This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Just come back from university to find my home pc appears to have been throughly bum raped during my absence.It appears to have been running without an operational firewall for some time. I think iv got rid of most of the problems using SpyBot, AVG, and doing a registry clean using CCleaner.

However my browsers (Mozilla and Chrome) keep redirecting me ether to links that dont work or the same sort of add pages. It normaly happens when i click on any link ether from google search or any hyperlink on a web page,recently iv been getting around this by using the back button and reloading the page til finaly i get a break through, however there are some occasions when this doesnt work. I also noticed that some times it redirects me automaticaly when im on a page without even clicking a link.

I tryed using spybot to get rid of this but it doesnt appear to find anything in a scan (which is unusual in itself) nor does AVG.

Pleas help me, im going mad :-S !

:pullhair:

Compsetup

Windows XP (SP2 i think)
Pentium 4, 3.0 GHZ
3GB RAM, X600

HijackThis Log :

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 03:18:11, on 03/07/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\M-Audio\Install\EvoInst.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\vsnpstd.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
C:\Program Files\USB TV\EM28XX\BDARemote.exe
C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
C:\Program Files\Virgin Broadband Wireless\wpa_supplicant.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe
C:\Program Files\Spotify\spotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Zombina-Web\wamp\wampmanager.exe
C:\Zombina-Web\wamp\bin\apache\apache2.2.11\bin\httpd.exe
C:\Zombina-Web\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
C:\Zombina-Web\wamp\bin\apache\apache2.2.11\bin\httpd.exe
C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chris Speck\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com//0seenus/saos01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
O2 - BHO: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - (no file)
O2 - BHO: FoxieToolbar Class - {432CAE3B-690F-4C3B-BD97-070EBDA210D5} - C:\Program Files\Foxie Suite\foxietoolbaru.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FoxieSecurityModule Class - {C65185B1-D52B-44A9-861F-8201B50D1F37} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O2 - BHO: flvpronetwork - {d2aebbd0-2d7d-ec6b-98af-874c3e0f3537} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {2991BC79-8959-3D13-A77D-64AC10B82334} - http://85.255.113.214/1/gdnFR2218.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://workhardplayhard1.spaces.msn.com//P…ad/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{372CFF97-FB45-4F5C-BED6-0A763D10C6AC}: NameServer = 93.188.165.169,93.188.161.191
O17 - HKLM\System\CCS\Services\Tcpip\..\{63230AAB-BB4B-499E-AB32-07607F545928}: NameServer = 93.188.165.169,93.188.161.191
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.165.169,93.188.161.191
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 93.188.165.169,93.188.161.191
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.165.169,93.188.161.191
O20 - AppInit_DLLs: acaptuser32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: M-Audio Installer (EvoInstallerService) - Unknown owner - C:\Program Files\M-Audio\Install\EvoInst.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: mental ray 3.7 Satellite for Autodesk 3ds Max Design 2010 32-bit 32-bit (mi-raysat_3dsmax2010_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NinjaVideo Helper (NinjaVideo Helper.exe) - NinjaVideo - C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: wampapache - Apache Software Foundation - C:\Zombina-Web\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - C:\Zombina-Web\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe

–
End of file - 17328 bytes
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
1. Sorry for the late reply I'm having problems with GMER, ran it twice now takes about 5 hours to run, the first time it crashed and the second time it simply wouldn't let me save the results, the pc just froze. However iv just read the details on your post again, and will now try running it with devices unchecked.Can I also ask how you put your pc into safe mode? Cheers, please find below my results from OTL. I'l reply with the result from my latest GMER run in roughly 15 hrs time. Unfortunately I need the pc to work on through the day so I'l leave it running again tonight.


2. Extras Text

OTL Extras logfile created on: 03/07/2010 13:25:16 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Chris Speck\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
7.00 Gb Paging File | 7.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 4605 4605 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.95 Gb Total Space | 8.34 Gb Free Space | 5.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 359.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRIS
Current User Name: Chris Speck
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with Paint Shop Pro Studio] – "C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\\Paint Shop Pro Studio.exe" "/Browse" "%L" (Jasc Software, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [oneclickpdf] – "C:\Program Files\Sowedoo Software\One Click PDF 2\OneClickPDF.exe" %l (Sowedoo Software)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"22797:TCP" = 22797:TCP:*:Enabled:BitComet 22797 TCP
"22797:UDP" = 22797:UDP:*:Enabled:BitComet 22797 UDP
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" = C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe:LocalSubNet:Enabled:Wireless Manager – (Affinegy, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems, Inc.)
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi – (Pinnacle Systems, Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade – (THQ Canada Inc.)
"C:\Program Files\BitComet\BitComet.exe" = C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client – (www.BitComet.com)
"C:\Program Files\Macromedia\FreeHand 10\FreeHand 10.exe" = C:\Program Files\Macromedia\FreeHand 10\FreeHand 10.exe:*:Enabled:FreeHand 10 – File not found
"C:\Program Files\Macromedia\Fireworks MX\Fireworks.exe" = C:\Program Files\Macromedia\Fireworks MX\Fireworks.exe:*:Enabled:Fireworks MX – File not found
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"C:\Documents and Settings\Chris Speck\Local Settings\Temp\ElectronicArts_Patcher_000.exe" = C:\Documents and Settings\Chris Speck\Local Settings\Temp\ElectronicArts_Patcher_000.exe:*:Enabled:ElectronicArts_Patcher_000 – File not found
"C:\Program Files\LucasArts\Force Commander\Resource\focom.exe" = C:\Program Files\LucasArts\Force Commander\Resource\focom.exe:*:Enabled:Focom – File not found
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade – File not found
"C:\Program Files\Valve\Steam\SteamApps\[removed]\day of defeat\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\[removed]\day of defeat\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\Valve\Steam\SteamApps\[removed]\counter-strike\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\[removed]\counter-strike\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App – (Microsoft Corporation)
"C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb – File not found
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray – File not found
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client – File not found
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – ()
"C:\Program Files\THQ\Dawn of War - Soulstorm Demo\Soulstorm.exe" = C:\Program Files\THQ\Dawn of War - Soulstorm Demo\Soulstorm.exe:*:Enabled:Soulstorm – File not found
"C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe" = C:\Program Files\THQ\Dawn of War - Soulstorm\Soulstorm.exe:*:Disabled:Soulstorm – (THQ Canada Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer – (Microsoft Corporation)
"C:\Program Files\Valve\Steam\SteamApps\common\warhammer 40,000 dawn of war ii - beta\DOW2.exe" = C:\Program Files\Valve\Steam\SteamApps\common\warhammer 40,000 dawn of war ii - beta\DOW2.exe:*:Enabled:DOW2 – (THQ Canada Inc.)
"C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe:*:Enabled:Dreamweaver MX – File not found
"C:\Program Files\Valve\Steam\SteamApps\[removed]\darwinia demo\darwinia.exe" = C:\Program Files\Valve\Steam\SteamApps\[removed]\darwinia demo\darwinia.exe:*:Enabled:Darwinia Demo – (Introversion Software)
"C:\Program Files\Valve\Steam\SteamApps\[removed]\half-life blue shift\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\[removed]\half-life blue shift\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\MATLAB\R2007b\bin\win32\MATLAB.exe" = C:\Program Files\MATLAB\R2007b\bin\win32\MATLAB.exe:*:Enabled:MATLAB – (The MathWorks Inc.)
"C:\Program Files\Kontiki\KService.exe" = C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service – (Kontiki Inc.)
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\TVAnts\Tvants.exe" = C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts – File not found
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\CAVEDOG\TOTALA\TotalA.exe" = C:\CAVEDOG\TOTALA\TotalA.exe:*:Enabled:Total Annihilation – (Cavedog Entertainment)
"C:\Zombina-Web\wamp\bin\apache\Apache2.2.11\bin\httpd.exe" = C:\Zombina-Web\wamp\bin\apache\Apache2.2.11\bin\httpd.exe:*:Enabled:Apache HTTP Server – (Apache Software Foundation)
"C:\Program Files\Google\Google SketchUp 7\SketchUp.exe" = C:\Program Files\Google\Google SketchUp 7\SketchUp.exe:*:Enabled:SketchUp Application – (Google, Inc.)
"C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" = C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe:LocalSubNet:Enabled:Wireless Manager – (Affinegy, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\Google\Google SketchUp 7\LayOut\LayOut.exe" = C:\Program Files\Google\Google SketchUp 7\LayOut\LayOut.exe:*:Enabled:LayOut – (Google, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Documents and Settings\All Users\Application Data\ASGvis\DRSpawner\DRSpawner.exe" = C:\Documents and Settings\All Users\Application Data\ASGvis\DRSpawner\DRSpawner.exe:*:Disabled:DRSpawner – ()
"C:\WINDOWS\system32\spoolsv.exe" = C:\WINDOWS\system32\spoolsv.exe:*:Enabled:spoolsv.exe – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam™
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}" = Microsoft Games for Windows - LIVE Redistributable
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0CB3C535-1171-4A20-B549-E2CB5DEB9723}" = MySQL Connector/ODBC 3.51
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14AFE241-FC6E-4FDB-BCA0-7AD6F4974171}" = Adobe Setup
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18063128-B9E1-AFAE-B7DD-2C313D2C375B}" = ccc-core-preinstall
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1C877DA0-5EFF-11D4-9254-0000F460E7A9}" = OpenMG Jukebox
"{20533183-D42D-4261-A125-956736FBEA8C}" = Dawn of War - Soulstorm
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24141F03-D9B2-D029-1C94-0BBA9977D173}" = Skins
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216016F0}" = Java™ 6 Update 16
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{2758691A-2CDE-4942-A4AC-0E8F61FE2067}" = USB Video Driver
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A425503-3D15-BE66-8781-3D153AF1F8A9}" = CCC Help English
"{2F97C024-5F00-11D4-9254-0000F460E7A9}" = OpenMG Jukebox Plug-in (Network Walkman(E))
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{362D5167-9716-44BE-89FD-BF9EB6EF814B}" = DawnOfWar
"{377F5472-544F-4055-A470-4EDA319BA1F3}" = V-Ray for SketchUp 7
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
"{3D347E6D-5A03-4342-B5BA-6A771885F379}" = Autodesk Backburner 2008.1
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{3EA0E0DD-4203-C20C-2740-582DFBF1CC59}" = BBC iPlayer Desktop
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{48F6195D-D72A-41DD-938E-DBF6D08AE282}" = MediaAudioCutter
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{505AFDC0-5E72-4928-8368-5DEA385E3647}" = CorelDRAW Graphics Suite 12
"{51AFB69C-1C54-4C77-A888-2860F8CD3E7D}" = Paint.NET v3.31
"{52C8CFE4-7C7C-11D7-A021-0060979CE4D3}" = Zoom ADSL Modem
"{5435FF3C-48CF-4B34-85E1-2C95673EB254}" = Dawn of War - Soulstorm
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{572FBF5D-3BAA-42FF-A468-A54C2C0A17C3}" = Autodesk Revit Architecture 2010
"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{662C42DE-1E03-4E9D-A968-E933FD3E7C18}" = Virtual Midi Controller Demo
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{68E733D9-1E1E-480C-AA30-D90DD6D432F9}" = V-Ray for SketchUp 7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774C9799-1FD5-4BB2-925D-54B97AE6A908}" = AVOne 3GP Video Converter
"{77FF5817-ABA9-1294-2D3D-A29F8FDA8BAD}" = ccc-core-static
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7E0AED65-CE72-3715-5FD0-A18C149B5BFF}" = Catalyst Control Center Graphics Full Existing
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{819E24AA-DB15-4BA8-8D76-92BDF710610B}" = Adobe Setup
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = MacromediaDreamweaver MX
"{8B7443F5-E141-42A0-AB61-ED2331AAD606}" = 4oD
"{8CE08C3C-8FF4-45D9-925E-4F3CE2D7FA7D}" = Adobe Setup
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{939D29FC-B82D-42A7-BB1E-8E3F121505CC}" = Autodesk Revit Structure 2010
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B97F3A0-993F-4453-BCA8-E0DAFBE57845}" = Theory Interactive
"{9BE2669E-2BD8-4164-A8B5-C904C864B403}" = WA Update v3.50 beta2
"{9C67CBD7-631C-0409-B00B-98B5DEB67C27}" = Autodesk 3ds Max Design 2010 32-bit
"{9C9785F3-26E3-4731-AD37-65044AE0A129}" = NinjaVideo Helper
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9DEE2DB4-D46C-E7CF-9465-802BD2077A0A}" = Catalyst Control Center Graphics Light
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A589DA26-51BD-475D-8C32-E19E34145842}" = Camtasia Studio 6
"{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}" = DiscAPI
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-2448-0000-705000000001}" = Adobe Reader Chinese Traditional Fonts
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD4E788B-B668-4C37-B277-C5AD52FF6299}" = V-Ray for SketchUp 7
"{C02EDE17-BC2E-4393-70BD-36185ABEBFF7}" = Catalyst Control Center Graphics Previews Common
"{C0467622-B130-4981-B9CE-34B94F8006D2}" = Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB5363FC-04F2-E3F2-78BD-A9A6DB63DB9E}" = ccc-utility
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CDE4CC8B-134B-421E-943C-90799E56F664}" = Dell Media Experience Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0CE053E-0E5E-4C12-9BAE-D0F36021E911}" = POV-Ray for Windows v3.62
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D3C2EF42-DE89-4BDD-9111-0A7C829B6AA3}" = Piranesi 5.1
"{D45EC259-4A19-4656-B588-C2C360DD18EA}" = Half-Life® 2
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{D76298C2-E532-4A11-BCFF-76F3F19DA84D}" = Network Walkman Driver
"{D9432306-513A-4695-977E-FC6AD9C3ED98}" = IDX Renditioner
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DD8408E9-9421-484F-979D-DB6361E3E828}" = Dawn Of War - Winter Assault
"{E1C256F5-58C6-44E9-939A-E1189C8126E2}" = Google SketchUp Pro 7
"{E31ABA95-B5A8-4373-AABF-BAC8CD34E217}" = V-Ray for SketchUp 7
"{E32D85B0-1B37-4192-81F1-46804EE760E3}" = One Click PDF
"{E3526223-E4B1-444D-8139-8A3D4499B8DF}" = Piranesi 2010 Pro
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EED50C97-C79E-4149-BD82-7C5A22437708}" = Adobe Setup
"{EEECE229-49F6-4851-A73A-99B058221F8C}" = RAPID
"{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}" = Pinnacle Instant DVD Recorder
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F7D689BA-E7DE-4727-9F8D-936B6C30A53A}" = Rapidshare Auto Downloader 3.6.2
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FC321AD2-48B4-4013-B997-A65D5FBBD006}" = NETGEAR Wireless Adapter WG311T
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FEC22238-FB7E-5D07-F88A-78F15460073A}" = Catalyst Control Center Graphics Full New
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"{FF39FC01-819B-42E4-AE49-1968AF12DDD4}" = Dawn of War - Dark Crusade
"{FFD06ACB-DF8B-D34D-9F9E-CDA18C15E208}" = Catalyst Control Center Core Implementation
"-1_0FVgGJK3x_P8" = LoudMo Contextual Ad Assistant
"2B0D8F3C-18AD-4D8E-879A-74A867C5C3CB_is1" = Wireless Manager
"4oD" = 4oD
"69083DC58646DE46A09847A522A1CC487F918039" = Windows Driver Package - eMPIA Technology Inc, (emAudio) MEDIA (08/31/2007 5.7.0831.0)
"9722CA1E8F72F362E93CBEC75A707FDABFC8D880" = Windows Driver Package - Advanced Micro Devices, Inc. (USB28xxBGA) Media (08/31/2007 5.7.0831.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Adobe_2a31ae7a5c43ff52d8577782dd34e04" = Adobe Illustrator CS4
"Adobe_6e02d32c7e5a9d9fc86bc91618cafda" = Adobe Premiere Pro CS4 Third Party Content
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Adobe_a68eec966ce913ddaa63251dc82ed31" = Adobe Flash CS4 Professional
"Adobe_acce07fd2c8fe7f9e3f26243e626578" = Adobe Dreamweaver CS4
"All ATI Software" = ATI - Software Uninstall Utility
"AoA Audio Extractor_is1" = AoA Audio Extractor 1.0
"ATI Display Driver" = ATI Display Driver
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.7 (Unicode)
"AudibleDownloadManager" = Audible Download Manager
"AutoCAD 2009 - English" = AutoCAD 2009 - English
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Autodesk FBX Plugin 2009.4 - 3ds Max Design 2010" = Autodesk FBX Plugin 2009.4 - 3ds Max Design 2010
"Autodesk Revit Architecture 2010" = Autodesk Revit Architecture 2010
"Autodesk Revit Structure 2010" = Autodesk Revit Structure 2010
"BitComet" = BitComet 0.96
"BitTorrent" = BitTorrent 4.0.4
"CCleaner" = CCleaner
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DellSupport" = Dell Support 5.0.0 (630)
"Digital Camera Driver" = Digital Camera Driver
"Easy MP3 Alarm Clock_is1" = Easy MP3 Alarm Clock 1.0
"EPANET 2.0" = EPANET 2.0
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Foxie Privacy, Security & Productivity Suite" = Foxie Privacy, Security & Productivity Suite 1.1.2
"Guitar Pro 5_is1" = Guitar Pro 5.0
"Hollywood FX for Studio" = Pinnacle Hollywood FX for Studio
"Hospital" = Theme Hospital
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{362D5167-9716-44BE-89FD-BF9EB6EF814B}" = DawnOfWar
"InstallShield_{FC321AD2-48B4-4013-B997-A65D5FBBD006}" = NETGEAR Wireless Adapter WG311T
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"IsoBuster_is1" = IsoBuster 1.8
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.7 (Standard)
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LimeWire" = LimeWire PRO 4.9.37
"LiveReg" = LiveReg (Symantec Corporation)
"MatlabR2007b" = MATLAB R2007b
"MetaFrame Presentation Server Web Client for Win32" = MetaFrame Presentation Server Web Client for Win32
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MS-MPEG4" = Microsoft MPEG-4 VKI Video Codec V1/V2/V3
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NetObjects Fusion Essentials" = NetObjects Fusion Essentials
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notepad++" = Notepad++
"PartyPoker" = PartyPoker
"Power Audio Recorder_is1" = Power Audio Recorder 1.72
"PowerISO" = PowerISO
"PROSet" = Intel® PRO Network Connections Drivers
"RAR Password Cracker" = RAR Password Cracker 4.12
"RealPlayer 6.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.89
"Sibelius v3.1" = Sibelius v3.1
"Skype_is1" = Skype 2.5
"Spotify" = Spotify
"ST5UNST #1" = Annihilator
"Steam App 15660" = Warhammer 40,000: Dawn of War II - Beta
"SUPER ©" = SUPER © Version 1.791
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Total Annihilation" = Total Annihilation
"Total Annihilation - Battle Tactics" = Total Annihilation - Battle Tactics
"Total Annihilation - Core Contingency" = Total Annihilation - Core Contingency
"TRUST 120 SPACEC@M" = TRUST 120 SPACEC@M
"TVAnts 1.0" = TVAnts 1.0
"Uninstall_is1" = Uninstall 1.0.0.0
"Video Chat Timer & Capture" = Video Chat Timer & Capture
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.4a
"WampServer 2_is1" = WampServer 2.0
"WavePad" = WavePad Uninstall
"WIC" = Windows Imaging Component
"Win Antivirus Pro" = Windows Antivirus Pro
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Worms Armageddon" = Worms Armageddon
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Zoom ADSL Modem" = Zoom ADSL Modem

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"5f48e2ab41c5d005" = RapidShare Manager
"Google Chrome" = Google Chrome
"oDVT" = oDesk Team
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 20/06/2010 22:03:15 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application totala.exe, version 3.1.0.0, faulting module
ddraw.dll, version 0.8.4.0, fault address 0x0000929e.

Error - 20/06/2010 22:09:56 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application totala.exe, version 3.1.0.0, faulting module
ddraw.dll, version 0.8.4.0, fault address 0x0000929e.

Error - 23/06/2010 13:02:56 | Computer Name = CHRIS | Source = Google Update | ID = 20
Description =

Error - 23/06/2010 13:09:18 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 15:41:05 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application totala.exe, version 3.1.0.0, faulting module
ddraw.dll, version 0.8.4.0, fault address 0x0000929e.

Error - 30/06/2010 20:57:38 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application spybotsd162.tmp, version 51.49.0.0, faulting
module ntdll.dll, version 5.1.2600.3520, fault address 0x00018af2.

Error - 30/06/2010 21:11:03 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application cwshredder.exe, version 2.19.0.1099, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 21:11:06 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application cwshredder.exe, version 2.19.0.1099, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 21:13:20 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application spybotsd162.tmp, version 51.49.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 22:19:07 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application SketchUp.exe, version 7.0.10247.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ Application Events ]
Error - 20/06/2010 22:03:15 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application totala.exe, version 3.1.0.0, faulting module
ddraw.dll, version 0.8.4.0, fault address 0x0000929e.

Error - 20/06/2010 22:09:56 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application totala.exe, version 3.1.0.0, faulting module
ddraw.dll, version 0.8.4.0, fault address 0x0000929e.

Error - 23/06/2010 13:02:56 | Computer Name = CHRIS | Source = Google Update | ID = 20
Description =

Error - 23/06/2010 13:09:18 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 15:41:05 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application totala.exe, version 3.1.0.0, faulting module
ddraw.dll, version 0.8.4.0, fault address 0x0000929e.

Error - 30/06/2010 20:57:38 | Computer Name = CHRIS | Source = Application Error | ID = 1000
Description = Faulting application spybotsd162.tmp, version 51.49.0.0, faulting
module ntdll.dll, version 5.1.2600.3520, fault address 0x00018af2.

Error - 30/06/2010 21:11:03 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application cwshredder.exe, version 2.19.0.1099, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 21:11:06 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application cwshredder.exe, version 2.19.0.1099, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 21:13:20 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application spybotsd162.tmp, version 51.49.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 30/06/2010 22:19:07 | Computer Name = CHRIS | Source = Application Hang | ID = 1002
Description = Hanging application SketchUp.exe, version 7.0.10247.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 30/06/2010 17:09:28 | Computer Name = CHRIS | Source = Service Control Manager | ID = 7000
Description = The AntipyPro_12 service failed to start due to the following error:
%%3

Error - 30/06/2010 17:09:29 | Computer Name = CHRIS | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Remote Packet Capture
Protocol v.0 (experimental) service to connect.

Error - 30/06/2010 17:09:29 | Computer Name = CHRIS | Source = Service Control Manager | ID = 7000
Description = The Remote Packet Capture Protocol v.0 (experimental) service failed
to start due to the following error: %%1053

Error - 30/06/2010 17:39:37 | Computer Name = CHRIS | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.1.2
with the system having network hardware address F8:1E:DF:A7:62:11. Network operations
on this system may be disrupted as a result.

Error - 30/06/2010 20:22:14 | Computer Name = CHRIS | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 30/06/2010 21:46:16 | Computer Name = CHRIS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 30/06/2010 21:46:18 | Computer Name = CHRIS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 30/06/2010 21:46:21 | Computer Name = CHRIS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 30/06/2010 21:46:23 | Computer Name = CHRIS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 02/07/2010 20:22:15 | Computer Name = CHRIS | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >













































3.0 OTL.txt


OTL logfile created on: 03/07/2010 13:25:16 - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Chris Speck\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
7.00 Gb Paging File | 7.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 4605 4605 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.95 Gb Total Space | 8.34 Gb Free Space | 5.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 359.14 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRIS
Current User Name: Chris Speck
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Chris Speck\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Spotify\spotify.exe (Spotify Ltd)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Zombina-Web\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe ()
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
PRC - C:\Zombina-Web\wamp\bin\apache\Apache2.2.11\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe (Affinegy, Inc.)
PRC - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe (Affinegy, Inc.)
PRC - C:\Program Files\Virgin Broadband Wireless\wpa_supplicant.exe ()
PRC - C:\Program Files\Virgin Broadband Wireless\ndis_events.exe ()
PRC - C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe (NinjaVideo)
PRC - C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Zombina-Web\wamp\wampmanager.exe (Aestan Software)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\M-Audio\Install\EvoInst.exe ()
PRC - C:\Program Files\NETGEAR\WG311T\wlancfg5.exe ()
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\vsnpstd.exe ()
PRC - C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe (Dominating Bytes Design)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Chris Speck\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\AppPatch\AcGenral.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msacm32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SAVScan) – File not found
SRV - (AntipPro2009_12) – File not found
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (wampmysqld) – C:\Zombina-Web\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe ()
SRV - (mi-raysat_3dsmax2010_32) – C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
SRV - (wampapache) – C:\Zombina-Web\wamp\bin\apache\apache2.2.11\bin\httpd.exe (Apache Software Foundation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Autodesk Network Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe (Autodesk, Inc.)
SRV - (AffinegyService) – C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe (Affinegy, Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (NinjaVideo Helper.exe) – C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe (NinjaVideo)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (KService) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (EvoInstallerService) – C:\Program Files\M-Audio\Install\EvoInst.exe ()
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SCDEmu) – C:\WINDOWS\system32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (AFGSp50) – C:\WINDOWS\system32\drivers\AFGSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (ASAPIW2K) – C:\WINDOWS\system32\drivers\asapiW2k.sys (VOB Computersysteme GmbH)
DRV - (PCLEPCI) – C:\WINDOWS\system32\drivers\Pclepci.sys (Pinnacle Systems GmbH)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\WG311T13.sys (Atheros Communications, Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (EVOLUSB) – C:\WINDOWS\system32\drivers\evolusb.sys (Evolution Electronics Ltd.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (snpstd) – C:\WINDOWS\system32\drivers\snpstd.sys ()
DRV - (NWWMUSB) Sony Network Walkman (E) – C:\WINDOWS\system32\drivers\nwwmusb.sys (Sony Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iamwired.net/websearch.php?src=tops&search;="
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.5
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {79047c68-4b92-06c8-3821-3ce9bc34886a}:[removed]
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.3
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/10/02 14:53:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010/05/16 20:05:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/01 21:08:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/26 06:27:30 | 000,000,000 | —D | M]

[2009/12/07 20:13:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Extensions
[2009/12/07 20:13:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/10/06 01:25:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions
[2009/12/07 20:13:57 | 000,000,000 | —D | M] (FlashGot) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009/10/03 23:51:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/08 21:26:21 | 000,000,000 | —D | M] (Clear Cache Button) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{563e4790-7e70-11da-a72b-0800200c9a66}
[2009/12/07 20:13:56 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/08/03 04:25:47 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2008/06/09 02:04:03 | 000,001,504 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\imdb.xml
[2010/05/15 18:10:19 | 000,000,266 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\Search.xml
[2008/06/09 02:04:16 | 000,000,705 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\webster.xml
[2008/06/09 02:04:25 | 000,001,032 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\wikipedia-eng.xml
[2010/05/15 00:21:25 | 000,002,057 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\youtube-video-search.xml
[2010/10/06 01:25:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/15 18:10:32 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{79047c68-4b92-06c8-3821-3ce9bc34886a}
[2010/05/01 18:19:43 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/10 20:02:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/05/08 01:12:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2010/05/16 20:14:55 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2010/05/16 20:06:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/04/01 19:00:33 | 000,023,000 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/04/01 19:00:33 | 000,138,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2008/08/16 18:42:36 | 000,013,112 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\cgpcfg.dll
[2008/08/16 18:42:02 | 000,070,456 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 18:42:12 | 000,091,448 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 18:42:08 | 000,020,800 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/08/16 18:43:00 | 000,206,136 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\ctxmui.dll
[2008/08/16 18:42:10 | 000,031,032 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\icafile.dll
[2008/08/16 18:42:32 | 000,040,248 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\icalogon.dll
[2007/06/21 18:39:18 | 000,034,376 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\logging.dll
[2008/05/21 09:41:08 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 09:41:08 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 09:41:08 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2009/01/16 20:17:04 | 000,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
[2010/05/16 20:05:39 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2008/11/06 17:33:48 | 001,332,224 | —- | M] (DivX,Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdivx32.dll
[2008/08/16 18:44:46 | 000,427,312 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2010/04/01 19:00:33 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009/12/21 18:34:06 | 000,103,864 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2010/01/04 00:28:32 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2008/06/05 14:58:54 | 000,648,504 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\sslsdk_b.dll
[2008/08/16 18:42:04 | 000,023,864 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2010/04/01 17:56:49 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 17:56:49 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/05/26 01:39:30 | 000,001,345 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\avg_igeared.xml
[2010/04/01 17:56:50 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 17:56:50 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/04/01 17:56:50 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 17:56:50 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/04/01 17:56:50 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/04/01 17:56:50 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/07/01 02:14:52 | 000,347,753 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 11920 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar BHO) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll (BitComet)
O2 - BHO: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - No CLSID value found.
O2 - BHO: (FoxieToolbar Class) - {432CAE3B-690F-4C3B-BD97-070EBDA210D5} - C:\Program Files\Foxie Suite\foxietoolbaru.dll (Team Foxie)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O2 - BHO: (FoxieSecurityModule Class) - {C65185B1-D52B-44A9-861F-8201B50D1F37} - C:\Program Files\Foxie Suite\foxiecoreu.dll (Team Foxie)
O2 - BHO: (no name) - {d2aebbd0-2d7d-ec6b-98af-874c3e0f3537} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Foxie) - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll (Team Foxie)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Wireless Manager] C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe (Affinegy, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKCU..\Run: [Steam] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm ()
O9 - Extra 'Tools' menuitem : Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm ()
O9 - Extra Button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll (BitComet)
O9 - Extra Button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe (Team Foxie)
O9 - Extra 'Tools' menuitem : Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe (Team Foxie)
O9 - Extra Button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe (Team Foxie)
O9 - Extra 'Tools' menuitem : Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe (Team Foxie)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm ()
O9 - Extra 'Tools' menuitem : The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: line6.net ([]* in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {2991BC79-8959-3D13-A77D-64AC10B82334} http://85.255.113.214/1/gdnFR2218.exe (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://workhardplayhard1.spaces.msn.com//P…ad/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} http://secure2.comned.com/signuptemplates/…login-devel.cab (SecureLogin class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab (MSN File Upload Control)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.165.169,93.188.161.191
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\WINDOWS\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/02 21:47:06 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\Shell\Auto\command - "" = F:\Windows.scr – File not found
O33 - MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{173fa3d3-7227-11de-86b0-00123fa8a129}\Shell\AutoRun\command - "" = windows69.exe
O33 - MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\Shell\Auto\command - "" = I:\Windows.scr – File not found
O33 - MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\Shell - "" = AutoRun
O33 - MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\Shell\Auto\command - "" = J:\Windows.scr – File not found
O33 - MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\Shell\Auto\command - "" = I:\Windows.scr – File not found
O33 - MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\Shell\Auto\command - "" = Windows.scr
O33 - MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (76574804416659456)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/03 19:46:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Temp
[2010/07/03 13:20:58 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Chris Speck\Desktop\OTL.exe
[2010/07/03 03:04:54 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Chris Speck\Desktop\HiJackThis.exe
[2010/07/03 02:25:11 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Chris Speck\Recent
[2010/07/01 02:57:14 | 000,000,000 | —D | C] – C:\Program Files\AutoCAD 2009
[2010/07/01 02:55:42 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/07/01 02:22:37 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/07/01 02:21:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Application Data\Yahoo!
[2010/07/01 02:21:12 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2010/07/01 02:21:03 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/06/08 16:05:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\My Documents\Job's
[2010/06/06 22:51:46 | 000,095,232 | —- | C] (The Center for Weird Studies) – C:\WINDOWS\System32\HPIUTIL.DLL
[2010/06/06 22:51:45 | 000,000,000 | —D | C] – C:\Program Files\Annihilator
[2010/06/06 14:59:25 | 000,000,000 | —D | C] – C:\Program Files\oDesk
[2010/06/06 14:59:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\oDesk
[2005/11/27 00:18:39 | 000,057,344 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd.dll
[2005/11/27 00:18:39 | 000,036,864 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/06 02:51:00 | 000,001,000 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006UA.job
[2010/10/05 04:32:14 | 002,398,672 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/04 19:51:00 | 000,000,948 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006Core.job
[2010/07/03 13:28:00 | 000,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2010/07/03 13:27:00 | 000,000,300 | -H– | M] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/07/03 13:20:59 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Chris Speck\Desktop\OTL.exe
[2010/07/03 03:16:55 | 000,359,929 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\dds.scr
[2010/07/03 03:04:55 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Chris Speck\Desktop\HiJackThis.exe
[2010/07/01 15:27:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/01 03:28:14 | 000,117,808 | —- | M] () – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/01 03:23:32 | 025,165,824 | -H– | M] () – C:\Documents and Settings\Chris Speck\NTUSER.DAT
[2010/07/01 03:21:55 | 000,001,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AutoCAD 2009.lnk
[2010/07/01 02:22:37 | 000,000,917 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\Revo Uninstaller.lnk
[2010/07/01 02:21:05 | 000,000,682 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\CCleaner.lnk
[2010/07/01 02:14:52 | 000,347,753 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/30 22:11:10 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/30 22:08:13 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/30 22:07:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/30 22:07:34 | 3219,279,872 | -HS- | M] () – C:\hiberfil.sys
[2010/06/30 20:04:56 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/28 23:20:00 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\AVG Free Control Center.job
[2010/06/28 18:21:11 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Chris Speck\ntuser.ini
[2010/06/25 18:10:03 | 003,710,182 | -H– | M] () – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\IconCache.db
[2010/06/23 18:12:13 | 000,002,308 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/06/23 18:12:12 | 000,002,330 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\Google Chrome.lnk
[2010/06/16 18:20:36 | 000,001,911 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Style Builder.lnk
[2010/06/16 18:20:36 | 000,001,825 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LayOut 2.lnk
[2010/06/16 18:20:36 | 000,001,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google SketchUp 7.lnk
[2010/06/15 23:49:03 | 000,000,484 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\MSN.lnk
[2010/06/09 23:26:21 | 000,000,792 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/06/08 02:51:36 | 024,147,192 | —- | M] () – C:\Documents and Settings\Chris Speck\My Documents\AutoSave_Untitled_1.skp
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/03 19:50:30 | 000,002,330 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\Google Chrome.lnk
[2010/10/03 19:50:30 | 000,002,308 | —- | C] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/03 19:46:08 | 000,001,000 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006UA.job
[2010/10/03 19:46:07 | 000,000,948 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006Core.job
[2010/07/03 03:11:04 | 000,359,929 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\dds.scr
[2010/07/01 03:21:55 | 000,001,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AutoCAD 2009.lnk
[2010/07/01 02:22:37 | 000,000,917 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\Revo Uninstaller.lnk
[2010/07/01 02:21:05 | 000,000,682 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\CCleaner.lnk
[2010/06/15 23:45:47 | 000,000,484 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\MSN.lnk
[2010/06/09 23:26:21 | 000,000,792 | —- | C] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/06/08 02:51:27 | 024,147,192 | —- | C] () – C:\Documents and Settings\Chris Speck\My Documents\AutoSave_Untitled_1.skp
[2010/06/06 22:51:46 | 000,050,176 | —- | C] () – C:\WINDOWS\System32\annihilator.dll
[2009/12/05 21:32:43 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/09/29 18:07:07 | 000,000,049 | —- | C] () – C:\WINDOWS\bsm.ini
[2009/08/07 14:08:55 | 000,488,448 | —- | C] () – C:\WINDOWS\System32\apdfprintmon.dll
[2009/06/21 03:09:45 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/05/14 01:38:31 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/22 00:19:06 | 000,172,173 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2008/09/02 16:54:16 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/09/02 16:54:16 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/09/02 01:26:07 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/09/02 01:26:06 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/05/17 13:47:07 | 000,000,355 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/02/27 01:45:25 | 000,017,403 | —- | C] () – C:\WINDOWS\wwdslcfg.ini
[2007/12/14 22:30:41 | 000,000,035 | —- | C] () – C:\WINDOWS\A6W.INI
[2007/05/19 20:13:23 | 000,000,126 | —- | C] () – C:\WINDOWS\_delis43.ini
[2006/11/17 23:55:30 | 000,000,394 | —- | C] () – C:\WINDOWS\capture.ini
[2006/01/02 21:55:15 | 000,194,248 | —- | C] () – C:\WINDOWS\System32\LTRFD13n.DLL
[2006/01/02 21:47:06 | 000,001,194 | —- | C] () – C:\WINDOWS\VFO.INI
[2006/01/02 21:47:01 | 000,196,096 | —- | C] () – C:\WINDOWS\System32\macd32.dll
[2006/01/02 21:47:01 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2006/01/02 21:47:01 | 000,136,192 | —- | C] () – C:\WINDOWS\System32\mamc32.dll
[2006/01/02 21:47:01 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\masd32.dll
[2006/01/02 21:47:01 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/01/02 20:52:46 | 000,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2005/12/28 16:05:27 | 000,000,000 | —- | C] () – C:\WINDOWS\WinPM.INI
[2005/12/27 21:04:57 | 003,870,720 | —- | C] () – C:\WINDOWS\System32\qt-mt323.dll
[2005/11/27 00:18:40 | 000,299,776 | —- | C] () – C:\WINDOWS\System32\drivers\snpstd.sys
[2005/11/27 00:18:39 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\dsnpstd.dll
[2005/11/27 00:18:39 | 000,015,541 | —- | C] () – C:\WINDOWS\snpstd.ini
[2005/11/21 20:27:30 | 000,262,416 | —- | C] () – C:\WINDOWS\System32\Asfv2.dll
[2005/11/21 20:27:29 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\TDI-SonyOMG.dll
[2005/11/18 20:42:12 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/11/18 15:59:52 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/18 15:08:28 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/15 15:25:10 | 000,000,067 | —- | C] () – C:\WINDOWS\#1 Video Converter.INI
[2005/11/15 14:11:17 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2005/11/15 14:11:17 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2005/11/15 14:11:17 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2005/11/15 14:11:17 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2005/11/10 20:17:09 | 000,000,155 | —- | C] () – C:\WINDOWS\CDPLAYER.INI
[2005/11/02 18:52:07 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/10/27 20:05:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/27 19:57:19 | 000,001,731 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/10/27 19:30:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/09 23:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/29 19:38:24 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2005/07/14 13:31:20 | 000,027,648 | RHS- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2005/06/21 23:37:42 | 000,062,464 | RHS- | C] () – C:\WINDOWS\System32\cygz.dll
[2005/04/09 17:04:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/12/20 19:24:03 | 001,663,068 | —- | C] () – C:\WINDOWS\System32\libmmd.dll
[2004/08/10 13:12:05 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/07/11 23:32:17 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MP3IFilter.dll

========== LOP Check ==========

[2009/08/07 14:10:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A-PDF
[2009/12/05 21:32:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Affinegy
[2010/02/07 17:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ASGvis
[2010/07/01 02:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/10/25 16:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2010/06/30 17:59:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/03/09 23:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2009/09/10 21:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2010/05/26 20:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Informatix
[2010/07/03 13:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/25 21:13:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Line 6
[2006/01/02 22:05:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2006/01/02 21:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2010/05/27 10:49:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/07/02 02:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/30 02:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/01/04 00:33:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2006/02/12 01:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\.BitTornado
[2005/11/03 04:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\.bittorrent
[2010/06/30 22:11:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Affinegy
[2009/10/20 03:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Audacity
[2010/07/01 02:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Autodesk
[2010/05/28 01:28:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\AVG9
[2009/07/29 02:15:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/01/31 22:08:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\com.adobe.ExMan
[2007/04/23 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Command & Conquer 3 Tiberium Wars
[2008/04/07 03:44:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\DMCache
[2008/11/30 19:43:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\EPANET
[2009/06/21 03:08:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Focus Mp3 Recorder
[2008/09/30 10:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\foobar2000
[2006/06/26 01:45:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\FoxieSpywareSwiftSweeper
[2008/04/10 18:37:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\ICAClient
[2008/04/07 03:47:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\IDM
[2010/05/27 17:57:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Informatix
[2005/11/02 18:54:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Leadertech
[2008/12/06 20:11:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Line 6
[2006/01/12 17:30:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\NCH Swift Sound
[2009/10/15 04:25:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Notepad++
[2006/03/13 15:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Seven Zip
[2010/07/03 12:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Spotify
[2006/01/25 17:02:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\uTorrent
[2008/09/30 02:46:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Viewpoint
[2010/06/28 23:20:00 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\AVG Free Control Center.job
[2010/07/03 13:27:00 | 000,000,300 | -H– | M] () – C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/10/25 05:59:57 | 000,071,878 | —- | M] () – C:\acadminidump.dmp
[2006/01/02 21:47:06 | 000,000,095 | —- | M] () – C:\AUTOEXEC.BAT
[2005/11/15 14:13:27 | 000,007,741 | —- | M] () – C:\avi_log.txt
[2009/01/18 16:47:05 | 000,000,212 | RHS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/11/29 20:54:24 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2005/11/03 00:57:36 | 000,003,499 | —- | M] () – C:\data
[2005/10/27 19:33:46 | 000,004,943 | RH– | M] () – C:\dell.sdr
[2010/06/30 22:07:34 | 3219,279,872 | -HS- | M] () – C:\hiberfil.sys
[2005/11/02 20:58:55 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/10/27 19:54:16 | 000,000,896 | -H– | M] () – C:\IPH.PH
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 05:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2009/02/05 21:47:35 | 000,000,000 | —- | M] () – C:\out.txt
[2010/06/30 22:07:13 | 533,725,183 | -HS- | M] () – C:\pagefile.sys
[2009/12/06 03:24:20 | 000,000,022 | —- | M] () – C:\Program1
[2010/06/10 01:52:33 | 000,000,000 | —- | M] () – C:\randombbbbbbbbb.txt
[2008/02/22 21:07:35 | 000,000,129 | —- | M] () – C:\Shortcut to 3½ Floppy (A).lnk
[2010/01/12 22:44:33 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/15 02:02:19 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/01/15 17:32:49 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/01/16 19:14:09 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/01/18 19:41:10 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/01/19 18:19:40 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/01/22 21:28:25 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/01/19 19:53:34 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/01/22 21:47:18 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2010/01/23 13:02:40 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2010/01/23 13:49:21 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2010/01/24 17:20:10 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/01/26 08:53:30 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/01/26 11:39:53 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2010/01/27 14:33:25 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/01/28 01:01:34 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2010/01/28 18:19:41 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/01/28 18:42:27 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/01/28 19:54:00 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/01/30 21:11:28 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2010/01/12 22:44:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/15 02:02:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/01/15 17:32:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/01/16 19:14:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/01/18 19:41:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/01/19 18:19:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/01/22 21:28:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/01/19 19:53:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/01/22 21:47:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/01/23 13:02:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/01/23 13:49:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/01/24 17:20:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/01/26 08:53:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/01/26 11:39:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/01/27 14:33:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/01/28 01:01:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/01/28 18:19:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/01/28 18:42:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/01/28 19:53:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/01/30 21:11:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2005/10/31 16:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2007/03/15 02:58:38 | 000,315,392 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\WINDOWS\system32\ATIDEMGX.dll
[2010/03/09 12:09:18 | 000,430,080 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\vbscript.dll
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 16:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\system32\user32.dll
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 05:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 05:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-05-28 23:31:59

========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:16E029F0
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:46E7580F
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4295826C
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >
Hello,

I have a feeling that GMER gave you so many problems running because you have a CD Emulation program installed. I'm going to have you run a OTL fix first followed by running downloading and running a program to disable your CD Emulation driver for the tme being, so that it doesn't interfere with any of our other tools.


OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    SRV - (SAVScan) – File not found
    SRV - (AntipPro2009_12) – File not found
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
    O2 - BHO: (no name) - {d2aebbd0-2d7d-ec6b-98af-874c3e0f3537} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O4 - HKCU..\Run: [Steam] File not found
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
    O15 - HKCU\..Trusted Domains: line6.net ([]* in Trusted sites)
    O16 - DPF: {2991BC79-8959-3D13-A77D-64AC10B82334} http://85.255.113.214/1/gdnFR2218.exe (Reg Error: Key error.)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.165.169,93.188.161.191
    O18 - Protocol\Handler\ipp - No CLSID value found
    O18 - Protocol\Handler\msdaipp - No CLSID value found
    O33 - MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\Shell\Auto\command - "" = F:\Windows.scr – File not found
    O33 - MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
    O33 - MountPoints2\{173fa3d3-7227-11de-86b0-00123fa8a129}\Shell\AutoRun\command - "" = windows69.exe
    O33 - MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\Shell\Auto\command - "" = I:\Windows.scr – File not found
    O33 - MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
    O33 - MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\Shell - "" = AutoRun
    O33 - MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\Shell\Auto\command - "" = J:\Windows.scr – File not found
    O33 - MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
    O33 - MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\Shell\Auto\command - "" = I:\Windows.scr – File not found
    O33 - MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
    O33 - MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\Shell\Auto\command - "" = Windows.scr
    O33 - MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/07/03 14:03:29 | 008,460,800 | —- | M] (Microsoft Corporation)
    [2010/07/03 13:27:00 | 000,000,300 | -H– | M] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
    [2005/10/31 16:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
    @Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:16E029F0
    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:46E7580F
    @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4295826C
    @Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
    :Files
    flushdns /c
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



The program below should hopefully give you less problems running GMER.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

If GMER still won't run for you in Normal Mode then please try running it in Safe Mode.


Entering Safe Mode

  • Restart your computer.
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll to Safe Mode
  • Then press the Enter Key on your Keyboard
  • Go into your usual account
Hello, sorry for my late reply. Im still having a few problems with GMER, uncked devices and ran defogger but when i came to my pc this morning it had crashed again. Will try putting it in safe mode tonight.

Heres my log from OTL with the new custome fix

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Error: No service named SAVScan was found to stop!
Service\Driver key SAVScan not found.
File File not found not found.
Service AntipPro2009_12 stopped successfully!
Service\Driver key AntipPro2009_12 not found.
File File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4322A444-92F8-4C3E-BD4C-013BA51E2871}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4322A444-92F8-4C3E-BD4C-013BA51E2871}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF3E430-B101-42AD-A544-FADC6B084872}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2aebbd0-2d7d-ec6b-98af-874c3e0f3537}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2aebbd0-2d7d-ec6b-98af-874c3e0f3537}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4322A444-92F8-4C3E-BD4C-013BA51E2871} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4322A444-92F8-4C3E-BD4C-013BA51E2871}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Steam not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\line6.net\ not found.
Starting removal of ActiveX control {2991BC79-8959-3D13-A77D-64AC10B82334}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2991BC79-8959-3D13-A77D-64AC10B82334}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2991BC79-8959-3D13-A77D-64AC10B82334}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\ not found.
File Protocol\Handler\ipp - No CLSID value found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ not found.
File Protocol\Handler\msdaipp - No CLSID value found not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{021e651b-e083-11dc-8558-00123fa8a129}\ not found.
File F:\Windows.scr not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{021e651b-e083-11dc-8558-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{021e651b-e083-11dc-8558-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{021e651b-e083-11dc-8558-00123fa8a129}\ not found.
C:\WINDOWS\system32\shell32.dll moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{173fa3d3-7227-11de-86b0-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{173fa3d3-7227-11de-86b0-00123fa8a129}\ not found.
File windows69.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3fd7b456-1ce5-11df-8748-00123fa8a129}\ not found.
File I:\Windows.scr not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3fd7b456-1ce5-11df-8748-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3fd7b456-1ce5-11df-8748-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3fd7b456-1ce5-11df-8748-00123fa8a129}\ not found.
File C:\WINDOWS\System32\shell32.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e14c918-fd5a-11dd-8667-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e14c918-fd5a-11dd-8667-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e14c918-fd5a-11dd-8667-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e14c918-fd5a-11dd-8667-00123fa8a129}\ not found.
File F:\LaunchU3.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8f334662-dacf-11de-8700-00123fa8a129}\ not found.
File J:\Windows.scr not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8f334662-dacf-11de-8700-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8f334662-dacf-11de-8700-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8f334662-dacf-11de-8700-00123fa8a129}\ not found.
File C:\WINDOWS\System32\shell32.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\ not found.
File I:\Windows.scr not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d9523b0f-a1eb-11de-86d7-00123fa8a129}\ not found.
File C:\WINDOWS\System32\shell32.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f2c64c38-a90d-11db-8443-00123fa8a129}\ not found.
File Windows.scr not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f2c64c38-a90d-11db-8443-00123fa8a129}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c64c38-a90d-11db-8443-00123fa8a129}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f2c64c38-a90d-11db-8443-00123fa8a129}\ not found.
File C:\WINDOWS\System32\shell32.dll not found.
File C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job not found.
File C:\StubInstaller.exe not found.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:16E029F0 .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:46E7580F .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:4295826C .
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD .
========== FILES ==========
< flushdns /c >
C:\Documents and Settings\Chris Speck\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Chris Speck\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Chris Speck
->Temp folder emptied: 382519 bytes
->Temporary Internet Files folder emptied: 879368 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 37959968 bytes
->Google Chrome cache emptied: 7345688 bytes
->Flash cache emptied: 6629 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 664 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 255802 bytes

Total Files Cleaned = 45.00 mb


[EMPTYFLASH]

User: All Users

User: Chris Speck
->Flash cache emptied: 0 bytes

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.7.0 log created on 07072010_185415

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Hello,

Okay. If GMER still gives you issues in Safe Mode, then post back and we will figure something else out.

I'd also like to see a new OTL scan. But before you scan your computer with OTL, I'm going to ask that you delete the current copy that you have on your desktop, by right clicking on the OTL file and selecting Delete. We will download a fresh copy. I'll include the relevant download link below, as well as some fresh instructions for the scan. :)

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello kind of getting worried, problem seems to have got worse, keep seeing this program Stubob.exe in my process tab. I have no idea what this is, its just appeared recently, seems to use a lot of memory.To make things worse I don't have any virus software installed on my pc, what ever problem the browser redirect issue is,it seems to stop the software from connecting to an update server.

Cheers
heres the otl txt, running GMER next.
2. OTL txt

OTL logfile created on: 09/07/2010 03:35:12 - Run 2
OTL by OldTimer - Version 3.2.8.1 Folder = C:\Documents and Settings\Chris Speck\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
7.00 Gb Paging File | 7.00 Gb Available in Paging File | 95.00% Paging File free
Paging file location(s): C:\pagefile.sys 4605 4605 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.95 Gb Total Space | 6.78 Gb Free Space | 4.65% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRIS
Current User Name: Chris Speck
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Chris Speck\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\msdb.exe ()
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe (Affinegy, Inc.)
PRC - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe (Affinegy, Inc.)
PRC - C:\Program Files\Virgin Broadband Wireless\ndis_events.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\M-Audio\Install\EvoInst.exe ()
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\vsnpstd.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Chris Speck\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\AppPatch\AcGenral.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msacm32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe ()
SRV - (mi-raysat_3dsmax2010_32) – C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe (Apache Software Foundation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Autodesk Network Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe (Autodesk, Inc.)
SRV - (AffinegyService) – C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe (Affinegy, Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (NinjaVideo Helper.exe) – C:\Program Files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe (NinjaVideo)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (KService) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (EvoInstallerService) – C:\Program Files\M-Audio\Install\EvoInst.exe ()
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (scrcap) – C:\WINDOWS\System32\DRIVERS\scrcap.sys File not found
DRV - (L6TPortGX) – C:\WINDOWS\System32\Drivers\L6TPortGX.sys File not found
DRV - (kahjebpu) – C:\WINDOWS\System32\drivers\kahjebpu.sys File not found
DRV - (dtscsi) – C:\WINDOWS\System32\Drivers\dtscsi.sys File not found
DRV - (cusbohcn) – C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\cusbohcn.sys File not found
DRV - (AFGMp50) – C:\WINDOWS\System32\Drivers\AFGMp50.sys File not found
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (AFGSp50) – C:\WINDOWS\system32\drivers\AFGSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (ASAPIW2K) – C:\WINDOWS\system32\drivers\asapiW2k.sys (VOB Computersysteme GmbH)
DRV - (PCLEPCI) – C:\WINDOWS\system32\drivers\Pclepci.sys (Pinnacle Systems GmbH)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\WG311T13.sys (Atheros Communications, Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (EVOLUSB) – C:\WINDOWS\system32\drivers\evolusb.sys (Evolution Electronics Ltd.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (snpstd) – C:\WINDOWS\system32\drivers\snpstd.sys ()
DRV - (NWWMUSB) Sony Network Walkman (E) – C:\WINDOWS\system32\drivers\nwwmusb.sys (Sony Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iamwired.net/websearch.php?src=tops&search;="
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.5
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {79047c68-4b92-06c8-3821-3ce9bc34886a}:4.6.6.8
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/01 21:08:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/26 06:27:30 | 000,000,000 | —D | M]

[2009/12/07 20:13:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Extensions
[2010/10/06 01:25:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions
[2009/12/07 20:13:57 | 000,000,000 | —D | M] (FlashGot) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009/10/03 23:51:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/08 21:26:21 | 000,000,000 | —D | M] (Clear Cache Button) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{563e4790-7e70-11da-a72b-0800200c9a66}
[2009/12/07 20:13:56 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/08/03 04:25:47 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2008/06/09 02:04:03 | 000,001,504 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\imdb.xml
[2010/05/15 18:10:19 | 000,000,266 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\Search.xml
[2008/06/09 02:04:16 | 000,000,705 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\webster.xml
[2008/06/09 02:04:25 | 000,001,032 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\wikipedia-eng.xml
[2010/05/15 00:21:25 | 000,002,057 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\searchplugins\youtube-video-search.xml
[2010/10/06 01:25:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/15 18:10:32 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{79047c68-4b92-06c8-3821-3ce9bc34886a}
[2008/08/16 18:42:02 | 000,070,456 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 18:42:12 | 000,091,448 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 18:42:08 | 000,020,800 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2007/06/21 18:39:18 | 000,034,376 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\logging.dll
[2008/05/21 09:41:08 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 09:41:08 | 000,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 09:41:08 | 000,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2008/08/16 18:44:46 | 000,427,312 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2008/08/16 18:42:04 | 000,023,864 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2010/04/01 17:56:49 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 17:56:50 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 17:56:50 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 17:56:50 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/07/07 18:54:18 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar BHO) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll (BitComet)
O2 - BHO: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - No CLSID value found.
O2 - BHO: (FoxieToolbar Class) - {432CAE3B-690F-4C3B-BD97-070EBDA210D5} - C:\Program Files\Foxie Suite\foxietoolbaru.dll (Team Foxie)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O2 - BHO: (FoxieSecurityModule Class) - {C65185B1-D52B-44A9-861F-8201B50D1F37} - C:\Program Files\Foxie Suite\foxiecoreu.dll (Team Foxie)
O2 - BHO: (no name) - {d2aebbd0-2d7d-ec6b-98af-874c3e0f3537} - No CLSID value found.
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Foxie) - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll (Team Foxie)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSDB] C:\Program Files\Common Files\msdb.exe ()
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Wireless Manager] C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe (Affinegy, Inc.)
O4 - HKCU..\Run: [EWABQAF7KL] C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\Sbw.exe File not found
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKCU..\Run: [UBC5AB1IDP] C:\WINDOWS\Stubob.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &Winamp; Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm ()
O9 - Extra 'Tools' menuitem : Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm ()
O9 - Extra Button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll (BitComet)
O9 - Extra Button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe (Team Foxie)
O9 - Extra 'Tools' menuitem : Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe (Team Foxie)
O9 - Extra Button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe (Team Foxie)
O9 - Extra 'Tools' menuitem : Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe (Team Foxie)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra Button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm ()
O9 - Extra 'Tools' menuitem : The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {2991BC79-8959-3D13-A77D-64AC10B82334} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://workhardplayhard1.spaces.msn.com//P…ad/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} http://secure2.comned.com/signuptemplates/…login-devel.cab (SecureLogin class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab (MSN File Upload Control)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed],[removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.229,93.188.166.209
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\WINDOWS\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/02 21:47:06 | 000,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: Midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\WINDOWS\System32\evolusbn.dll (Evolution Electronics Ltd.)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.atrac3 - C:\WINDOWS\System32\atrac3.acm (Sony Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: VIDC.MP43 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (89241178368638976)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/03 19:46:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\Temp
[2010/07/09 03:30:52 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Chris Speck\Desktop\OTL.exe
[2010/07/08 15:27:01 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2010/07/08 03:29:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Chris Speck\Recent
[2010/07/07 04:25:49 | 000,000,000 | —D | C] – C:\_OTL
[2010/07/07 00:37:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\My Documents\Corel User Files
[2010/07/05 15:09:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Desktop\Artisteer 2.3 Theme Creator For JoomlaWPBlogger
[2010/07/05 05:51:05 | 000,000,000 | —D | C] – C:\Program Files\Artisteer 2
[2010/07/04 03:13:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Application Data\Artisteer
[2010/07/03 23:07:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\InfoJoin
[2010/07/03 23:07:22 | 000,000,000 | —D | C] – C:\Program Files\PostCast Server
[2010/07/03 21:51:16 | 000,000,000 | —D | C] – C:\wamp
[2010/07/03 03:04:54 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Chris Speck\Desktop\HiJackThis.exe
[2010/07/01 02:57:14 | 000,000,000 | —D | C] – C:\Program Files\AutoCAD 2009
[2010/07/01 02:22:37 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/07/01 02:21:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Chris Speck\Application Data\Yahoo!
[2010/07/01 02:21:12 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[2010/07/01 02:21:03 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2005/11/27 00:18:39 | 000,057,344 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd.dll
[2005/11/27 00:18:39 | 000,036,864 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd.dll

========== Files - Modified Within 30 Days ==========

[2010/10/06 02:51:00 | 000,001,000 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006UA.job
[2010/10/04 19:51:00 | 000,000,948 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006Core.job
[2010/07/09 03:38:00 | 000,000,366 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2010/07/09 03:30:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Chris Speck\Desktop\OTL.exe
[2010/07/09 02:55:40 | 000,000,258 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/07/09 00:29:35 | 000,000,292 | -H– | M] () – C:\WINDOWS\tasks\5c10f4d5.job
[2010/07/09 00:26:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/09 00:24:50 | 000,045,568 | —- | M] () – C:\WINDOWS\System32\ernel32.dll
[2010/07/09 00:24:31 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/09 00:24:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/09 00:24:15 | 3219,279,872 | -HS- | M] () – C:\hiberfil.sys
[2010/07/09 00:22:01 | 026,214,400 | -H– | M] () – C:\Documents and Settings\Chris Speck\NTUSER.DAT
[2010/07/09 00:22:01 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Chris Speck\ntuser.ini
[2010/07/08 23:49:43 | 000,348,374 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2010/07/08 15:27:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/08 01:44:18 | 003,714,430 | -H– | M] () – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\IconCache.db
[2010/07/08 01:44:05 | 000,000,190 | —- | M] () – C:\Documents and Settings\Chris Speck\defogger_reenable
[2010/07/07 18:54:18 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2010/07/05 23:20:00 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\AVG Free Control Center.job
[2010/07/05 21:12:16 | 000,000,796 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Artisteer 2.lnk
[2010/07/05 21:12:16 | 000,000,778 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\Artisteer 2.lnk
[2010/07/05 06:01:56 | 000,170,496 | —- | M] () – C:\WINDOWS\Stuboc.exe
[2010/07/05 06:01:56 | 000,170,496 | —- | M] () – C:\WINDOWS\Stubob.exe
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\5c10f4d5.exe
[2010/07/05 05:49:14 | 000,170,496 | —- | M] () – C:\WINDOWS\Stuboa.exe
[2010/07/05 03:58:26 | 000,003,842 | —- | M] () – C:\Documents and Settings\Chris Speck\My Documents\images.jpg
[2010/07/05 02:25:02 | 000,233,984 | —- | M] () – C:\Documents and Settings\Chris Speck\My Documents\567978_5_graduate_ad.doc
[2010/07/05 01:54:53 | 000,117,808 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/03 23:08:33 | 000,000,517 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PostCast Server.lnk
[2010/07/03 23:08:20 | 000,000,030 | —- | M] () – C:\WINDOWS\%UNINSTALL_LANG%
[2010/07/03 21:37:10 | 000,000,419 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\www.lnk
[2010/07/03 14:40:39 | 002,468,976 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/03 13:41:42 | 000,293,376 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\5kkw8xkt.exe
[2010/07/03 03:16:55 | 000,359,929 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\dds.scr
[2010/07/03 03:04:55 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Chris Speck\Desktop\HiJackThis.exe
[2010/07/01 03:28:14 | 000,117,808 | —- | M] () – C:\Documents and Settings\Chris Speck\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/01 03:21:55 | 000,001,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AutoCAD 2009.lnk
[2010/07/01 02:22:37 | 000,000,917 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\Revo Uninstaller.lnk
[2010/07/01 02:21:05 | 000,000,682 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\CCleaner.lnk
[2010/06/30 20:04:56 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/23 18:12:13 | 000,002,308 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/06/23 18:12:12 | 000,002,330 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\Google Chrome.lnk
[2010/06/16 18:20:36 | 000,001,911 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Style Builder.lnk
[2010/06/16 18:20:36 | 000,001,825 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LayOut 2.lnk
[2010/06/16 18:20:36 | 000,001,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google SketchUp 7.lnk
[2010/06/15 23:49:03 | 000,000,484 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\MSN.lnk
[2010/06/09 23:26:21 | 000,000,792 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk

========== Files Created - No Company Name ==========

[2010/10/03 19:50:30 | 000,002,330 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\Google Chrome.lnk
[2010/10/03 19:50:30 | 000,002,308 | —- | C] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/03 19:46:08 | 000,001,000 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006UA.job
[2010/10/03 19:46:07 | 000,000,948 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006Core.job
[2010/07/08 01:43:50 | 000,000,190 | —- | C] () – C:\Documents and Settings\Chris Speck\defogger_reenable
[2010/07/07 02:48:26 | 000,170,496 | —- | C] () – C:\WINDOWS\Stuboc.exe
[2010/07/05 21:12:16 | 000,000,796 | —- | C] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Artisteer 2.lnk
[2010/07/05 21:12:16 | 000,000,778 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\Artisteer 2.lnk
[2010/07/05 20:33:43 | 000,170,496 | —- | C] () – C:\WINDOWS\Stubob.exe
[2010/07/05 05:57:44 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ernel32.dll
[2010/07/05 05:57:42 | 000,000,292 | -H– | C] () – C:\WINDOWS\tasks\5c10f4d5.job
[2010/07/05 05:57:41 | 000,045,568 | —- | C] () – C:\Documents and Settings\Chris Speck\Application Data\5c10f4d5.exe
[2010/07/05 05:49:28 | 000,170,496 | —- | C] () – C:\WINDOWS\Stuboa.exe
[2010/07/05 05:49:17 | 000,000,258 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/07/05 03:58:26 | 000,003,842 | —- | C] () – C:\Documents and Settings\Chris Speck\My Documents\images.jpg
[2010/07/05 02:25:01 | 000,233,984 | —- | C] () – C:\Documents and Settings\Chris Speck\My Documents\567978_5_graduate_ad.doc
[2010/07/03 23:08:33 | 000,000,517 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PostCast Server.lnk
[2010/07/03 23:08:20 | 000,000,030 | —- | C] () – C:\WINDOWS\%UNINSTALL_LANG%
[2010/07/03 13:41:42 | 000,293,376 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\5kkw8xkt.exe
[2010/07/03 03:11:04 | 000,359,929 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\dds.scr
[2010/07/01 03:21:55 | 000,001,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AutoCAD 2009.lnk
[2010/07/01 02:22:37 | 000,000,917 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\Revo Uninstaller.lnk
[2010/07/01 02:21:05 | 000,000,682 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\CCleaner.lnk
[2010/06/15 23:45:47 | 000,000,484 | —- | C] () – C:\Documents and Settings\Chris Speck\Desktop\MSN.lnk
[2010/06/09 23:26:21 | 000,000,792 | —- | C] () – C:\Documents and Settings\Chris Speck\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/06/06 22:51:46 | 000,050,176 | —- | C] () – C:\WINDOWS\System32\annihilator.dll
[2009/12/05 21:32:43 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/09/29 18:07:07 | 000,000,049 | —- | C] () – C:\WINDOWS\bsm.ini
[2009/08/07 14:08:55 | 000,488,448 | —- | C] () – C:\WINDOWS\System32\apdfprintmon.dll
[2009/06/21 03:09:45 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\FoxImager.dll
[2009/05/14 01:38:31 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/22 00:19:06 | 000,172,173 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2008/09/02 16:54:16 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/09/02 16:54:16 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/09/02 01:26:07 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/09/02 01:26:06 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/05/17 13:47:07 | 000,000,355 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/02/27 01:45:25 | 000,017,403 | —- | C] () – C:\WINDOWS\wwdslcfg.ini
[2007/12/14 22:30:41 | 000,000,035 | —- | C] () – C:\WINDOWS\A6W.INI
[2007/05/19 20:13:23 | 000,000,126 | —- | C] () – C:\WINDOWS\_delis43.ini
[2006/11/17 23:55:30 | 000,000,394 | —- | C] () – C:\WINDOWS\capture.ini
[2006/01/02 21:55:15 | 000,194,248 | —- | C] () – C:\WINDOWS\System32\LTRFD13n.DLL
[2006/01/02 21:47:06 | 000,001,194 | —- | C] () – C:\WINDOWS\VFO.INI
[2006/01/02 21:47:01 | 000,196,096 | —- | C] () – C:\WINDOWS\System32\macd32.dll
[2006/01/02 21:47:01 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2006/01/02 21:47:01 | 000,136,192 | —- | C] () – C:\WINDOWS\System32\mamc32.dll
[2006/01/02 21:47:01 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\masd32.dll
[2006/01/02 21:47:01 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2005/12/28 16:05:27 | 000,000,000 | —- | C] () – C:\WINDOWS\WinPM.INI
[2005/12/27 21:04:57 | 003,870,720 | —- | C] () – C:\WINDOWS\System32\qt-mt323.dll
[2005/11/27 00:18:40 | 000,299,776 | —- | C] () – C:\WINDOWS\System32\drivers\snpstd.sys
[2005/11/27 00:18:39 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\dsnpstd.dll
[2005/11/27 00:18:39 | 000,015,541 | —- | C] () – C:\WINDOWS\snpstd.ini
[2005/11/21 20:27:30 | 000,262,416 | —- | C] () – C:\WINDOWS\System32\Asfv2.dll
[2005/11/21 20:27:29 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\TDI-SonyOMG.dll
[2005/11/18 20:42:12 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/11/18 15:59:52 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/18 15:08:28 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/11/15 15:25:10 | 000,000,067 | —- | C] () – C:\WINDOWS\#1 Video Converter.INI
[2005/11/15 14:11:17 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2005/11/15 14:11:17 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2005/11/15 14:11:17 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2005/11/15 14:11:17 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2005/11/10 20:17:09 | 000,000,155 | —- | C] () – C:\WINDOWS\CDPLAYER.INI
[2005/11/02 18:52:07 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/10/27 20:05:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/27 19:57:19 | 000,001,731 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/10/27 19:30:16 | 000,000,402 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/09 23:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/29 19:38:24 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2005/07/14 13:31:20 | 000,027,648 | RHS- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2005/06/21 23:37:42 | 000,062,464 | RHS- | C] () – C:\WINDOWS\System32\cygz.dll
[2005/04/09 17:04:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/12/20 19:24:03 | 001,663,068 | —- | C] () – C:\WINDOWS\System32\libmmd.dll
[2004/08/10 13:12:05 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/07/11 23:32:17 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MP3IFilter.dll
[2002/03/07 15:29:52 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\adexservice.dll
[1999/10/22 12:57:44 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\asmapi.dll

========== LOP Check ==========

[2009/08/07 14:10:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A-PDF
[2009/12/05 21:32:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Affinegy
[2010/02/07 17:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ASGvis
[2010/07/01 02:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/10/25 16:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2010/06/30 17:59:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/03/09 23:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2009/09/10 21:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2010/05/26 20:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Informatix
[2010/07/09 03:37:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/25 21:13:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Line 6
[2006/01/02 22:05:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2006/01/02 21:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2010/05/27 10:49:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/07/07 00:10:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/30 02:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/01/04 00:33:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2006/02/12 01:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\.BitTornado
[2005/11/03 04:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\.bittorrent
[2010/07/09 00:21:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Affinegy
[2010/07/04 03:13:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Artisteer
[2009/10/20 03:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Audacity
[2010/07/01 02:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Autodesk
[2010/05/28 01:28:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\AVG9
[2009/07/29 02:15:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/01/31 22:08:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\com.adobe.ExMan
[2007/04/23 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Command & Conquer 3 Tiberium Wars
[2008/04/07 03:44:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\DMCache
[2008/11/30 19:43:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\EPANET
[2009/06/21 03:08:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Focus Mp3 Recorder
[2008/09/30 10:30:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\foobar2000
[2006/06/26 01:45:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\FoxieSpywareSwiftSweeper
[2008/04/10 18:37:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\ICAClient
[2008/04/07 03:47:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\IDM
[2010/05/27 17:57:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Informatix
[2005/11/02 18:54:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Leadertech
[2008/12/06 20:11:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Line 6
[2006/01/12 17:30:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\NCH Swift Sound
[2009/10/15 04:25:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Notepad++
[2006/03/13 15:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Seven Zip
[2010/07/09 03:02:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Spotify
[2006/01/25 17:02:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\uTorrent
[2008/09/30 02:46:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chris Speck\Application Data\Viewpoint
[2010/07/09 00:29:35 | 000,000,292 | -H– | M] () – C:\WINDOWS\Tasks\5c10f4d5.job
[2010/07/05 23:20:00 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\AVG Free Control Center.job
[2010/07/09 02:55:40 | 000,000,258 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/10/25 05:59:57 | 000,071,878 | —- | M] () – C:\acadminidump.dmp
[2006/01/02 21:47:06 | 000,000,095 | —- | M] () – C:\AUTOEXEC.BAT
[2005/11/15 14:13:27 | 000,007,741 | —- | M] () – C:\avi_log.txt
[2009/01/18 16:47:05 | 000,000,212 | RHS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/11/29 20:54:24 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2005/11/03 00:57:36 | 000,003,499 | —- | M] () – C:\data
[2005/10/27 19:33:46 | 000,004,943 | RH– | M] () – C:\dell.sdr
[2010/07/09 00:24:15 | 3219,279,872 | -HS- | M] () – C:\hiberfil.sys
[2005/11/02 20:58:55 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/10/27 19:54:16 | 000,000,896 | -H– | M] () – C:\IPH.PH
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 05:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2009/02/05 21:47:35 | 000,000,000 | —- | M] () – C:\out.txt
[2010/07/09 00:23:55 | 533,725,183 | -HS- | M] () – C:\pagefile.sys
[2009/12/06 03:24:20 | 000,000,022 | —- | M] () – C:\Program1
[2010/06/10 01:52:33 | 000,000,000 | —- | M] () – C:\randombbbbbbbbb.txt
[2008/02/22 21:07:35 | 000,000,129 | —- | M] () – C:\Shortcut to 3½ Floppy (A).lnk
[2010/01/12 22:44:33 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/01/15 02:02:19 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/01/15 17:32:49 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/01/16 19:14:09 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/01/18 19:41:10 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/01/19 18:19:40 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/01/22 21:28:25 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/01/19 19:53:34 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/01/22 21:47:18 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2010/01/23 13:02:40 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2010/01/23 13:49:21 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2010/01/24 17:20:10 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/01/26 08:53:30 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/01/26 11:39:53 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2010/01/27 14:33:25 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/01/28 01:01:34 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2010/01/28 18:19:41 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/01/28 18:42:27 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/01/28 19:54:00 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/01/30 21:11:28 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2010/01/12 22:44:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/01/15 02:02:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/01/15 17:32:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/01/16 19:14:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/01/18 19:41:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/01/19 18:19:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/01/22 21:28:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/01/19 19:53:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/01/22 21:47:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/01/23 13:02:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/01/23 13:49:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/01/24 17:20:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/01/26 08:53:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/01/26 11:39:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/01/27 14:33:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/01/28 01:01:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/01/28 18:19:41 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/01/28 18:42:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/01/28 19:53:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/01/30 21:11:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\5i5q5.dll
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\7q3w79y.dll
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\k1yW3179.dll
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\kUO3oC.dll
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\o31mY3cE9.dll
[2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\SK93gM.dll

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\*. /mp /s >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %systemroot%\system32\*.dll /lockedfiles >
[2007/03/15 02:58:38 | 000,315,392 | —- | M] (Advanced Micro Devices, Inc.) Unable to obtain MD5 – C:\WINDOWS\system32\ATIDEMGX.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 16:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\system32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 05:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 05:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-05-28 23:31:59
< End of report >
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    DRV - (kahjebpu) – C:\WINDOWS\System32\drivers\kahjebpu.sys File not found
    DRV - (cusbohcn) – C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\cusbohcn.sys File not found
    FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iamwired.net/websearch.php?src=tops&search="
    O2 - BHO: (no name) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - No CLSID value found.
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
    O2 - BHO: (no name) - {d2aebbd0-2d7d-ec6b-98af-874c3e0f3537} - No CLSID value found.
    O4 - HKLM..\Run: [KernelFaultCheck] File not found
    O4 - HKCU..\Run: [EWABQAF7KL] C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\Sbw.exe File not found
    O4 - HKCU..\Run: [UBC5AB1IDP] C:\WINDOWS\Stubob.exe ()
    O16 - DPF: {2991BC79-8959-3D13-A77D-64AC10B82334} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} Reg Error: Value error. (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed],[removed]
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.229,93.188.166.209
    [2010/07/09 02:55:40 | 000,000,258 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    [2010/07/09 00:29:35 | 000,000,292 | -H– | M] () – C:\WINDOWS\tasks\5c10f4d5.job
    [2010/07/09 00:24:50 | 000,045,568 | —- | M] () – C:\WINDOWS\System32\ernel32.dll
    [2010/07/05 06:01:56 | 000,170,496 | —- | M] () – C:\WINDOWS\Stuboc.exe
    [2010/07/05 06:01:56 | 000,170,496 | —- | M] () – C:\WINDOWS\Stubob.exe
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\Documents and Settings\Chris Speck\Application Data\5c10f4d5.exe
    [2010/07/05 05:49:14 | 000,170,496 | —- | M] () – C:\WINDOWS\Stuboa.exe
    [2010/07/03 13:41:42 | 000,293,376 | —- | M] () – C:\Documents and Settings\Chris Speck\Desktop\5kkw8xkt.exe
    [2010/07/09 00:29:35 | 000,000,292 | -H– | M] () – C:\WINDOWS\Tasks\5c10f4d5.job
    [2010/07/09 02:55:40 | 000,000,258 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\5i5q5.dll
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\7q3w79y.dll
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\k1yW3179.dll
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\kUO3oC.dll
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\o31mY3cE9.dll
    [2010/07/05 05:57:40 | 000,045,568 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\SK93gM.dll
    :Files
    windows69.exe /s /alldrives
    flushdns /c
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
oK GMER finished running this time, (8 hours run time) but when I went to save and copy the log, the pc froze and the program crashed, couldn't get the pc to do anything then, left it for about an hour, still no response ended up having to pull the plug. The PC was in safe mode, with devices unchecked but unfortunately I still don't have a GMER log for you (unless it automatically saves a copy of finished logs somewhere?). I will run the fix you just posted and try again with GMER tonight unless you say other wise. I also wanted to ask you if any of the program's we'r running would effect my wamp server. I normally assign my working web projects to 127.0.0.1 through the windows/system32/devices/etc/host file but since running fogger the other day localhost seems to be giving me some trouble.Permission rights and such like, any clue's at all? Once again thanks for helping your a life saver! Will give you a boss review if that's possible in here!
Hello,

Lets not worry about the GMER scan for now. We will do something else instead. Please run the OTL fix when you get a chance and then post the log back here for review.

I also wanted to ask you if any of the program's we'r running would effect my wamp server. I normally assign my working web projects to 127.0.0.1 through the windows/system32/devices/etc/host file but since running fogger the other day localhost seems to be giving me some trouble.Permission rights and such like, any clue's at all?

I reset your host file, so that may be why your experiencing issues with it.
OK here's the OTL Log. Cant seem to get http://127.0.0.1 to work? is there anything I have to re-install or do you think its just the redirect bug playing up?

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Error: No service named kahjebpu was found to stop!
Service\Driver key kahjebpu not found.
File C:\WINDOWS\System32\drivers\kahjebpu.sys File not found not found.
Error: No service named cusbohcn was found to stop!
Service\Driver key cusbohcn not found.
File C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\cusbohcn.sys File not found not found.
Prefs.js: "http://flvdirect.iamwired.net/websearch.php?src=tops&search=" removed from browser.search.defaulturl
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4322A444-92F8-4C3E-BD4C-013BA51E2871}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4322A444-92F8-4C3E-BD4C-013BA51E2871}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{53707962-6F74-2D53-2644-206D7942484F}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF3E430-B101-42AD-A544-FADC6B084872}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2aebbd0-2d7d-ec6b-98af-874c3e0f3537}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2aebbd0-2d7d-ec6b-98af-874c3e0f3537}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EWABQAF7KL not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\UBC5AB1IDP not found.
File C:\WINDOWS\Stubob.exe not found.
Starting removal of ActiveX control {2991BC79-8959-3D13-A77D-64AC10B82334}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2991BC79-8959-3D13-A77D-64AC10B82334}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer| /E : value set successfully!
File C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job not found.
File C:\WINDOWS\tasks\5c10f4d5.job not found.
File C:\WINDOWS\System32\ernel32.dll not found.
File C:\WINDOWS\Stuboc.exe not found.
File C:\WINDOWS\Stubob.exe not found.
File C:\Documents and Settings\Chris Speck\Application Data\5c10f4d5.exe not found.
File C:\WINDOWS\Stuboa.exe not found.
File C:\Documents and Settings\Chris Speck\Desktop\5kkw8xkt.exe not found.
File C:\WINDOWS\Tasks\5c10f4d5.job not found.
File C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job not found.
File C:\WINDOWS\system32\spool\prtprocs\w32x86\5i5q5.dll not found.
File C:\WINDOWS\system32\spool\prtprocs\w32x86\7q3w79y.dll not found.
File C:\WINDOWS\system32\spool\prtprocs\w32x86\k1yW3179.dll not found.
File C:\WINDOWS\system32\spool\prtprocs\w32x86\kUO3oC.dll not found.
File C:\WINDOWS\system32\spool\prtprocs\w32x86\o31mY3cE9.dll not found.
File C:\WINDOWS\system32\spool\prtprocs\w32x86\SK93gM.dll not found.
========== FILES ==========
windows69.exe not found in C:\
< flushdns /c >
C:\Documents and Settings\Chris Speck\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Chris Speck\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Chris Speck
->Temp folder emptied: 494541 bytes
->Temporary Internet Files folder emptied: 1474783 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40046613 bytes
->Google Chrome cache emptied: 6623746 bytes
->Flash cache emptied: 6855 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 577079 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33750 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 574475 bytes

Total Files Cleaned = 48.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Chris Speck
->Flash cache emptied: 0 bytes

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.8.1 log created on 07092010_233609
Hello,

It's quite possible that it's the infection that is causing you these issues. We can revisit this issue a little later. In the mean time I'd like for you to download and run ComboFix on your computer.

Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
Hello, Here's the combo Log, looking at my browser my pc doesn't seem to be redirecting me any more, Thanks!!!! Is there any more fix's i should run to stop me getting it again? can you recommend any free ad-ware or ant virus software which might be suitable?

Thanks again, life saver!


ComboFix 10-07-15.01 - Chris Speck 16/07/2010 12:02:24.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3070.2227 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Images
c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\program files\Internet Explorer\OnlO0r.bak
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\-1_0FVgGJK3x_P8.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\kbiwkmwfvmfhqf.dat
c:\windows\system32\kbiwkmyuunbaqj.dat
c:\windows\system32\lowsec
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\spool\prtprocs\w32x86\QG1i93q79.dll
c:\windows\system32\sysnet.dat
c:\windows\system32\system
c:\windows\system32\WanPacket.dll
c:\windows\system32\wispex.html
c:\windows\system32\wpcap.dll

Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_kbiwkmebxnxeyi
——-\Legacy_NPF
——-\Service_kbiwkmebxnxeyi
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2010-06-16 to 2010-07-16 )))))))))))))))))))))))))))))))
.

2010-10-03 18:46 . 2010-06-23 17:10 ——– d—–w- c:\documents and settings\Chris Speck\Local Settings\Application Data\Temp
2010-07-08 14:27 . 2010-07-08 14:27 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-07-07 03:25 . 2010-07-07 03:25 ——– d—–w- C:\_OTL
2010-07-05 04:51 . 2010-07-05 20:10 ——– d—–w- c:\program files\Artisteer 2
2010-07-04 02:13 . 2010-07-04 02:13 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\Artisteer
2010-07-03 22:07 . 2010-07-03 22:07 ——– d—–w- c:\program files\Common Files\InfoJoin
2010-07-03 22:07 . 2010-07-08 02:12 ——– d—–w- c:\program files\PostCast Server
2010-07-03 20:51 . 2010-07-08 21:43 ——– d—–w- C:\wamp
2010-07-01 01:57 . 2010-07-01 02:21 ——– d—–w- c:\program files\AutoCAD 2009
2010-07-01 01:22 . 2010-07-01 01:22 ——– d—–w- c:\program files\VS Revo Group
2010-07-01 01:21 . 2010-07-01 01:21 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\Yahoo!
2010-07-01 01:21 . 2010-07-01 01:24 ——– d—–w- c:\program files\Yahoo!
2010-07-01 01:21 . 2010-07-01 01:21 ——– d—–w- c:\program files\CCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-16 11:23 . 2009-03-09 22:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2010-07-16 11:13 . 2009-12-05 20:53 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\Affinegy
2010-07-15 20:44 . 2009-05-16 13:36 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\Spotify
2010-07-15 03:21 . 2007-03-27 13:20 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-14 16:09 . 2010-06-06 21:51 ——– d—–w- c:\program files\Annihilator
2010-07-09 22:49 . 2005-11-02 19:59 117808 -c–a-w- c:\documents and settings\Chris Speck\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-03 22:06 . 2009-05-14 00:38 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-03 13:43 . 2005-11-06 13:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-01 02:21 . 2008-03-02 21:07 ——– d—–w- c:\program files\Common Files\Autodesk Shared
2010-07-01 01:57 . 2008-03-02 21:20 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\Autodesk
2010-07-01 01:57 . 2008-03-02 21:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Autodesk
2010-07-01 00:53 . 2005-11-06 13:43 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-06-30 16:59 . 2010-05-26 00:21 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-06-30 15:29 . 2005-11-12 16:08 ——– d—–w- c:\program files\Macromedia
2010-06-30 15:29 . 2005-10-27 18:51 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-30 15:29 . 2005-11-12 16:09 ——– d—–w- c:\program files\Common Files\Macromedia
2010-06-06 13:59 . 2010-06-06 13:59 ——– d—–w- c:\program files\oDesk
2010-06-02 02:11 . 2010-06-02 02:11 73728 —-a-w- c:\program files\Common Files\msdb.exe
2010-06-01 21:05 . 2008-03-02 21:20 ——– d—–w- c:\program files\AutoCAD 2007
2010-05-28 00:28 . 2010-05-28 00:28 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\AVG9
2010-05-27 16:57 . 2010-05-27 16:57 ——– d—–w- c:\documents and settings\Chris Speck\Application Data\Informatix
2010-05-27 16:51 . 2010-05-26 18:46 ——– d—–w- c:\program files\Informatix
2010-05-27 09:49 . 2010-05-27 09:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-05-26 19:40 . 2010-05-26 19:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Informatix
2010-05-26 15:18 . 2005-11-02 20:13 ——– d—–w- c:\program files\Areas
2010-05-26 00:22 . 2010-05-26 00:22 ——– d—–w- c:\program files\AVG
2010-05-16 19:05 . 2010-05-16 19:06 411368 —-a-w- c:\windows\system32\deploytk.dll
2008-08-16 17:42 . 2008-08-16 17:42 13112 -c–a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 17:42 . 2008-08-16 17:42 70456 -c–a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 17:42 . 2008-08-16 17:42 91448 -c–a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 17:42 . 2008-08-16 17:42 20800 -c–a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 17:43 . 2008-08-16 17:43 206136 -c–a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 17:42 . 2008-08-16 17:42 31032 -c–a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 17:42 . 2008-08-16 17:42 40248 -c–a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-06-21 17:39 . 2007-06-21 17:39 34376 -c–a-w- c:\program files\mozilla firefox\plugins\logging.dll
2008-05-21 08:41 . 2008-05-21 08:41 479232 -c–a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-21 08:41 . 2008-05-21 08:41 548864 -c–a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-21 08:41 . 2008-05-21 08:41 626688 -c–a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 13:58 . 2008-06-05 13:58 648504 -c–a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 17:42 . 2008-08-16 17:42 23864 -c–a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2005-07-14 12:31 . 2005-07-14 12:31 27648 -csha-r- c:\windows\system32\AVSredirect.dll
2005-06-26 15:32 . 2005-06-26 15:32 1109385 -csha-r- c:\windows\system32\cygwin1.dll
2005-06-21 22:37 . 2005-06-21 22:37 62464 -csha-r- c:\windows\system32\cygz.dll
2005-02-28 13:16 . 2005-02-28 13:16 240128 -csha-r- c:\windows\system32\x.264.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"Google Update"="c:\documents and settings\Chris Speck\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-10-03 136176]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-01-27 180269]
"MSDB"="c:\program files\Common Files\msdb.exe" [2010-06-02 73728]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\acaptuser32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=evolusbn.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Audible Download Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Audible Download Manager.lnk
backup=c:\windows\pss\Audible Download Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BDARemote.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BDARemote.lnk
backup=c:\windows\pss\BDARemote.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DRSpawner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DRSpawner.lnk
backup=c:\windows\pss\DRSpawner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG311T Wireless Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG311T Wireless Assistant.lnk
backup=c:\windows\pss\NETGEAR WG311T Wireless Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Chris Speck^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk]
path=c:\documents and settings\Chris Speck\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
backup=c:\windows\pss\BBC iPlayer Desktop.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Chris Speck^Start Menu^Programs^Startup^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
2007-04-23 11:23 1032640 —-a-w- c:\program files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 -c–a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 06:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2006-09-14 20:09 157592 -c–a-w- c:\program files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-02-23 15:19 53248 -c—-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-01-22 19:16 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 16:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 -c–a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmgStartup]
2000-12-06 12:59 24576 -c–a-w- c:\program files\Common Files\Sony Shared\OpenMG\OmgStartup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-11 01:26 406016 -c–a-w- c:\windows\system32\PSDrvCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 23:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-16 19:05 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-04 14:56 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2006-01-27 17:21 180269 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\day of defeat\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike\\hl.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\warhammer 40,000 dawn of war ii - beta\\DOW2.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\darwinia demo\\darwinia.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\half-life blue shift\\hl.exe"=
"c:\\Program Files\\MATLAB\\R2007b\\bin\\win32\\MATLAB.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\CAVEDOG\\TOTALA\\TotalA.exe"=
"c:\\Program Files\\Google\\Google SketchUp 7\\SketchUp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google SketchUp 7\\LayOut\\LayOut.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\ASGvis\\DRSpawner\\DRSpawner.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22797:TCP"= 22797:TCP:BitComet 22797 TCP
"22797:UDP"= 22797:UDP:BitComet 22797 UDP
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R2 EvoInstallerService;M-Audio Installer;c:\program files\M-Audio\Install\EvoInst.exe [05/02/2009 21:26 90112]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max Design 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [12/03/2009 17:36 86016]
R2 NinjaVideo Helper.exe;NinjaVideo Helper;c:\program files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe [10/04/2008 21:01 110592]
S3 EVOLUSB;%EVOL_USB.SvcDesc%;c:\windows\system32\drivers\evolusb.sys [05/02/2009 21:26 21984]
S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\Drivers\L6TPortGX.sys –> c:\windows\system32\Drivers\L6TPortGX.sys [?]
S3 NWWMUSB;Sony Network Walkman (E);c:\windows\system32\drivers\nwwmusb.sys [21/11/2005 20:30 27255]
S3 scrcap;scrcap;c:\windows\system32\DRIVERS\scrcap.sys –> c:\windows\system32\DRIVERS\scrcap.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [02/01/2006 20:52 721904]
.
Contents of the 'Scheduled Tasks' folder

2010-07-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2010-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006Core.job
- c:\documents and settings\Chris Speck\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-03 18:45]

2010-10-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2500501035-2615412177-632401041-1006UA.job
- c:\documents and settings\Chris Speck\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-03 18:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Winamp Toolbar Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Name-Space Handler: HTTP\* - {5B18FD94-2904-4AA0-AD63-7231D59E63A2} - c:\program files\Foxie Suite\foxiecoreu.dll
DPF: {2991BC79-8959-3D13-A77D-64AC10B82334}
FF - ProfilePath - c:\documents and settings\Chris Speck\Application Data\Mozilla\Firefox\Profiles\6gc817u6.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\program files\Mozilla Firefox\extensions\{79047c68-4b92-06c8-3821-3ce9bc34886a}\components\4yz6Q-.dll
FF - plugin: c:\documents and settings\Chris Speck\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

BHO-{d2aebbd0-2d7d-ec6b-98af-874c3e0f3537} - (no file)
ActiveSetup-{VXRPSHA4-WWFP-0Z0J-KBQP-0GKU4DW71AAK} - c:\docume~1\CHRISS~1\LOCALS~1\Temp\patch.exe
AddRemove–1_0FVgGJK3x_P8 - c:\windows\system32\-1_0FVgGJK3x_P8.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-16 12:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2500501035-2615412177-632401041-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:82,ba,61,84,f3,4c,b9,b0,9d,00,b9,8d,41,eb,95,4c,ca,36,bd,f5,4b,ac,5e,
4e,d9,c6,48,66,e3,84,a5,d0,87,29,cd,55,8d,47,f1,12,e2,15,94,b0,de,d2,85,02,\
"??"=hex:32,6d,17,bd,ce,bc,fe,c7,b0,58,a8,8f,4a,f8,bf,a3

[HKEY_USERS\S-1-5-21-2500501035-2615412177-632401041-1006\Software\SecuROM\License information*]
"datasecu"=hex:9d,aa,c5,5a,d2,53,b9,4d,fd,d5,f4,6d,87,1c,49,46,ce,7f,91,c3,0c,
70,18,f6,7c,d5,4c,e8,77,85,09,61,6f,c5,ce,c6,dc,96,85,bf,69,ee,1f,23,dd,d5,\
"rkeysecu"=hex:a9,99,9e,c5,a1,49,0b,49,f2,f9,50,b9,23,28,c2,a8

[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{18291fd7-bc5d-4b8f-8f8a-9a350eb3af96}]
@Denied: (Full) (Everyone)
"Model"=dword:000000e2
"Therad"=dword:0000002b
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):c7,79,43,8d,b1,f5,e4,a4,95,44,93,bd,71,12,6f,43,3f,fa,db,71,f9,
cd,35,33,41,2b,7a,8b,39,d7,c2,9b,02,6e,35,c5,95,f2,ec,c6,00,00,00,00,00,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2588)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\Virgin Broadband Wireless\ndis_events.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2010-07-16 12:37:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-16 11:37

Pre-Run: 7,819,735,040 bytes free
Post-Run: 6,419,533,824 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

- - End Of File - - 31AC06F59EE0CA68D2B3DCB358A439E1
Hello,

We are going to run a few more scans to ensure that we get it all, and I will include my recommendations for staying clean in my All Clean speech.

Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



Kaspersky Online Scanner
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



NEXT:



OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Push [external image: Posted Image]
  • A report will open. Copy and Paste that report in your next reply.



NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that is produced after running the updated MalwareBytes' Anti-Malware scan.
3. The log that is produced after running the Kaspersky Online Virus Scanner.
4. The log that is produced after running the SecurityCheck scan.
5. The log that is produced after running the OTL scan.
6. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.

Cheers,
SweetTech.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI