This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My PC is running very slow,please help!

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,my pc normally runs reasonably well and I try my best to keep it virus/spyware free but these past few days it has been running very sluggish even my internet connection is crawling :pullhair: I have tried a few virus scans and the usual malware scans but nothing is getting picked up.I have also done a disk and registry defrag etc.but it is still very sluggish.I am sure it is malware but as I say nothing is getting detected in the scans.if anyone could assist that would be great!
Hello Ally and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

————————————–

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\drivers\*.sys /90
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Patndoris,thank you for taking the time to me help out.the first time I ran otl,it froze with an access violation error and I had to run the scan again but it worked ok the second time.here are the results> OTL logfile created on: 27/06/2010 09:31:38 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\AlistairGC\Desktop\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 193.35 Gb Free Space | 83.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALISTAIR-DFB05C
Current User Name: AlistairGC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/27 09:28:21 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\AlistairGC\desktop\Downloads\OTL.exe
PRC - [2010/06/23 22:36:06 | 000,300,424 | —- | M] (Cloanto Corporation) – C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/02 14:58:52 | 000,495,616 | —- | M] () – C:\Program Files\RocketDock\RocketDock.exe


========== Modules (SafeList) ==========

MOD - [2010/06/27 09:28:21 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\AlistairGC\desktop\Downloads\OTL.exe
MOD - [2009/11/06 23:04:36 | 000,109,072 | —- | M] (Kaspersky Lab) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll
MOD - [2009/11/06 23:04:24 | 000,017,936 | —- | M] (Kaspersky Lab) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll
MOD - [2008/04/14 01:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
MOD - [2007/09/02 14:57:36 | 000,069,632 | —- | M] () – C:\Program Files\RocketDock\RocketDock.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/04/10 17:05:58 | 000,266,544 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2009/10/20 19:39:28 | 000,340,456 | —- | M] (Kaspersky Lab) [Auto | Stopped] – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe – (AVP)
SRV - [2009/06/26 09:26:20 | 000,085,504 | —- | M] (PC Pitstop LLC) [Disabled | Stopped] – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe – (PCPitstop Scheduling)


========== Driver Services (SafeList) ==========

DRV - [2010/06/11 01:58:51 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/04/06 18:13:04 | 005,912,096 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2010/02/23 13:45:14 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV)
DRV - [2010/02/23 13:45:14 | 000,012,872 | —- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2009/12/11 17:02:42 | 004,525,056 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2009/11/18 19:24:26 | 000,095,232 | —- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV - [2009/11/18 07:17:00 | 001,395,800 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2009/11/18 07:16:00 | 001,691,480 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2009/11/11 16:35:34 | 000,315,408 | —- | M] (Kaspersky Lab) [File_System | System | Running] – C:\WINDOWS\system32\drivers\klif.sys – (KLIF)
DRV - [2009/10/14 20:18:34 | 000,036,880 | —- | M] (Kaspersky Lab) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\klbg.sys – (klbg)
DRV - [2009/10/02 18:39:44 | 000,019,472 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\klmouflt.sys – (klmouflt)
DRV - [2009/09/14 13:42:46 | 000,032,272 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\klim5.sys – (klim5)
DRV - [2009/09/01 14:29:50 | 000,128,016 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\kl1.sys – (kl1)
DRV - [2009/07/07 23:00:32 | 000,532,992 | —- | M] (Line 6) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L6TPortGX.sys – (L6TPortGX)
DRV - [2009/06/30 10:37:16 | 000,028,552 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\pavboot.sys – (pavboot)
DRV - [2009/06/24 19:24:00 | 003,734,976 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtKHDMI.sys – (RTHDMIAzAudService)
DRV - [2008/08/01 19:36:26 | 000,022,016 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2008/08/01 19:36:20 | 000,054,784 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2008/04/13 17:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2006/09/24 14:28:46 | 000,005,248 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] – C:\WINDOWS\system32\speedfan.sys – (speedfan)
DRV - [2006/06/14 14:44:30 | 000,012,288 | R— | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EIO_XP.sys – (EIO_XP)
DRV - [2004/08/11 01:00:00 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2001/07/13 14:56:14 | 000,014,976 | —- | M] () [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\SBKUPNT.SYS – (SBKUPNT)
DRV - [1996/04/03 20:33:26 | 000,005,248 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\giveio.sys – (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = about:blank

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://uk.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.4
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.26


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/23 18:15:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/23 20:28:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010/06/20 21:34:55 | 000,000,000 | —D | M]

[2010/02/02 00:25:23 | 000,000,000 | —D | M] – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Extensions
[2010/06/26 06:23:41 | 000,000,000 | —D | M] – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Firefox\Profiles\tz4zjgec.default\extensions
[2010/06/23 02:34:57 | 000,000,000 | —D | M] (FlashGot) – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Firefox\Profiles\tz4zjgec.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010/06/09 01:07:04 | 000,000,000 | —D | M] (Image Zoom) – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Firefox\Profiles\tz4zjgec.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2010/05/03 19:35:31 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Firefox\Profiles\tz4zjgec.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/04 08:22:36 | 000,002,255 | —- | M] () – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Firefox\Profiles\tz4zjgec.default\searchplugins\askcom.xml
[2010/02/02 17:13:30 | 000,001,196 | —- | M] () – C:\Documents and Settings\AlistairGC\Application Data\Mozilla\Firefox\Profiles\tz4zjgec.default\searchplugins\winamp-search.xml
[2010/06/26 06:23:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/02/02 15:51:40 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/01/13 23:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2007/03/10 00:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2010/04/03 20:02:21 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/03 20:02:22 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/03 20:02:22 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/03 20:02:22 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/06/22 19:05:12 | 000,479,811 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net m.fr.a2dfp.net ad.a8.net asy.a8ww.net adserver.abv.bg adv.abv.bg bimg.abv.bg www2.a-counter.kiev.ua track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com www.accuserveadsystem.com achmedia.com aconti.net secure.aconti.net www.aconti.net ads.active.com am1.activemeter.com www.activemeter.com
O1 - Hosts: 127.0.0.1 ads.activepower.net stat.active24stats.nl ad2games.com cms.ad2click.nl ads.ad2games.com content.ad20.net core.ad20.net as.ad611.com banner.ad.nu
O1 - Hosts: 127.0.0.1 cl21.v4.adaction.se adadvisor.net www.adagencypro.com tag1.adaptiveads.com www.adbanner.ro vad.adbasket.net wad.adbasket.net ad.pop1.adbn.ru ad.top1.adbn.ru
O1 - Hosts: 127.0.0.1 ad.rich1.adbn.ru james.adbutler.de www.adbutler.de ad-clix.com www.ad-clix.com adcomplete.com www.adcomplete.com axa.addcontrol.net www.adeos.eu
O1 - Hosts: 127.0.0.1 pt.server1.adexit.com www.adexit.com 222-33544_999.pub.adfirmative.com c.adfirmative.com www.adfirmative.com track.adform.net ad.adfox.cz ads.adfox.ru gazeta.adfox.ru
O1 - Hosts: 127.0.0.1 media.adfrontiers.com www.ad-groups.com ssl3.adhost.com www2.adhost.com mztag.ad-indicator.com zone10.adicate.com adfarm1.adition.com imagesrv.adition.com ad.adition.net
O1 - Hosts: 127.0.0.1 hosting.adjug.com tracking.adjug.com adsearch.adkontekst.pl publicidad.adlead.com www.adlimg03.com regio.adlink.de west.adlink.de rc.de.adlink.net tr.de.adlink.net
O1 - Hosts: 127.0.0.1 ads3.adman.gr r2d2.adman.gr js.admeld.com tag.admeld.com admigo.ru data.admigo.ru apps.admission.net appcache.admission.net view.admission.net
O1 - Hosts: 127.0.0.1 www.ad.admitad.com rms.admeta.com ads.admodus.com ad.adnet.biz ad.adnetwork.com.br adnext.fr adpixel.com.ru tt11.adobe.com ad01.adonspot.com
O1 - Hosts: 127.0.0.1 ad02.adonspot.com img.adplan-ds.com ab.adpro.com.ua system.adquick.nl www.adquest.nl www.adreap.com adroll.com jsad1.adsflip.com www.adsforadults.com
O1 - Hosts: 127.0.0.1 www.ad-purge.com cntr.adrime.com images.adrime.com ad.adriver.ru www.adrotate.net serv.ad-rotator.com antevenio.flux.ads-click.com engage2.advanstar.com yield.adv.bg
O1 - Hosts: 127.0.0.1 ds.advg.jp beta.adyea.com delivery.adyea.com img.ads-click.com ad.ads.dk tdkads.ads.dk js.adscale.de ih.adscale.de adservicedomain.info
O1 - Hosts: 127.0.0.1 adsfac.net images.adshuffle.com this.content.served.by.adshuffle.com adsfac.eu www.adshot.de allchix.adsmax.com www2.adsmax.com www.adsodainteractive.com www.adspace.be
O1 - Hosts: 127.0.0.1 ads.adsponse.de adserve.adster.com images.adster.com openx.adtext.ro ads.adtiger.de www.adtiger.de ad.adtoma.com downldcl.adtoolsinc.com www.adtoolsinc.com
O1 - Hosts: 127.0.0.1 www.adtrade.net www.adtrader.com adtraf.ru ads.adtube.de ads1.adultadvertising.net cdn.adultadvertising.net www.adultadvertising.net www.adultbanners.co.uk www.adultmoviegroup.com
O1 - Hosts: 127.0.0.1 www.adult-tracker.de counter.adultrevenueservice.com counterimg1.adultrevenueservice.com www.adultwords.eu ad.adver.com.tw advert.hu www.adverticus.de ads.advertise.net advertisingpurchase.com
O1 - Hosts: 127.0.0.1 ad.adverticum.net img.adverticum.net imgs.adverticum.net www.advertising365.com ad.advertstream.com usas1.advfn.com images.adviews.de www.adviews.de ad.adworx.at
O1 - Hosts: 127.0.0.1 adxrnet.net a-fast.com www.ad-z.de ads.afa.net ads.affiliateclub.com banners.affiliatefuture.com media.affiliatelounge.com js.affiliatelounge.com record.affiliatelounge.com
O1 - Hosts: 127.0.0.1 web1.affiliatelounge.com hits.affiliatetraction.com banners.affilimatch.de tracker.affistats.com adz.afterdawn.net stats.agent.co.il stats.agentinteractive.com adlik2.akavita.com adserver.akqa.net
O1 - Hosts: 127.0.0.1 ads1.a-lehdet.fi download.china.alibaba.com www.allbrowsers.net allpills.net tracking.allposters.com ad.allstar.cz adtaobao.allyes.cn taobaoafp.allyes.cn bokee.allyes.com
O1 - Hosts: 127.0.0.1 demoafp.allyes.com eastmoney.allyes.com smarttrade.allyes.com sroomafp.allyes.com taobaoafp.allyes.com tom.allyes.com uuseeafp.allyes.com yeskyafp.allyes.com www.almoso3h.com
O1 - Hosts: 127.0.0.1 ad.altervista.org pqwaker.altervista.org adimg.alice.it adv.alice.it altmedia101.com www.alwayson-network.com adtools2.amakings.com banners.amsterdamcash.com widgets.amung.us
O1 - Hosts: 2514 more lines…
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
O4 - HKCU..\Run: [EPSON SX410 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFCE.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [HostsMan] C:\Program Files\HostsMan\hm.exe (abelhadigital.com)
O4 - HKCU..\Run: [HostsServer] C:\Program Files\HostsMan\hostssrv.exe (abelhadigital.com)
O4 - HKCU..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Software Director Scheduler.lnk = C:\Program Files\Common Files\Cloanto\Software Director\softdir.exe (Cloanto Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 01 00 00 00 [binary data]
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab)
O15 - HKCU\..Trusted Domains: line6.net ([]* in Trusted sites)
O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} http://download.tenebril.com/pub/bin/scann…wareScanner.ocx (TenebrilSpywareScanner Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\kloehk.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Documents and Settings\AlistairGC\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\AlistairGC\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/01 22:56:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/02/01 22:40:55 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/26 23:24:32 | 000,000,000 | RH-D | C] – C:\Documents and Settings\AlistairGC\Recent
[2010/06/23 22:37:09 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\Cloanto
[2010/06/23 22:36:09 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\Amiga Files
[2010/06/23 22:36:09 | 000,000,000 | —D | C] – C:\Program Files\Cloanto
[2010/06/23 06:28:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/06/23 06:28:07 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2010/06/23 05:31:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Readon
[2010/06/23 05:17:56 | 000,000,000 | —D | C] – C:\Program Files\Readon Technology
[2010/06/22 22:20:42 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010/06/22 19:19:30 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/06/16 16:07:18 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdjpn.dll
[2010/06/16 16:07:18 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdjpn.dll
[2010/06/16 16:07:18 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdkor.dll
[2010/06/16 16:07:18 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdkor.dll
[2010/06/16 16:07:18 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd101c.dll
[2010/06/16 16:07:18 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101c.dll
[2010/06/16 16:07:18 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd103.dll
[2010/06/16 16:07:18 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd103.dll
[2010/06/16 16:07:15 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd106.dll
[2010/06/16 16:07:15 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd106.dll
[2010/06/16 16:07:15 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbd101b.dll
[2010/06/16 16:07:15 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbd101b.dll
[2010/06/16 16:04:32 | 000,000,000 | —D | C] – C:\Program Files\TVAnts
[2010/06/15 17:58:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/06/15 17:55:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Symantec
[2010/06/15 17:55:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2010/06/15 17:55:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/06/11 07:46:00 | 000,000,000 | R–D | C] – C:\Documents and Settings\AlistairGC\My Documents\Spectrum
[2010/06/11 03:23:27 | 000,000,000 | —D | C] – C:\Program Files\P2PFilter
[2010/06/11 03:22:48 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\vlc
[2010/06/11 03:20:59 | 000,000,000 | —D | C] – C:\WINDOWS\System32\TVUAx
[2010/06/11 03:16:08 | 000,000,000 | R–D | C] – C:\Documents and Settings\AlistairGC\My Documents\Readon Player
[2010/06/11 03:16:08 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\Readon_Technology
[2010/06/11 03:14:11 | 000,000,000 | —D | C] – C:\Program Files\Veetle
[2010/06/11 02:26:43 | 000,000,000 | —D | C] – C:\Program Files\TweakNow RegCleaner
[2010/06/11 02:26:43 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\TweakNow RegCleaner
[2010/06/11 01:08:55 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\GlarySoft
[2010/06/11 01:07:25 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2010/06/09 05:03:02 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/08 20:46:35 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\FixItCenter
[2010/06/08 20:40:17 | 000,000,000 | —D | C] – C:\WINDOWS\MATS
[2010/06/08 20:40:16 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Fix it Center
[2010/06/08 20:39:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2010/06/07 02:56:49 | 000,000,000 | —D | C] – C:\Program Files\Computerbrains C.C.S
[2010/06/07 02:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\CCS64
[2010/06/07 00:42:10 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\Help
[2010/06/07 00:42:10 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\Help
[2010/06/01 16:06:11 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\Cloanto
[2010/06/01 16:04:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Cloanto
[2010/06/01 16:04:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Cloanto
[2010/06/01 15:17:59 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Application Data\Stella
[2010/06/01 15:12:05 | 000,000,000 | —D | C] – C:\Program Files\Stella
[2010/06/01 14:51:57 | 000,000,000 | —D | C] – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\www.datadevelopment.co.uk
[2010/05/31 13:44:15 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/05/31 13:44:15 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/05/30 16:14:20 | 000,000,000 | —D | C] – C:\Program Files\SopCast
[2010/05/30 16:03:16 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight

========== Files - Modified Within 30 Days ==========

[2010/06/27 09:25:42 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/06/27 09:25:41 | 000,000,616 | -H– | M] () – C:\WINDOWS\tasks\ConfigExec.job
[2010/06/27 09:25:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/27 09:25:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/27 02:45:14 | 005,767,168 | —- | M] () – C:\Documents and Settings\AlistairGC\NTUSER.DAT
[2010/06/27 02:45:14 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\AlistairGC\ntuser.ini
[2010/06/26 09:12:18 | 006,745,490 | -H– | M] () – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\IconCache.db
[2010/06/26 08:45:01 | 000,000,580 | -H– | M] () – C:\WINDOWS\tasks\DataUpload.job
[2010/06/25 12:11:51 | 000,000,096 | —- | M] () – C:\WINDOWS\System32\w3data.vss
[2010/06/25 12:11:51 | 000,000,096 | —- | M] () – C:\WINDOWS\System32\msvcsv60.dll
[2010/06/25 12:11:51 | 000,000,096 | —- | M] () – C:\WINDOWS\msocreg32.dat
[2010/06/24 11:48:14 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/23 22:37:10 | 000,001,769 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Software Director Scheduler.lnk
[2010/06/23 14:06:06 | 000,018,368 | —- | M] () – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/23 14:05:48 | 002,002,704 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/22 22:06:50 | 000,000,000 | —- | M] () – C:\WINDOWS\ativpsrm.bin
[2010/06/22 22:00:35 | 000,000,036 | —- | M] () – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\housecall.guid.cache
[2010/06/22 19:32:01 | 000,501,020 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/22 19:32:01 | 000,440,820 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/06/22 19:32:01 | 000,071,138 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/06/22 19:05:12 | 000,479,811 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/06/22 18:03:18 | 005,767,168 | —- | M] () – C:\Documents and Settings\AlistairGC\NTUSER.DAT.gbck
[2010/06/18 03:36:14 | 000,063,488 | —- | M] () – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/16 03:59:18 | 000,000,232 | —- | M] () – C:\Documents and Settings\AlistairGC\Desktop\Realtek HD.lnk
[2010/06/14 16:55:20 | 000,001,041 | —- | M] () – C:\Documents and Settings\AlistairGC\Application Data\vso_ts_preview.xml

========== Files Created - No Company Name ==========

[2010/06/23 22:37:10 | 000,001,769 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Software Director Scheduler.lnk
[2010/06/22 22:06:50 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/06/22 22:00:35 | 000,000,036 | —- | C] () – C:\Documents and Settings\AlistairGC\Local Settings\Application Data\housecall.guid.cache
[2010/06/16 03:59:18 | 000,000,232 | —- | C] () – C:\Documents and Settings\AlistairGC\Desktop\Realtek HD.lnk
[2010/06/13 04:09:02 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\ntuser.dat.LOG
[2010/06/11 01:07:36 | 000,000,322 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/06/08 20:45:31 | 000,000,616 | -H– | C] () – C:\WINDOWS\tasks\ConfigExec.job
[2010/06/08 20:45:31 | 000,000,580 | -H– | C] () – C:\WINDOWS\tasks\DataUpload.job
[2010/03/05 02:24:22 | 000,014,976 | —- | C] () – C:\WINDOWS\System32\drivers\SBKUPNT.SYS
[2010/03/05 02:24:22 | 000,000,543 | —- | C] () – C:\WINDOWS\SWISV3.INI
[2010/03/05 02:22:48 | 000,000,351 | —- | C] () – C:\WINDOWS\SKNIFE.INI
[2010/03/05 02:22:38 | 000,002,799 | —- | C] () – C:\WINDOWS\SKLANG.INI
[2010/02/08 12:28:46 | 000,138,184 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/02/07 08:17:59 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\AVERM.dll
[2010/02/07 08:17:59 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2010/02/07 00:58:01 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2010/02/07 00:58:01 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\UNRAR3.dll
[2010/02/07 00:58:01 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2010/02/07 00:58:01 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\unacev2.dll
[2010/02/05 08:56:17 | 000,000,096 | —- | C] () – C:\WINDOWS\System32\msvcsv60.dll
[2010/02/05 08:02:05 | 000,000,032 | —- | C] () – C:\WINDOWS\GearBox.ini
[2010/02/03 19:40:19 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/02/03 08:17:25 | 000,327,168 | —- | C] () – C:\WINDOWS\System32\cutil32.dll
[2010/02/02 19:21:04 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2010/02/02 19:11:27 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/02/01 23:00:57 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/02/01 23:00:56 | 000,010,855 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/02/01 23:00:44 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/05 16:44:10 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2010/02/01 23:40:20 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2010/02/01 23:40:20 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2010/02/01 23:40:20 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2010/02/01 23:40:20 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/04/06 18:13:04 | 005,912,096 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\RtkHDAud.sys

< %systemroot%\System32\config\*.sav >
[2010/02/01 22:45:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/01 22:45:08 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/01 22:45:07 | 000,929,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL Extras logfile created on: 27/06/2010 09:31:38 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\AlistairGC\Desktop\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 88.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 193.35 Gb Free Space | 83.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALISTAIR-DFB05C
Current User Name: AlistairGC
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Documents and Settings\AlistairGC\My Documents\Readon Player\PPStream\ppstreamsetup.exe" = C:\Documents and Settings\AlistairGC\My Documents\Readon Player\PPStream\ppstreamsetup.exe:*:Enabled:PPStream Installer – (PPStream Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00460304-776C-A796-C608-646BF980EC46}" = ccc-core-static
"{036778E0-D3CE-40AC-94E7-F5AF42F3245D}" = System Requirements Lab
"{07205226-AAB8-F2D9-2526-5A66374382E9}" = Skins
"{1584854C-1513-40EA-96D4-493384D0A3C7}" = Readon TV Movie Radio Player [removed]
"{1BA7B068-4719-42A3-B553-D4ED97434F92}" = ASUS Utilities
"{1E99F5D7-4262-4C7C-9135-F066E7485811}" = System Requirements Lab
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21E77392-C30A-4AA2-8CA7-5728316939D6}" = AmpliTube X-GEAR
"{26190AE8-5AA4-0E3B-52CD-59639B19C00D}" = CCC Help Danish
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 19
"{27E10D92-0E23-5B27-3560-85900B58C096}" = Catalyst Control Center InstallProxy
"{299A760B-F9B6-7188-675E-4C44D13D5E2E}" = CCC Help Hungarian
"{30CF9022-AEB7-1F22-E0DD-8C981421EDA3}" = CCC Help Swedish
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C728284-C001-4F15-D1CF-137AC0EC7200}" = Catalyst Control Center Graphics Light
"{443BDB1D-9D11-1622-5463-BC5DD151E99C}" = CCC Help Russian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5E1EA949-18B6-F9BD-8ED8-DD659434953D}" = CCC Help Chinese Traditional
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6421EC43-08D1-DCB5-DDE1-576CB4EAF054}" = CCC Help English
"{65B5F236-F170-FA96-076C-6B8699941A0E}" = Catalyst Control Center Core Implementation
"{65BA862A-5BAC-2745-33FE-CFB150C643E7}" = CCC Help Turkish
"{66AC1F27-31F0-B0D0-35BE-59B8B25E22D6}" = CCC Help Dutch
"{66BA35B0-1911-47EF-B170-1DCFFDA362F1}" = AmpliTube Jimi Hendrix
"{682849BC-495D-6C9F-F95F-57C5D55C6CFE}" = CCC Help Italian
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6ED53E0C-EAC0-4F0F-947D-6BA817E4C8C3}" = HostsMan 3.2.73
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75B2DC21-4C80-C214-24DF-E70F67344629}" = CCC Help Japanese
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{80BC8DD5-50F9-6B05-CE77-80BE9E7DD5F6}" = CCC Help Finnish
"{86A6E58A-9E31-7A72-89C0-CBD8C73F6150}" = CCC Help German
"{87C2248A-C7DD-49ED-9BCD-B312A9D0819E}" = Epson Easy Photo Print 2
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D9A043F-C11E-ED0D-E770-C5BC44D3F513}" = CCC Help Chinese Standard
"{8DC20D05-8290-7E44-5F0A-3B8CE3A37EC3}" = CCC Help French
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{9647D0B8-8A59-5036-FEB2-8F76F8BB4F55}" = CCC Help Spanish
"{9901E703-D169-7139-1EA3-11AA788D09E6}" = EA Download Manager UI
"{9960404D-ABA0-0266-8E12-945225C819A9}" = Catalyst Control Center Graphics Full Existing
"{9C8FFE5E-8874-AE20-FFE7-E3B9105581C3}" = CCC Help Czech
"{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"{9EDEF5B1-B740-4DFF-AC16-E2428E1713E8}" = AmpliTube Metal
"{9F84955E-69AF-458E-80ED-11815CE7339B}" = Amiga Forever
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8244E14-F4E4-31EB-F21D-E7EF39C418F9}" = ccc-core-preinstall
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A961C6FD-C583-45F6-A0A4-5E4376C29E41}" = Catalyst Control Center - Branding
"{AB4E651E-AE7D-293F-118F-ADC6C9DA5C52}" = CCC Help Greek
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AE83825B-D164-74AF-8BB5-1994031C3EF4}" = ATI Catalyst Install Manager
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{B7B5A370-3DFF-4F0E-AE11-FD267C4938AA}" = CCS64 V3.8
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C28329AA-A364-94D2-78CF-F9D771D436FD}" = Catalyst Control Center Localization All
"{C74B4FF7-2EA0-C4A8-72FB-848B291D86D8}" = CCC Help Korean
"{C95AACD4-9507-4F5C-9D53-22B1ACCFECD1}" = AmpliTube2
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CB0888EE-96D8-4713-84DC-36462C33AEB4}" = Bazooka Scanner
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF1D7323-8A0A-49C7-83B0-088DB90721E2}" = AmpegSVX
"{D291EBA2-0D79-E8A5-1446-2FBAFF2AF8A7}" = CCC Help Norwegian
"{D7B7F3D1-6B2F-1EFA-3C06-4C0D419BC5B6}" = Catalyst Control Center Graphics Full New
"{D82E84AC-352B-BF56-4EE6-0642B418E05F}" = CCC Help Thai
"{DB34B7D9-3D88-0BCD-EC73-F4257D5E3773}" = CCC Help Portuguese
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.9.322
"{DFCBC0F1-0B1B-BD17-C25B-9668C3D8E7AD}" = ccc-utility
"{E07B7A31-E160-466D-A003-3BB7B8989D52}" = Full Tilt Poker.Net
"{E6D22FE1-AB5F-42CA-9480-6F70B96DDD88}" = Need for Speed™ Undercover
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1A06A77-C165-D0D6-BA42-028D0AE7EC8A}" = CCC Help Polish
"1-Click YouTube Downloader_is1" = 1-Click YouTube Downloader 3.5
"1F0E20D8CBC90AE0A7D8D4BE19DA2B828EA87737" = Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (04/06/2010 5.10.0.6083)
"68B5B659620BA71C88432828271F056F69D0C6DE" = Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (12/25/2009 5.10.0.6013)
"7-Zip" = 7-Zip 4.65
"ActiveScan 2.0" = Panda ActiveScan 2.0
"AD9BEB3DAB1038EFFD54D6304D1EF6AD77B00CF3" = Windows Driver Package - NVIDIA (nvnetbus) NVIDIA Network Bus Enumerator (08/01/2008 67.8.9)
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Allok Video Joiner_is1" = Allok Video Joiner 4.4.1117
"Allok Video Splitter_is1" = Allok Video Splitter 3.1.1117
"ASIO4ALL" = ASIO4ALL
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"CompuApps SwissKnife V3" = CompuApps SwissKnife V3
"D5F4FEC618ADFEC3DDD071D03C748C1FCCAF2AF9" = Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (06/24/2009 5.10.0.5880)
"D7D7FC245514D8A73514D0C1533247DF9D582CF9" = Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (03/13/2010 5.10.0.6066)
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"EA Download Manager" = EA Download Manager
"EPSON Scanner" = EPSON Scan
"Epson Stylus SX210_SX410_TX210_TX410 User’s Guide" = Epson Stylus SX210_SX410_TX210_TX410 Manual
"Foxit Reader" = Foxit Reader
"Free Download Manager_is1" = Free Download Manager 3.0
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2
"Game Booster_is1" = Game Booster
"Glary Utilities_is1" = Glary Utilities 2.23.0.923
"Guitar Pro 5_is1" = Guitar Pro 5.2
"ie8" = Windows Internet Explorer 8
"InstallWIX_{9D8B0949-7C47-476F-9F06-F900D3B078EA}" = Kaspersky Internet Security 2010
"Line 6 Uninstaller" = Line 6 Uninstaller
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Mp3tag" = Mp3tag v2.45a
"NVIDIA Drivers" = NVIDIA Drivers
"P2PFilter" = P2PFilter 3.0.5
"PC Matic_is1" = PC Matic 1.0.0.0
"PC Wizard 2010_is1" = PC Wizard 2010.1.93
"PhotoScape" = PhotoScape
"PokerStars" = PokerStars
"Revo Uninstaller" = Revo Uninstaller 1.88
"RiffWorks T4" = RiffWorks T4
"RocketDock_is1" = RocketDock 1.3.5
"Smart Defrag_is1" = Smart Defrag
"SopCast" = SopCast 3.2.9
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.3
"Stella_is1" = Stella 3.1.2
"The KMPlayer" = The KMPlayer (remove only)
"Trojan Remover_is1" = Trojan Remover 6.8.1
"TVAnts 1.0" = TVAnts 1.0
"Tweak UI 2.10" = Tweak UI
"TweakNow RegCleaner_is1" = TweakNow RegCleaner
"UnderCoverXP_is1" = UnderCoverXP 1.23
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.17
"Winamp" = Winamp
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.8

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"IconTweaker" = IconTweaker 1.11
"PhotoFiltre" = PhotoFiltre
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13/02/2010 18:00:50 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application kmplayer.exe, version 2.9.4.1435, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 13/02/2010 19:02:48 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application kmplayer.exe, version 2.9.4.1435, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 13/02/2010 19:14:37 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application kmplayer.exe, version 2.9.4.1435, faulting module
kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 01/03/2010 21:02:51 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application amplitube x-gear.exe, version 1.5.0.0, faulting
module amplitube x-gear.exe, version 1.5.0.0, fault address 0x0004e778.

Error - 29/03/2010 11:16:53 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.2.3727, faulting module
npqscan.dll, version 0.9.9.13, fault address 0x000851a9.

Error - 29/03/2010 11:22:30 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.2.3727, faulting module
qscanff.dll, version 0.9.9.13, fault address 0x00056060.

Error - 29/03/2010 11:24:02 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.2.3727, faulting module
npqscan.dll, version 0.9.9.13, fault address 0x000851a9.

Error - 29/03/2010 20:57:58 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application pavark.exe, version 5.0.0.4, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x000369da.

Error - 01/04/2010 05:40:49 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.2.3727, faulting module
qscanff.dll, version 0.9.9.15, fault address 0x00056510.

Error - 11/04/2010 09:55:18 | Computer Name = ALISTAIR-DFB05C | Source = Application Error | ID = 1000
Description = Faulting application kmplayer.exe, version 2.9.4.1435, faulting module
unknown, version 0.0.0.0, fault address 0xa53b653c.

[ System Events ]
Error - 23/06/2010 00:09:56 | Computer Name = ALISTAIR-DFB05C | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 23/06/2010 00:09:57 | Computer Name = ALISTAIR-DFB05C | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 23/06/2010 09:07:02 | Computer Name = ALISTAIR-DFB05C | Source = DCOM | ID = 10016
Description = The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.

Error - 23/06/2010 16:26:52 | Computer Name = ALISTAIR-DFB05C | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 23/06/2010 16:26:52 | Computer Name = ALISTAIR-DFB05C | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 24/06/2010 12:50:40 | Computer Name = ALISTAIR-DFB05C | Source = SideBySide | ID = 16842810
Description = Syntax error in manifest or policy file "I:\setup.exe" on line 0.

Error - 24/06/2010 12:50:40 | Computer Name = ALISTAIR-DFB05C | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for I:\setup.exe. Reference error
message: The operation completed successfully. .

Error - 26/06/2010 03:45:18 | Computer Name = ALISTAIR-DFB05C | Source = Service Control Manager | ID = 7034
Description = The Microsoft Automated Troubleshooting Service service terminated
unexpectedly. It has done this 1 time(s).

Error - 27/06/2010 04:30:07 | Computer Name = ALISTAIR-DFB05C | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 27/06/2010 04:30:07 | Computer Name = ALISTAIR-DFB05C | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-27 10:38:46
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ALISTA~1\LOCALS~1\Temp\fgrdqfob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xAE10658C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xAE106E0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xAE107922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xAE107E94]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xAE1070EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xAE105436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xAE107D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xAE106192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xAE107C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xAE10634E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xAE107FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xAE109C08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xAE106AAA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xAE107CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xAE1095FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xAE1059FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xAE105D88]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xAE107576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xAE10A5CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xAE105ECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xAE105F74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xAE107382]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xAE10968C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xAE105412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xAE105424]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwMapViewOfSection [0xAE109CBC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xAE1060C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xAE107F36]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xAE106E8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xAE1055DC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xAE107E04]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xAE106792]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xAE109C32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xAE108068]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xAE1066B6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xAE10601E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xAE105C46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xAE109FD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xAE105896]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xAE109922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xAE105B0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xAE1052B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xAE1083F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xAE1082B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xAE10939A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xAE10CE2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xAE10A4AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xAE105248]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xAE10765C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xAE106CC8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xAE108C4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xAE109786]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xAE10A114]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xAE10571E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xAE10A1F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xAE10A320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xAE109526]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xAE10690A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xAE106860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xAE109E8A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xAE1069EA]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF84 5 Bytes JMP AE0FB4DC \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF912 5 Bytes JMP AE0FB8B6 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntkrnlpa.exe!ZwCallbackReturn + 2C98 80504534 16 Bytes [4E, 63, 10, AE, C6, 7F, 10, …]
.text ntkrnlpa.exe!ZwCallbackReturn + 2D54 805045F0 12 Bytes [8C, 96, 10, AE, 12, 54, 10, …] {MOV WORD [ESI+0x5412ae10], SS; ADC [ESI-0x51efabdc], CH}
.text ntkrnlpa.exe!ZwCallbackReturn + 2ED0 8050476C 16 Bytes [0E, 5B, 10, AE, B0, 52, 10, …]
.text ntkrnlpa.exe!ZwCallbackReturn + 2F08 805047A4 5 Bytes [AC, A4, 10, AE, 48]
.text ntkrnlpa.exe!ZwCallbackReturn + 2F0E 805047AA 2 Bytes [10, AE]
.text …
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6618000, 0x223937, 0xE8000020]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

—- EOF - GMER 1.0.15 —-
P2P - I see you have P2P software ( µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
  • [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.
Hi Patndoris,I ran a quick scan with MBytes and it found no infections,here is the log > Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4247 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 27/06/2010 18:30:49 mbam-log-2010-06-27 (18-30-49).txt Scan type: Quick scan Objects scanned: 116487 Time elapsed: 5 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    DRV - [2009/06/30 10:37:16 | 000,028,552 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\pavboot.sys – (pavboot)
    [2010/06/22 22:06:50 | 000,000,000 | —- | M] () – C:\WINDOWS\ativpsrm.bin
    
    :Commands
    [purity]
    [emptytemp]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log

Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Can you please let me know if there is any improvement in how your system is running?
Hi Patndoris, here is the otl scan result and the eset online result > All processes killed ========== OTL ========== Error: Unable to stop service pavboot! Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pavboot deleted successfully. C:\WINDOWS\system32\drivers\pavboot.sys moved successfully. C:\WINDOWS\ativpsrm.bin moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: AlistairGC ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 39379893 bytes ->Flash cache emptied: 881 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 118124 bytes Total Files Cleaned = 38.00 mb Restore point Set: OTL Restore Point (0) OTL by OldTimer - Version 3.2.7.0 log created on 06272010_213458 Files\Folders moved on Reboot… Registry entries deleted on Reboot… ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=7d2644f6a06d5d46adb32758177829f2 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-06-27 09:05:48 # local_time=2010-06-27 10:05:48 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1280 16777191 100 0 12608156 12608156 0 0 # compatibility_mode=8192 67108863 100 0 182 182 0 0 # scanned=67716 # found=0 # cleaned=0 # scan_time=1127 My internet speed feels like it has improved slightly.
Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.

If you ran DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 20 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 20 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u20 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

Please let me know whe you have completed these steps.
Hi Patndoris, I have removed the tools and installed the new java.After going through the fixes though when booting my pc a black screen appears saying windows did not shutdown correctly a recent hardware or software change may have caused this,this has happened twice now.but other than this my PC has been running a bit faster.
1. Can you please advise if you are getting the error after a Restart or after a complete Shut Down of the computer? 2. When you get the error are you choosing "Start Windows Normally" or are you selecting "Last Good Configuration"? 3. Do you know after which fix this started happening? Or was it after you did the last set of instructions with Java and OTC? I want to be sure I understand the scenario fully before moving ahead.
Hi Patndoris ,1. I have only gotten the error twice and it has been after a complete shutdown. 2.I chose start windows normally 3.I think it was after the last set of instructions that it happened. I have not had this start up problem again though since.
Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.

Since the start up error only happened twice, there could have been any number of reasons for it. But if it's not happening now, it probably isn't anything to worry about. If you get the error again, please try choosing "last known good configuration" and seeing if that helps. I'll leave this thread open for a few days just in case you have any further issues with this error.

Please follow these simple steps in order to keep your computer malware free and secure:

Set a New Restore Point to prevent possible reinfection from an old one.
Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
* Go to Start > Programs > Accessories > System Tools
* Click "System Restore"
* Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
* Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
* Then go to Start > Run and type: Cleanmgr
* Click "OK"
* Click the "More Options" Tab.
* Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your Kaspersky AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
From your logs, it would appear you are using Kaspersky as your firewall (part of the internet security suite). I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Make your Internet Explorer more secure
This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

You should always update your version of the Adobe Flash to the newest version:
You should keep your version of Sun Java Platform (JRE) to the newest version:
We have already completed this step, but it is important to continue to keep this updated in the future.

Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

The download and tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Update and Run Malwarebytes Anti-Malware
Update and scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with SuperAntiSpyware.

Update and run SUPERAntiSpyware Home Edition (free edition)
You should also update and scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with Malwarebytes.

Perform an online virus scan
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender: http://www.bitdefender.com/scan8/

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck & Happy surfing!
Hi Patndoris,I havent had any black screens since so it must have been something else.My pc is running a bit better along with my internet connection.Thanks for all your help and for taking the time to get me sorted!best regards,Ally. :thumbup: :notworthy:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI