC79\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E61NWTHV\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9XJ7039X\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.

Registry entries deleted on Reboot…

Continuing down is the OTL SCAN LOG
OTL SCAN LOG

OTL logfile created on: 13/06/2010 4:42:15 PM - Run 2
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Oliver\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 78.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.75 Gb Total Space | 533.32 Gb Free Space | 78.00% Space Free | Partition Type: NTFS
Drive D: | 14.74 Gb Total Space | 2.08 Gb Free Space | 14.14% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLIVERS-PC
Current User Name: Oliver
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Oliver\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Safari\Safari.exe (Apple Inc.)
PRC - C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
PRC - C:\Windows\SysWOW64\BeepApp.exe (Promise Technology INC)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe ()
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonClient.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonServer.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Oliver\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (Ati External Event Utility) – C:\Windows\SysNative\Ati2evxx.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AMD_RAIDXpert) – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
SRV - (HPBtnSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 08:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (avgntflt) – C:\Windows\SysNative\DRIVERS\avgntflt.sys ()
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:64bit: - (ahcix64s) – C:\Windows\SysNative\drivers\ahcix64s.sys ()
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys ()
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys ()
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\DRIVERS\usbfilter.sys ()
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\SysNative\DRIVERS\AtiPcie.sys ()
DRV:64bit: - (netr7364) – C:\Windows\SysNative\DRIVERS\netr7364.sys ()
DRV:64bit: - (Avc) – C:\Windows\SysNative\DRIVERS\avc.sys ()
DRV:64bit: - (61883) – C:\Windows\SysNative\DRIVERS\61883.sys ()
DRV:64bit: - (MSDV) – C:\Windows\SysNative\DRIVERS\msdv.sys ()
DRV:64bit: - (US122WdmService) – C:\Windows\SysNative\Drivers\US122Wdmx64.sys ()
DRV:64bit: - (US122DL) – C:\Windows\SysNative\Drivers\US122DLx64.sys ()
DRV:64bit: - (US122) – C:\Windows\SysNative\Drivers\US122x64.sys ()
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/11/28 17:11:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/11/27 22:14:29 | 000,000,000 | —D | M]

[2009/11/04 00:38:03 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Mozilla\Extensions
[2010/06/12 09:09:48 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\iw5tcj7q.default\extensions
[2010/05/27 14:49:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\iw5tcj7q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/13 16:18:22 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/08 00:48:49 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (CatcherBHO Class) - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - C:\Program Files (x86)\Moyea\YouTube FLV Downloader\MoyeaCatcher.dll (Moyea Software Co., Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [Microsoft Default Manager] c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TSMAgent] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Oliver\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Oliver\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\readit\command - "" = notepad readme.doc
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/13 16:30:07 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/12 21:45:40 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Oliver\Desktop\OTL.exe
[2010/06/12 20:25:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2010/06/12 11:38:32 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Apple Computer
[2010/06/12 11:38:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2010/06/12 06:02:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/06/12 05:56:42 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Malwarebytes
[2010/06/12 05:56:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/12 05:56:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/06/12 05:56:33 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/12 05:46:15 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\QuickScan
[2010/06/11 04:41:59 | 000,000,000 | —D | C] – C:\temp
[2010/06/11 04:41:54 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Music Editor Free
[2010/06/11 04:41:44 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\Windows\SysWow64\NCTAudioFile2.dll
[2010/06/11 04:41:44 | 001,212,416 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioInformation2.dll
[2010/06/11 04:41:44 | 000,880,640 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioEditor2.dll
[2010/06/11 04:41:44 | 000,835,584 | —- | C] (NCT) – C:\Windows\SysWow64\NCTAudioCDGrabber2.dll
[2010/06/11 04:41:44 | 000,602,112 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioTransform2.dll
[2010/06/11 04:41:44 | 000,479,232 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioVisualization2.dll
[2010/06/11 04:41:44 | 000,458,752 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioRecord2.dll
[2010/06/11 04:41:44 | 000,458,752 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioPlayer2.dll
[2010/06/11 04:41:44 | 000,417,792 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTTextToAudio2.dll
[2010/06/11 04:41:44 | 000,348,160 | —- | C] (NCT Company Ltd.) – C:\Windows\SysWow64\NCTWMAFile2.dll
[2010/06/11 04:41:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Music Editor Free
[2010/06/11 04:17:00 | 000,000,000 | —D | C] – C:\Users\Oliver\Documents\KRISTAL Media Files
[2010/06/11 04:14:19 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\GetRightToGo
[2010/06/08 00:51:25 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\skypePM
[2010/06/08 00:48:56 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Skype
[2010/06/08 00:48:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/06/08 00:48:31 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2010/06/08 00:48:27 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2010/06/03 05:14:36 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\PeerNetworking
[2010/06/03 02:03:04 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Facebook
[2010/06/02 04:36:28 | 000,000,000 | —D | C] – C:\Westwood
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vstplugins
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\ProgramData\Sonoma Wire Works
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\IK Multimedia
[2010/06/02 00:59:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sonoma Wire Works
[2010/06/02 00:47:19 | 000,000,000 | —D | C] – C:\Users\Oliver\Untitled
[2010/06/02 00:22:13 | 000,172,032 | —- | C] (TASCAM) – C:\Windows\SysWow64\U122_A24.DLL
[2010/06/02 00:22:13 | 000,172,032 | —- | C] (TASCAM) – C:\Windows\SysWow64\U122_A16.DLL
[2010/06/02 00:22:12 | 000,000,000 | —D | C] – C:\Program Files\US122
[2010/06/01 23:58:09 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2010/06/01 23:58:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinZip
[2010/06/01 20:09:31 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Local\Google
[2010/05/27 14:51:47 | 000,000,000 | —D | C] – C:\Users\Oliver\Documents\Any Video Converter
[2010/05/27 14:51:28 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\AnvSoft
[2010/05/27 14:51:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\AnvSoft
[2010/05/22 19:49:13 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Dropbox

========== Files - Modified Within 90 Days ==========

[2010/06/13 16:42:04 | 002,097,152 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT
[2010/06/13 16:37:18 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/13 16:37:18 | 000,599,942 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/13 16:37:18 | 000,105,448 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/13 16:31:56 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 16:31:55 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 16:31:53 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/13 16:31:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/13 16:30:43 | 000,524,288 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/06/13 16:30:43 | 000,065,536 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/06/13 16:19:01 | 002,525,469 | -H– | M] () – C:\Users\Oliver\AppData\Local\IconCache.db
[2010/06/13 16:17:15 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job
[2010/06/13 16:00:28 | 553,110,826 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/06/13 07:36:10 | 000,046,592 | —- | M] () – C:\Users\Oliver\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/12 21:45:43 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Oliver\Desktop\OTL.exe
[2010/06/12 20:45:14 | 000,293,376 | —- | M] () – C:\Users\Oliver\Desktop\l5wy89pb.exe
[2010/06/12 20:40:48 | 000,525,824 | —- | M] () – C:\Users\Oliver\Desktop\dds.scr
[2010/06/12 12:35:19 | 000,336,952 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/12 11:38:20 | 000,001,866 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/12 11:08:45 | 000,086,696 | —- | M] () – C:\Users\Oliver\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/06/12 06:17:26 | 000,002,561 | —- | M] () – C:\Users\Oliver\Desktop\HiJackThis.lnk
[2010/06/11 04:41:48 | 000,001,734 | —- | M] () – C:\Users\Oliver\Desktop\Music Editor Free.lnk
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\SysWow64\w3data.vss
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\SysWow64\msvcsv60.dll
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\msocreg32.dat
[2010/06/08 00:51:25 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2010/06/08 00:48:32 | 000,001,890 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/06/03 05:14:36 | 000,024,226 | —- | M] () – C:\Users\Oliver\AppData\Roaming\UserTile.png
[2010/06/03 01:00:12 | 000,001,490 | —- | M] () – C:\Users\Oliver\.recently-used.xbel
[2010/06/01 23:58:17 | 000,001,898 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2010/06/01 23:58:17 | 000,001,832 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/05/27 14:51:32 | 000,000,971 | —- | M] () – C:\Users\Oliver\Desktop\Any Video Converter.lnk
[2010/05/26 11:53:52 | 000,048,128 | —- | M] () – C:\Windows\SysNative\atmlib.dll
[2010/05/26 09:56:53 | 000,366,080 | —- | M] () – C:\Windows\SysNative\atmfd.dll
[2010/05/22 19:54:16 | 000,000,958 | —- | M] () – C:\Users\Oliver\Desktop\Free FLV Converter.lnk
[2010/05/08 00:40:14 | 000,311,296 | —- | M] (Koyote Soft - http://www.koyotesoft.com) – C:\Windows\SysWow64\TubeFinder.exe
[2010/05/04 14:18:31 | 001,032,704 | —- | M] () – C:\Windows\SysNative\wininet.dll
[2010/05/04 14:16:22 | 000,208,896 | —- | M] () – C:\Windows\SysNative\occache.dll
[2010/05/04 14:15:02 | 001,129,984 | —- | M] () – C:\Windows\SysNative\mstime.dll
[2010/05/04 14:14:31 | 000,758,784 | —- | M] () – C:\Windows\SysNative\mshtmled.dll
[2010/05/04 14:14:22 | 000,580,608 | —- | M] () – C:\Windows\SysNative\msfeeds.dll
[2010/05/04 14:12:55 | 000,032,256 | —- | M] () – C:\Windows\SysNative\jsproxy.dll
[2010/05/04 14:12:27 | 000,375,296 | —- | M] () – C:\Windows\SysNative\iertutil.dll
[2010/05/04 14:12:27 | 000,249,856 | —- | M] () – C:\Windows\SysNative\iepeers.dll
[2010/05/04 14:12:17 | 000,480,256 | —- | M] () – C:\Windows\SysNative\iedkcs32.dll
[2010/05/04 14:12:17 | 000,086,528 | —- | M] () – C:\Windows\SysNative\ieencode.dll
[2010/05/04 14:12:16 | 000,422,400 | —- | M] () – C:\Windows\SysNative\ieapfltr.dll
[2010/05/04 14:12:16 | 000,267,776 | —- | M] () – C:\Windows\SysNative\ieaksie.dll
[2010/05/04 12:53:47 | 000,485,376 | —- | M] () – C:\Windows\SysNative\html.iec
[2010/05/04 12:27:37 | 000,032,768 | —- | M] () – C:\Windows\SysNative\ieUnatt.exe
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] () – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/16 11:35:10 | 001,570,816 | —- | M] () – C:\Windows\SysNative\quartz.dll
[2010/04/05 11:51:12 | 000,084,480 | —- | M] () – C:\Windows\SysNative\asycfilt.dll

========== Files Created - No Company Name ==========

[2010/06/12 20:45:09 | 000,293,376 | —- | C] () – C:\Users\Oliver\Desktop\l5wy89pb.exe
[2010/06/12 20:40:42 | 000,525,824 | —- | C] () – C:\Users\Oliver\Desktop\dds.scr
[2010/06/12 11:38:20 | 000,001,866 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/12 06:02:42 | 000,002,561 | —- | C] () – C:\Users\Oliver\Desktop\HiJackThis.lnk
[2010/06/12 05:56:33 | 000,024,664 | —- | C] () – C:\Windows\SysNative\drivers\mbam.sys
[2010/06/11 04:41:48 | 000,001,734 | —- | C] () – C:\Users\Oliver\Desktop\Music Editor Free.lnk
[2010/06/11 04:41:45 | 000,113,486 | —- | C] () – C:\Windows\SysWow64\NCTWMAProfiles.prx
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\SysWow64\w3data.vss
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\SysWow64\msvcsv60.dll
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\msocreg32.dat
[2010/06/08 18:26:06 | 005,690,368 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2010/06/08 18:26:04 | 007,006,208 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2010/06/08 18:26:03 | 001,426,944 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2010/06/08 18:26:03 | 001,032,704 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2010/06/08 18:26:03 | 000,208,896 | —- | C] () – C:\Windows\SysNative\occache.dll
[2010/06/08 18:26:01 | 000,758,784 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2010/06/08 18:26:01 | 000,580,608 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2010/06/08 18:26:01 | 000,480,256 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2010/06/08 18:26:01 | 000,422,400 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2010/06/08 18:26:01 | 000,375,296 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2010/06/08 18:26:01 | 000,249,856 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2010/06/08 18:26:00 | 001,383,424 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2010/06/08 18:26:00 | 001,129,984 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2010/06/08 18:26:00 | 000,485,376 | —- | C] () – C:\Windows\SysNative\html.iec
[2010/06/08 18:26:00 | 000,267,776 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2010/06/08 18:26:00 | 000,086,528 | —- | C] () – C:\Windows\SysNative\ieencode.dll
[2010/06/08 18:26:00 | 000,032,768 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2010/06/08 18:26:00 | 000,032,256 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2010/06/08 18:24:43 | 000,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2010/06/08 18:24:43 | 000,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2010/06/08 18:16:52 | 000,084,480 | —- | C] () – C:\Windows\SysNative\asycfilt.dll
[2010/06/08 18:12:25 | 002,750,976 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2010/06/08 17:47:52 | 001,570,816 | —- | C] () – C:\Windows\SysNative\quartz.dll
[2010/06/08 00:51:25 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/06/08 00:48:32 | 000,001,890 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2010/06/03 05:14:36 | 000,024,226 | —- | C] () – C:\Users\Oliver\AppData\Roaming\UserTile.png
[2010/06/03 04:19:38 | 000,000,420 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job
[2010/06/03 01:00:12 | 000,001,490 | —- | C] () – C:\Users\Oliver\.recently-used.xbel
[2010/06/02 00:22:13 | 000,555,008 | —- | C] () – C:\Windows\SysNative\US122cp.cpl
[2010/06/02 00:22:13 | 000,223,232 | —- | C] () – C:\Windows\SysNative\U122_A24x64.DLL
[2010/06/02 00:22:13 | 000,223,232 | —- | C] () – C:\Windows\SysNative\U122_A16x64.DLL
[2010/06/02 00:22:13 | 000,200,320 | —- | C] () – C:\Windows\SysNative\drivers\US122x64.sys
[2010/06/02 00:22:13 | 000,062,976 | —- | C] () – C:\Windows\SysNative\drivers\US122Wdmx64.sys
[2010/06/02 00:22:13 | 000,020,224 | —- | C] () – C:\Windows\SysNative\drivers\US122DLx64.sys
[2010/06/01 23:58:17 | 000,001,898 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2010/06/01 23:58:17 | 000,001,832 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/06/01 20:14:27 | 000,442,368 | —- | C] () – C:\Windows\SysNative\winhttp.dll
[2010/05/31 06:12:29 | 000,656,384 | —- | C] () – C:\Windows\SysNative\kerberos.dll
[2010/05/31 06:12:27 | 000,338,944 | —- | C] () – C:\Windows\SysNative\schannel.dll
[2010/05/27 14:51:32 | 000,000,971 | —- | C] () – C:\Users\Oliver\Desktop\Any Video Converter.lnk
[2010/05/27 14:45:10 | 000,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2010/05/18 18:09:18 | 001,420,688 | —- | C] () – C:\Windows\SysNative\drivers\tcpip.sys
[2010/05/18 18:09:17 | 000,224,256 | —- | C] () – C:\Windows\SysNative\iphlpsvc.dll
[2010/05/18 18:09:17 | 000,029,696 | —- | C] () – C:\Windows\SysNative\drivers\tunnel.sys
[2010/05/18 18:09:04 | 000,135,168 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb.sys
[2010/05/18 18:09:03 | 000,273,920 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb10.sys
[2010/05/18 18:09:03 | 000,105,472 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb20.sys
[2010/05/18 18:08:59 | 004,690,832 | —- | C] () – C:\Windows\SysNative\ntoskrnl.exe
[2010/05/18 18:08:57 | 000,974,848 | —- | C] () – C:\Windows\SysNative\inetcomm.dll
[2010/05/18 18:08:52 | 000,603,648 | —- | C] () – C:\Windows\SysNative\vbscript.dll
[2010/05/18 18:08:37 | 000,072,192 | —- | C] () – C:\Windows\SysNative\l3codeca.acm
[2010/05/18 18:06:05 | 000,104,960 | —- | C] () – C:\Windows\SysNative\cabview.dll
[2010/05/18 18:05:09 | 000,218,112 | —- | C] () – C:\Windows\SysNative\wintrust.dll
[2009/07/13 14:49:27 | 000,354,816 | —- | C] () – C:\Windows\SysWow64\pythoncom26.dll
[2009/07/13 14:49:27 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\pywintypes26.dll
[2009/01/14 16:35:57 | 000,516,096 | —- | C] () – C:\Windows\SysWow64\RegisterDialog.dll
[2008/09/19 04:59:22 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\libxml2.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/05/27 14:51:28 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\AnvSoft
[2010/06/12 12:34:44 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Dropbox
[2010/06/03 02:03:06 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Facebook
[2010/05/27 14:41:38 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\FreeFLVConverter
[2010/06/13 03:20:37 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\FrostWire
[2010/06/11 04:14:48 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\GetRightToGo
[2010/06/03 01:00:12 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\gtk-2.0
[2009/11/28 16:46:49 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Moyea
[2010/06/11 05:08:55 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Music Editor Free
[2009/11/04 01:10:29 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\OpenOffice.org
[2010/06/03 05:14:36 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\PeerNetworking
[2009/09/30 11:25:29 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Publish Providers
[2010/06/12 07:10:41 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\QuickScan
[2010/06/12 05:30:07 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Sony
[2009/10/04 08:12:47 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Sony Creative Software
[2009/09/30 00:22:16 | 000,000,552 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/06/13 16:30:44 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/13 16:17:15 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job

========== Purity Check ==========


< End of report >
otter,

You accidentally omitted the colon before "OTL" in the first line of my script, so I'm afraid the critical part of the script failed. Here are the steps I need you to repeat - be sure to get that first colon in there. The first line has to look like this:

:OTL


🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
    O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\Shell\readit\command - "" = notepad readme.doc
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
  • If you are using a router, disconnect your computer from the router before continuing
  • Click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Do a hard reset (back to factory defaults) on your router. A simple power cycle will not suffice - you must do a hard reset. Usually there is a small button to push with a pin or paperclip on the back of the router, but check your router's documentation to be sure. When you set it back up change the default admin login and password. Once you have reset the router please reconnect your computer.

🖼Click to load external image (Posted Image) Double click on OTL to open it
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of that file.
Please include the following in your next post:
  • OTL Fix log
  • New OTL Scan log
FIX LOG


All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\ not found.
File E:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e8dc882f-7de8-11de-85a2-806e6f6e6963}\ not found.
File notepad readme.doc not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Oliver\Desktop\cmd.bat deleted successfully.
C:\Users\Oliver\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Oliver
->Flash cache emptied: 930 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Oliver
->Temp folder emptied: 32233 bytes
->Temporary Internet Files folder emptied: 644479 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Apple Safari cache emptied: 59561845 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 95972 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 874125783 bytes

Total Files Cleaned = 891.00 mb


OTL by OldTimer - Version 3.2.6.0 log created on 06132010_190555

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\hsperfdata_OLIVERS-PC$\1896 not found!
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YAPET23Q\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QXGYQC79\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E61NWTHV\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9XJ7039X\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.

Registry entries deleted on Reboot…
OTL LOG


OTL logfile created on: 13/06/2010 7:11:01 PM - Run 3
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Oliver\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 80.00% Memory free
16.00 Gb Paging File | 14.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.75 Gb Total Space | 535.14 Gb Free Space | 78.26% Space Free | Partition Type: NTFS
Drive D: | 14.74 Gb Total Space | 2.08 Gb Free Space | 14.14% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OLIVERS-PC
Current User Name: Oliver
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Oliver\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Safari\Safari.exe (Apple Inc.)
PRC - C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
PRC - C:\Windows\SysWOW64\BeepApp.exe (Promise Technology INC)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe ()
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonClient.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonServer.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Oliver\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (Ati External Event Utility) – C:\Windows\SysNative\Ati2evxx.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AMD_RAIDXpert) – C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
SRV - (HPBtnSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 08:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (avgntflt) – C:\Windows\SysNative\DRIVERS\avgntflt.sys ()
DRV:64bit: - (PCDSRVC{F36B3A4C-F95654BD-06000000}_0) – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:64bit: - (ahcix64s) – C:\Windows\SysNative\drivers\ahcix64s.sys ()
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys ()
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys ()
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\DRIVERS\usbfilter.sys ()
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\SysNative\DRIVERS\AtiPcie.sys ()
DRV:64bit: - (netr7364) – C:\Windows\SysNative\DRIVERS\netr7364.sys ()
DRV:64bit: - (Avc) – C:\Windows\SysNative\DRIVERS\avc.sys ()
DRV:64bit: - (61883) – C:\Windows\SysNative\DRIVERS\61883.sys ()
DRV:64bit: - (MSDV) – C:\Windows\SysNative\DRIVERS\msdv.sys ()
DRV:64bit: - (US122WdmService) – C:\Windows\SysNative\Drivers\US122Wdmx64.sys ()
DRV:64bit: - (US122DL) – C:\Windows\SysNative\Drivers\US122DLx64.sys ()
DRV:64bit: - (US122) – C:\Windows\SysNative\Drivers\US122x64.sys ()
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/11/28 17:11:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/11/27 22:14:29 | 000,000,000 | —D | M]

[2009/11/04 00:38:03 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Mozilla\Extensions
[2010/06/12 09:09:48 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\iw5tcj7q.default\extensions
[2010/05/27 14:49:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\iw5tcj7q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/13 16:18:22 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/08 00:48:49 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (CatcherBHO Class) - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - C:\Program Files (x86)\Moyea\YouTube FLV Downloader\MoyeaCatcher.dll (Moyea Software Co., Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0552.0\msneshellx.dll (Microsoft Corp.)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [Microsoft Default Manager] c:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TSMAgent] c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] c:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Oliver\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Oliver\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/13 16:30:07 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/12 21:45:40 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Oliver\Desktop\OTL.exe
[2010/06/12 20:25:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2010/06/12 11:38:32 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Apple Computer
[2010/06/12 11:38:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2010/06/12 06:02:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/06/12 05:56:42 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Malwarebytes
[2010/06/12 05:56:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/12 05:56:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/06/12 05:56:33 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/12 05:46:15 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\QuickScan
[2010/06/11 04:41:59 | 000,000,000 | —D | C] – C:\temp
[2010/06/11 04:41:54 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Music Editor Free
[2010/06/11 04:41:44 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\Windows\SysWow64\NCTAudioFile2.dll
[2010/06/11 04:41:44 | 001,212,416 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioInformation2.dll
[2010/06/11 04:41:44 | 000,880,640 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioEditor2.dll
[2010/06/11 04:41:44 | 000,835,584 | —- | C] (NCT) – C:\Windows\SysWow64\NCTAudioCDGrabber2.dll
[2010/06/11 04:41:44 | 000,602,112 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioTransform2.dll
[2010/06/11 04:41:44 | 000,479,232 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioVisualization2.dll
[2010/06/11 04:41:44 | 000,458,752 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioRecord2.dll
[2010/06/11 04:41:44 | 000,458,752 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTAudioPlayer2.dll
[2010/06/11 04:41:44 | 000,417,792 | —- | C] (Online Media Technologies Ltd.) – C:\Windows\SysWow64\NCTTextToAudio2.dll
[2010/06/11 04:41:44 | 000,348,160 | —- | C] (NCT Company Ltd.) – C:\Windows\SysWow64\NCTWMAFile2.dll
[2010/06/11 04:41:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Music Editor Free
[2010/06/11 04:17:00 | 000,000,000 | —D | C] – C:\Users\Oliver\Documents\KRISTAL Media Files
[2010/06/11 04:14:19 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\GetRightToGo
[2010/06/08 00:51:25 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\skypePM
[2010/06/08 00:48:56 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Skype
[2010/06/08 00:48:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2010/06/08 00:48:31 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2010/06/08 00:48:27 | 000,000,000 | —D | C] – C:\ProgramData\Skype
[2010/06/03 05:14:36 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\PeerNetworking
[2010/06/03 02:03:04 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Facebook
[2010/06/02 04:36:28 | 000,000,000 | —D | C] – C:\Westwood
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Vstplugins
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\ProgramData\Sonoma Wire Works
[2010/06/02 00:59:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\IK Multimedia
[2010/06/02 00:59:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sonoma Wire Works
[2010/06/02 00:47:19 | 000,000,000 | —D | C] – C:\Users\Oliver\Untitled
[2010/06/02 00:22:13 | 000,172,032 | —- | C] (TASCAM) – C:\Windows\SysWow64\U122_A24.DLL
[2010/06/02 00:22:13 | 000,172,032 | —- | C] (TASCAM) – C:\Windows\SysWow64\U122_A16.DLL
[2010/06/02 00:22:12 | 000,000,000 | —D | C] – C:\Program Files\US122
[2010/06/01 23:58:09 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2010/06/01 23:58:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinZip
[2010/06/01 20:09:31 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Local\Google
[2010/05/27 14:51:47 | 000,000,000 | —D | C] – C:\Users\Oliver\Documents\Any Video Converter
[2010/05/27 14:51:28 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\AnvSoft
[2010/05/27 14:51:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\AnvSoft
[2010/05/22 19:49:13 | 000,000,000 | —D | C] – C:\Users\Oliver\AppData\Roaming\Dropbox

========== Files - Modified Within 90 Days ==========

[2010/06/13 19:11:04 | 002,097,152 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT
[2010/06/13 19:07:28 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 19:07:27 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 19:07:23 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/13 19:07:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/13 19:06:16 | 000,524,288 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/06/13 19:06:16 | 000,065,536 | -HS- | M] () – C:\Users\Oliver\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/06/13 19:06:14 | 002,528,451 | -H– | M] () – C:\Users\Oliver\AppData\Local\IconCache.db
[2010/06/13 16:37:18 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/13 16:37:18 | 000,599,942 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/13 16:37:18 | 000,105,448 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/13 16:17:15 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job
[2010/06/13 16:00:28 | 553,110,826 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/06/13 07:36:10 | 000,046,592 | —- | M] () – C:\Users\Oliver\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/12 21:45:43 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Oliver\Desktop\OTL.exe
[2010/06/12 20:45:14 | 000,293,376 | —- | M] () – C:\Users\Oliver\Desktop\l5wy89pb.exe
[2010/06/12 20:40:48 | 000,525,824 | —- | M] () – C:\Users\Oliver\Desktop\dds.scr
[2010/06/12 12:35:19 | 000,336,952 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/12 11:38:20 | 000,001,866 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/12 11:08:45 | 000,086,696 | —- | M] () – C:\Users\Oliver\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/06/12 06:17:26 | 000,002,561 | —- | M] () – C:\Users\Oliver\Desktop\HiJackThis.lnk
[2010/06/11 04:41:48 | 000,001,734 | —- | M] () – C:\Users\Oliver\Desktop\Music Editor Free.lnk
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\SysWow64\w3data.vss
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\SysWow64\msvcsv60.dll
[2010/06/11 04:14:43 | 000,000,016 | —- | M] () – C:\Windows\msocreg32.dat
[2010/06/08 00:51:25 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2010/06/08 00:48:32 | 000,001,890 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/06/03 05:14:36 | 000,024,226 | —- | M] () – C:\Users\Oliver\AppData\Roaming\UserTile.png
[2010/06/03 01:00:12 | 000,001,490 | —- | M] () – C:\Users\Oliver\.recently-used.xbel
[2010/06/01 23:58:17 | 000,001,898 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2010/06/01 23:58:17 | 000,001,832 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/05/27 14:51:32 | 000,000,971 | —- | M] () – C:\Users\Oliver\Desktop\Any Video Converter.lnk
[2010/05/26 11:53:52 | 000,048,128 | —- | M] () – C:\Windows\SysNative\atmlib.dll
[2010/05/26 09:56:53 | 000,366,080 | —- | M] () – C:\Windows\SysNative\atmfd.dll
[2010/05/22 19:54:16 | 000,000,958 | —- | M] () – C:\Users\Oliver\Desktop\Free FLV Converter.lnk
[2010/05/08 00:40:14 | 000,311,296 | —- | M] (Koyote Soft - http://www.koyotesoft.com) – C:\Windows\SysWow64\TubeFinder.exe
[2010/05/04 14:18:31 | 001,032,704 | —- | M] () – C:\Windows\SysNative\wininet.dll
[2010/05/04 14:16:22 | 000,208,896 | —- | M] () – C:\Windows\SysNative\occache.dll
[2010/05/04 14:15:02 | 001,129,984 | —- | M] () – C:\Windows\SysNative\mstime.dll
[2010/05/04 14:14:31 | 000,758,784 | —- | M] () – C:\Windows\SysNative\mshtmled.dll
[2010/05/04 14:14:22 | 000,580,608 | —- | M] () – C:\Windows\SysNative\msfeeds.dll
[2010/05/04 14:12:55 | 000,032,256 | —- | M] () – C:\Windows\SysNative\jsproxy.dll
[2010/05/04 14:12:27 | 000,375,296 | —- | M] () – C:\Windows\SysNative\iertutil.dll
[2010/05/04 14:12:27 | 000,249,856 | —- | M] () – C:\Windows\SysNative\iepeers.dll
[2010/05/04 14:12:17 | 000,480,256 | —- | M] () – C:\Windows\SysNative\iedkcs32.dll
[2010/05/04 14:12:17 | 000,086,528 | —- | M] () – C:\Windows\SysNative\ieencode.dll
[2010/05/04 14:12:16 | 000,422,400 | —- | M] () – C:\Windows\SysNative\ieapfltr.dll
[2010/05/04 14:12:16 | 000,267,776 | —- | M] () – C:\Windows\SysNative\ieaksie.dll
[2010/05/04 12:53:47 | 000,485,376 | —- | M] () – C:\Windows\SysNative\html.iec
[2010/05/04 12:27:37 | 000,032,768 | —- | M] () – C:\Windows\SysNative\ieUnatt.exe
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] () – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/16 11:35:10 | 001,570,816 | —- | M] () – C:\Windows\SysNative\quartz.dll
[2010/04/05 11:51:12 | 000,084,480 | —- | M] () – C:\Windows\SysNative\asycfilt.dll

========== Files Created - No Company Name ==========

[2010/06/12 20:45:09 | 000,293,376 | —- | C] () – C:\Users\Oliver\Desktop\l5wy89pb.exe
[2010/06/12 20:40:42 | 000,525,824 | —- | C] () – C:\Users\Oliver\Desktop\dds.scr
[2010/06/12 11:38:20 | 000,001,866 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2010/06/12 06:02:42 | 000,002,561 | —- | C] () – C:\Users\Oliver\Desktop\HiJackThis.lnk
[2010/06/12 05:56:33 | 000,024,664 | —- | C] () – C:\Windows\SysNative\drivers\mbam.sys
[2010/06/11 04:41:48 | 000,001,734 | —- | C] () – C:\Users\Oliver\Desktop\Music Editor Free.lnk
[2010/06/11 04:41:45 | 000,113,486 | —- | C] () – C:\Windows\SysWow64\NCTWMAProfiles.prx
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\SysWow64\w3data.vss
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\SysWow64\msvcsv60.dll
[2010/06/11 04:14:41 | 000,000,016 | —- | C] () – C:\Windows\msocreg32.dat
[2010/06/08 18:26:06 | 005,690,368 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2010/06/08 18:26:04 | 007,006,208 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2010/06/08 18:26:03 | 001,426,944 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2010/06/08 18:26:03 | 001,032,704 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2010/06/08 18:26:03 | 000,208,896 | —- | C] () – C:\Windows\SysNative\occache.dll
[2010/06/08 18:26:01 | 000,758,784 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2010/06/08 18:26:01 | 000,580,608 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2010/06/08 18:26:01 | 000,480,256 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2010/06/08 18:26:01 | 000,422,400 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2010/06/08 18:26:01 | 000,375,296 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2010/06/08 18:26:01 | 000,249,856 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2010/06/08 18:26:00 | 001,383,424 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2010/06/08 18:26:00 | 001,129,984 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2010/06/08 18:26:00 | 000,485,376 | —- | C] () – C:\Windows\SysNative\html.iec
[2010/06/08 18:26:00 | 000,267,776 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2010/06/08 18:26:00 | 000,086,528 | —- | C] () – C:\Windows\SysNative\ieencode.dll
[2010/06/08 18:26:00 | 000,032,768 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2010/06/08 18:26:00 | 000,032,256 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2010/06/08 18:24:43 | 000,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2010/06/08 18:24:43 | 000,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2010/06/08 18:16:52 | 000,084,480 | —- | C] () – C:\Windows\SysNative\asycfilt.dll
[2010/06/08 18:12:25 | 002,750,976 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2010/06/08 17:47:52 | 001,570,816 | —- | C] () – C:\Windows\SysNative\quartz.dll
[2010/06/08 00:51:25 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/06/08 00:48:32 | 000,001,890 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2010/06/03 05:14:36 | 000,024,226 | —- | C] () – C:\Users\Oliver\AppData\Roaming\UserTile.png
[2010/06/03 04:19:38 | 000,000,420 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job
[2010/06/03 01:00:12 | 000,001,490 | —- | C] () – C:\Users\Oliver\.recently-used.xbel
[2010/06/02 00:22:13 | 000,555,008 | —- | C] () – C:\Windows\SysNative\US122cp.cpl
[2010/06/02 00:22:13 | 000,223,232 | —- | C] () – C:\Windows\SysNative\U122_A24x64.DLL
[2010/06/02 00:22:13 | 000,223,232 | —- | C] () – C:\Windows\SysNative\U122_A16x64.DLL
[2010/06/02 00:22:13 | 000,200,320 | —- | C] () – C:\Windows\SysNative\drivers\US122x64.sys
[2010/06/02 00:22:13 | 000,062,976 | —- | C] () – C:\Windows\SysNative\drivers\US122Wdmx64.sys
[2010/06/02 00:22:13 | 000,020,224 | —- | C] () – C:\Windows\SysNative\drivers\US122DLx64.sys
[2010/06/01 23:58:17 | 000,001,898 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2010/06/01 23:58:17 | 000,001,832 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2010/06/01 20:14:27 | 000,442,368 | —- | C] () – C:\Windows\SysNative\winhttp.dll
[2010/05/31 06:12:29 | 000,656,384 | —- | C] () – C:\Windows\SysNative\kerberos.dll
[2010/05/31 06:12:27 | 000,338,944 | —- | C] () – C:\Windows\SysNative\schannel.dll
[2010/05/27 14:51:32 | 000,000,971 | —- | C] () – C:\Users\Oliver\Desktop\Any Video Converter.lnk
[2010/05/27 14:45:10 | 000,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2010/05/18 18:09:18 | 001,420,688 | —- | C] () – C:\Windows\SysNative\drivers\tcpip.sys
[2010/05/18 18:09:17 | 000,224,256 | —- | C] () – C:\Windows\SysNative\iphlpsvc.dll
[2010/05/18 18:09:17 | 000,029,696 | —- | C] () – C:\Windows\SysNative\drivers\tunnel.sys
[2010/05/18 18:09:04 | 000,135,168 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb.sys
[2010/05/18 18:09:03 | 000,273,920 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb10.sys
[2010/05/18 18:09:03 | 000,105,472 | —- | C] () – C:\Windows\SysNative\drivers\mrxsmb20.sys
[2010/05/18 18:08:59 | 004,690,832 | —- | C] () – C:\Windows\SysNative\ntoskrnl.exe
[2010/05/18 18:08:57 | 000,974,848 | —- | C] () – C:\Windows\SysNative\inetcomm.dll
[2010/05/18 18:08:52 | 000,603,648 | —- | C] () – C:\Windows\SysNative\vbscript.dll
[2010/05/18 18:08:37 | 000,072,192 | —- | C] () – C:\Windows\SysNative\l3codeca.acm
[2010/05/18 18:06:05 | 000,104,960 | —- | C] () – C:\Windows\SysNative\cabview.dll
[2010/05/18 18:05:09 | 000,218,112 | —- | C] () – C:\Windows\SysNative\wintrust.dll
[2009/07/13 14:49:27 | 000,354,816 | —- | C] () – C:\Windows\SysWow64\pythoncom26.dll
[2009/07/13 14:49:27 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\pywintypes26.dll
[2009/01/14 16:35:57 | 000,516,096 | —- | C] () – C:\Windows\SysWow64\RegisterDialog.dll
[2008/09/19 04:59:22 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\libxml2.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/05/27 14:51:28 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\AnvSoft
[2010/06/12 12:34:44 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Dropbox
[2010/06/03 02:03:06 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Facebook
[2010/05/27 14:41:38 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\FreeFLVConverter
[2010/06/13 03:20:37 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\FrostWire
[2010/06/11 04:14:48 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\GetRightToGo
[2010/06/03 01:00:12 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\gtk-2.0
[2009/11/28 16:46:49 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Moyea
[2010/06/11 05:08:55 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Music Editor Free
[2009/11/04 01:10:29 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\OpenOffice.org
[2010/06/03 05:14:36 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\PeerNetworking
[2009/09/30 11:25:29 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Publish Providers
[2010/06/12 07:10:41 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\QuickScan
[2010/06/12 05:30:07 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Sony
[2009/10/04 08:12:47 | 000,000,000 | —D | M] – C:\Users\Oliver\AppData\Roaming\Sony Creative Software
[2009/09/30 00:22:16 | 000,000,552 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/06/13 19:06:17 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/13 16:17:15 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{16F7021C-AC8A-4AC5-9DA8-E4518F8C30DF}.job

========== Purity Check ==========


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI