This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

trojan aspx.js.win32

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I seem to have been infected by a the trojan mentioned above. Mcafee has been repeating alerts about trojans like genericfakeAlert!data and FakeAlert-GA.ddl being removed. There are also different alerts popping up on my task bar like "A security threat detected on your computer. TrojanASPX.JS.Win32. It strongly recommended to remove this threat right now. Click on the message to remove it.", there also pop ups from window telling me that certains things have stopped working like "windows services has stopped working and was closed". an hour after i got infected My computer rebooted and a blue screen appeared, it rebooted again and i tried to go safe mode but it took me to a black screen. I manage to run a MBAM scan and I quarantined and removed the stuff that scan found, but I would like to make sure that my PC is not infected anymore. Any help will be appreciated. Thanks
Hello skeeno and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.


Please work your way through the following steps. If you encounter any difficulties come back and let me know.


  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then right click on the OTL.exe icon and select "Run as Administrator" to run the program.
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click GMER.exe and select "Run as Administrator". If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please provide the OTL logs and the GMER log in your next reply.

Note: You may need to make more than one post to fit the required information in.
Thanks for helping :) I downloaded OTL and proceeded to do the scan and a warning message popped up stating "There is no disk in the drive Please insert a disk into drive\Device\Harddisk2\DR2 what should i do?

I clicked cancel but the scan continued and i got this

OTL logfile created on: 08/07/2010 21:41:25 - Run 1
OTL by OldTimer - Version 3.2.8.1 Folder = C:\Users\Johnry\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.78 Gb Total Space | 93.17 Gb Free Space | 41.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.04 Gb Free Space | 60.36% Space Free | Partition Type: NTFS
Drive E: | 5.56 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SKEENOMAN
Current User Name: Johnry
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/07/08 21:15:45 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Johnry\Desktop\OTL.exe
PRC - [2010/06/10 06:58:32 | 000,865,832 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2010/05/14 11:00:26 | 000,249,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/10/29 07:54:44 | 001,218,008 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 10:22:08 | 000,144,704 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee\MSK\msksrver.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/05/21 19:58:14 | 000,413,496 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe
PRC - [2009/04/11 07:28:15 | 000,244,224 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wisptis.exe
PRC - [2009/04/11 07:28:06 | 000,304,128 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/30 16:28:36 | 001,533,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/03/30 16:28:36 | 000,183,152 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/03/26 17:16:24 | 000,186,664 | —- | M] (Wacom Technology, Corp.) – C:\Windows\System32\WTablet\Wacom_TabletUser.exe
PRC - [2009/03/26 17:15:24 | 002,789,672 | —- | M] (Wacom Technology, Corp.) – C:\Windows\System32\Wacom_Tablet.exe
PRC - [2008/05/01 23:41:38 | 000,136,488 | —- | M] (Wacom Technology, Corp.) – C:\Windows\System32\WTablet\Pen_TabletUser.exe
PRC - [2008/05/01 23:40:44 | 003,032,360 | —- | M] (Wacom Technology, Corp.) – C:\Windows\System32\Pen_Tablet.exe
PRC - [2008/01/19 08:38:38 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 08:33:12 | 000,198,656 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
PRC - [2008/01/17 07:22:20 | 004,907,008 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\AERTSrv.exe
PRC - [2007/08/21 21:35:19 | 000,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/07/31 02:07:56 | 000,072,704 | —- | M] (Creative Labs) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
PRC - [2007/04/06 14:07:42 | 000,439,768 | —- | M] (Intel Corporation) – C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
PRC - [2007/03/15 12:09:36 | 000,460,784 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/02/20 13:58:44 | 000,053,248 | —- | M] (Logitech Inc.) – C:\Program Files\SetPoint\LBTWiz.exe
PRC - [2007/02/20 13:57:32 | 000,110,592 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
PRC - [2007/02/20 13:29:00 | 000,679,936 | —- | M] (Logitech Inc.) – C:\Program Files\SetPoint\SetPoint.exe
PRC - [2007/01/11 19:15:00 | 000,101,136 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.exe
PRC - [2006/11/27 09:14:52 | 000,180,224 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
PRC - [2006/11/05 11:22:16 | 000,221,184 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
PRC - [2006/11/05 10:55:48 | 000,010,752 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
PRC - [2006/11/04 02:07:04 | 000,537,480 | —- | M] ( ) – C:\Windows\System32\dlcxcoms.exe
PRC - [2006/11/03 23:04:46 | 000,304,008 | —- | M] () – C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
PRC - [2006/11/03 23:04:26 | 000,291,720 | —- | M] () – C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
PRC - [2006/09/19 10:07:28 | 000,827,392 | —- | M] () – C:\Windows\vsnpstd3.exe


========== Modules (SafeList) ==========

MOD - [2010/07/08 21:15:45 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Johnry\Desktop\OTL.exe
MOD - [2009/11/01 16:29:02 | 000,554,832 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcp80.dll
MOD - [2009/11/01 16:29:01 | 000,632,656 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll
MOD - [2009/04/11 07:28:24 | 000,380,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
MOD - [2009/04/11 07:21:38 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/19 08:33:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx
MOD - [2007/02/20 13:23:26 | 000,044,544 | —- | M] (Logitech Inc.) – C:\Program Files\SetPoint\lgscroll.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/06/10 06:58:32 | 000,865,832 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\MSC\mcmscsvc.exe – (mcmscsvc)
SRV - [2010/05/14 11:00:26 | 000,249,136 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2010/03/18 13:16:28 | 000,753,504 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe – (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/11/01 13:14:33 | 000,320,760 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\MPF\MPFSrv.exe – (MpfService)
SRV - [2009/09/25 02:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/09/16 11:23:32 | 000,365,072 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2009/09/16 10:22:08 | 000,144,704 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\VirusScan\Mcshield.exe – (McShield)
SRV - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) [On_Demand | Running] – C:\Program Files\McAfee\VirusScan\mcsysmon.exe – (McSysmon)
SRV - [2009/08/05 22:48:42 | 000,704,864 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc)
SRV - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\McAfee\MSK\MskSrver.exe – (MSK80Service)
SRV - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe – (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\program files\common files\mcafee\mna\mcnasvc.exe – (McNASvc)
SRV - [2009/03/30 16:28:36 | 001,533,808 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc)
SRV - [2009/03/26 17:15:24 | 002,789,672 | —- | M] (Wacom Technology, Corp.) [Auto | Running] – C:\Windows\System32\Wacom_Tablet.exe – (TabletServiceWacom)
SRV - [2008/05/01 23:40:44 | 003,032,360 | —- | M] (Wacom Technology, Corp.) [Auto | Running] – C:\Windows\System32\Pen_Tablet.exe – (TabletServicePen)
SRV - [2008/01/19 08:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\AERTSrv.exe – (AERTFilters)
SRV - [2007/07/31 02:21:41 | 001,862,144 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager)
SRV - [2007/07/31 02:07:56 | 000,072,704 | —- | M] (Creative Labs) [Auto | Running] – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe – (Creative Labs Licensing Service)
SRV - [2007/04/06 14:10:56 | 000,223,704 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\CCU\AlertService.exe – (AlertService) Intel®
SRV - [2007/04/06 14:10:22 | 000,272,856 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe – (QualityManager) Intel®
SRV - [2007/04/06 14:10:08 | 000,449,496 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe – (Remote UI Service) Intel®
SRV - [2007/04/06 14:08:58 | 000,158,168 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe – (MCLServiceATL) Intel®
SRV - [2007/04/06 14:08:36 | 000,036,312 | R— | M] (Intel® Corporation) [Auto | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe – (IntelDHSvcConf)
SRV - [2007/04/06 14:08:24 | 000,039,896 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe – (DHTRACE) Intel®
SRV - [2007/04/06 14:08:14 | 000,059,352 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe – (ISSM) Intel®
SRV - [2007/04/06 14:07:46 | 000,313,816 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe – (NMSCore) Intel®
SRV - [2007/04/06 14:06:48 | 000,256,472 | —- | M] () [On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe – (M1 Server) Intel® Viiv™
SRV - [2007/03/19 12:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/02/20 13:57:32 | 000,110,592 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE – (LBTServ)
SRV - [2007/02/12 10:46:34 | 000,208,896 | —- | M] () [On_Demand | Stopped] – C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe – (DQLWinService)
SRV - [2006/11/04 02:07:04 | 000,537,480 | —- | M] ( ) [Auto | Running] – C:\Windows\System32\dlcxcoms.exe – (dlcx_device)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\XDva098.sys – (XDva098)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\XDva095.sys – (XDva095)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\XDva062.sys – (XDva062)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\XDva039.sys – (XDva039)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\wacomvhid.sys – (wacomvhid)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\EagleNT.sys – (EagleNT)
DRV - File not found [Kernel | Disabled | Stopped] – C:\Windows\System32\drivers\blbdrive.sys – (blbdrive)
DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\mferkdk.sys – (mferkdk)
DRV - [2009/08/05 22:48:42 | 000,054,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\fssfltr.sys – (fssfltr)
DRV - [2009/07/16 12:32:26 | 000,130,424 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\Mpfp.sys – (MPFP)
DRV - [2009/04/11 05:42:54 | 000,073,216 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/10/06 11:53:24 | 000,015,656 | —- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\wacmoumonitor.sys – (wacmoumonitor)
DRV - [2008/05/09 18:41:20 | 000,278,984 | —- | M] () [Kernel | Auto | Running] – C:\Windows\System32\drivers\atksgt.sys – (atksgt)
DRV - [2008/01/24 11:06:40 | 002,054,872 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/01/19 06:53:39 | 000,007,680 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\umpass.sys – (UMPass)
DRV - [2007/10/06 15:31:46 | 000,025,416 | —- | M] () [Kernel | Auto | Running] – C:\Windows\System32\drivers\lirsgt.sys – (lirsgt)
DRV - [2007/09/17 08:07:00 | 007,624,192 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2007/08/28 18:05:12 | 000,055,808 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\xusb21.sys – (xusb21)
DRV - [2007/07/31 09:43:50 | 000,020,152 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2007/07/31 09:43:50 | 000,019,128 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2007/07/31 09:43:50 | 000,017,592 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/07/31 02:20:16 | 000,005,504 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntelDH.sys – (IntelDH)
DRV - [2007/04/29 09:42:24 | 000,228,224 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2007/04/26 11:41:38 | 000,304,920 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastor.sys – (iaStor)
DRV - [2007/04/24 09:33:34 | 000,083,336 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\s125bus.sys – (s125bus) Sony Ericsson Device 125 driver (WDM)
DRV - [2007/04/23 13:54:50 | 000,100,488 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\s115mgmt.sys – (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/23 13:54:50 | 000,098,568 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\s115obex.sys – (s115obex)
DRV - [2007/04/23 13:54:48 | 000,108,680 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\s115mdm.sys – (s115mdm)
DRV - [2007/04/23 13:54:48 | 000,015,112 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\s115mdfl.sys – (s115mdfl)
DRV - [2007/04/06 14:10:40 | 000,014,808 | —- | M] () [File_System | On_Demand | Stopped] – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys – (TSHWMDTCP)
DRV - [2007/03/27 19:19:36 | 010,252,544 | —- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\snpstd3.sys – (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2007/02/25 12:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/02/18 20:34:50 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\nmsunidr.sys – (nmsunidr)
DRV - [2007/02/16 20:12:36 | 000,011,312 | —- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\wacommousefilter.sys – (wacommousefilter)
DRV - [2007/02/16 01:11:28 | 000,011,440 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\WacomVKHid.sys – (WacomVKHid)
DRV - [2007/02/09 12:34:16 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2007/02/08 20:05:30 | 000,028,120 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2007/02/08 20:05:30 | 000,012,856 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2007/01/11 19:15:16 | 000,032,528 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LMouFilt.Sys – (LMouFilt)
DRV - [2007/01/11 19:15:06 | 000,032,272 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\LHidFilt.Sys – (LHidFilt)
DRV - [2006/11/02 10:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 10:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 10:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 10:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 10:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 10:51:25 | 000,232,040 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2006/11/02 10:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 10:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 10:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 10:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 10:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 10:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 10:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 10:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 10:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 10:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 10:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 10:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 10:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 10:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 10:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 10:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 10:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 10:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 10:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 10:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 10:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 10:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 10:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 10:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 10:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 10:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 09:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 09:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 09:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 09:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 09:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 09:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 08:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 08:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 08:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2006/10/26 16:22:02 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/10/26 16:21:34 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/10/26 16:21:34 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/10/26 16:21:32 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/10/26 16:21:30 | 000,026,296 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/10/26 16:21:28 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/10/26 16:21:26 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/10/26 16:21:24 | 000,104,536 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/07/21 11:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2005/06/13 10:03:12 | 000,060,768 | —- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\w800bus.sys – (w800bus) Sony Ericsson W800 driver (WDM)
DRV - [2004/10/29 16:38:14 | 000,009,216 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\wacomvhidpen.sys – (WacomVHidPen)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource;=3&q;="
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {196E6E73-C424-4595-AA03-8416C1463A31}:1.9.1
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/08/21 21:35:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/20 20:51:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{196E6E73-C424-4595-AA03-8416C1463A31}: C:\Users\Johnry\AppData\Local\{196E6E73-C424-4595-AA03-8416C1463A31} [2010/07/08 17:18:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/01 22:14:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/28 11:11:23 | 000,000,000 | —D | M]

[2008/09/20 16:07:02 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\mozilla\Extensions
[2010/07/08 17:24:52 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\mozilla\Firefox\Profiles\c6mc4ufv.default\extensions
[2010/04/27 23:22:23 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Johnry\AppData\Roaming\mozilla\Firefox\Profiles\c6mc4ufv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/29 09:21:13 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Johnry\AppData\Roaming\mozilla\Firefox\Profiles\c6mc4ufv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/03/18 12:44:24 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Johnry\AppData\Roaming\mozilla\Firefox\Profiles\c6mc4ufv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/01 16:24:47 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Johnry\AppData\Roaming\mozilla\Firefox\Profiles\c6mc4ufv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/04/14 00:25:45 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\mozilla\Firefox\Profiles\c6mc4ufv.default\extensions\[removed]
[2010/07/08 17:24:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/08/21 21:35:45 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/03/14 01:43:30 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/03/14 01:43:30 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/03/14 01:43:30 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/03/14 01:43:30 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DLCXCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL ()
O4 - HKLM..\Run: [dlcxmon.exe] C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe ()
O4 - HKLM..\Run: [ECenter] c:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [Logitech BT Wizard] File not found
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE (Logitech Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 926\memcard.exe ()
O4 - HKLM..\Run: [NMSSupport] C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe File not found
O4 - HKCU..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Dock.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Dock.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/04/30 03:57:32 | 000,054,544 | R— | M] (Electronic Arts) - E:\Autorun.exe – [ UDF ]
O32 - AutoRun File - [2008/10/22 00:48:37 | 000,000,045 | R— | M] () - E:\Autorun.inf – [ UDF ]
O33 - MountPoints2\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\Shell - "" = AutoRun
O33 - MountPoints2\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2010/07/08 21:15:22 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Johnry\Desktop\OTL.exe
[2010/07/08 18:28:33 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/07/08 17:18:44 | 000,000,000 | —D | C] – C:\Users\Johnry\AppData\Local\{196E6E73-C424-4595-AA03-8416C1463A31}
[2010/06/25 23:11:31 | 000,000,000 | —D | C] – C:\1fe119627cd859107d4408abb3c9ff02
[2010/06/23 23:44:57 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2010/06/23 23:44:57 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2010/06/23 23:44:56 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2010/06/23 11:02:41 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/06/23 11:02:40 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/06/16 23:18:17 | 000,000,000 | —D | C] – C:\Users\Johnry\Documents\Electronic Arts
[2010/06/09 12:13:16 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2010/06/09 12:13:14 | 000,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/06/09 12:13:14 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/06/09 12:13:04 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/06/09 12:13:04 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/06/09 12:13:04 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/06/09 12:13:03 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/06/09 12:13:03 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/06/09 12:13:03 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/06/09 12:13:03 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/06/09 12:13:03 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/06/09 12:13:03 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/06/09 12:13:03 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/06/09 12:13:03 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/06/09 12:13:03 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/06/09 12:13:03 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/06/09 12:13:03 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/06/09 12:13:03 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/06/09 12:13:00 | 002,037,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/01/19 18:28:58 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\dlcxhcp.dll
[2009/01/19 18:28:57 | 000,991,232 | —- | C] ( ) – C:\Windows\System32\dlcxusb1.dll
[2009/01/19 18:28:57 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\dlcxinpa.dll
[2009/01/19 18:28:57 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\dlcxiesc.dll
[2009/01/19 18:28:56 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\dlcxserv.dll
[2009/01/19 18:28:56 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\dlcxpmui.dll
[2009/01/19 18:28:56 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\dlcxprox.dll
[2009/01/19 18:28:56 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\dlcxpplc.dll
[2009/01/19 18:28:55 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\dlcxlmpm.dll
[2009/01/19 18:28:54 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\dlcxhbn3.dll
[2009/01/19 18:28:51 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\dlcxcomc.dll
[2009/01/19 18:28:51 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\dlcxcomm.dll
[2007/03/12 12:41:52 | 000,061,440 | —- | C] ( ) – C:\Windows\System32\vsnpstd3.dll
[2005/11/23 13:55:32 | 000,053,248 | —- | C] ( ) – C:\Windows\System32\csnpstd3.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Johnry\Documents\*.tmp files -> C:\Users\Johnry\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/08 21:50:23 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{31A8A415-450C-4E20-BE1A-A30144560375}.job
[2010/07/08 21:46:16 | 003,932,160 | —- | M] () – C:\Users\Johnry\ntuser.dat
[2010/07/08 21:32:03 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/08 21:24:56 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/08 21:24:56 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/08 21:15:45 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Johnry\Desktop\OTL.exe
[2010/07/08 19:26:16 | 000,033,167 | —- | M] () – C:\Windows\System32\Config.MPF
[2010/07/08 19:25:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/08 19:24:56 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/08 19:24:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/08 19:24:24 | 2145,570,816 | -HS- | M] () – C:\hiberfil.sys
[2010/07/08 19:23:48 | 000,524,288 | -HS- | M] () – C:\Users\Johnry\ntuser.dat{7bf5d16b-d1e6-11de-8ca3-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
[2010/07/08 19:23:48 | 000,065,536 | -HS- | M] () – C:\Users\Johnry\ntuser.dat{7bf5d16b-d1e6-11de-8ca3-806e6f6e6963}.TM.blf
[2010/07/08 19:23:28 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/07/08 19:23:13 | 006,291,456 | -H– | M] () – C:\Users\Johnry\AppData\Local\IconCache.db
[2010/07/04 16:09:29 | 000,000,766 | —- | M] () – C:\Users\Johnry\Desktop\CCleaner.lnk
[2010/07/02 20:03:25 | 000,062,976 | —- | M] () – C:\Users\Johnry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/01 01:00:03 | 000,000,354 | —- | M] () – C:\Windows\tasks\McQcTask.job
[2010/06/29 22:44:18 | 000,701,564 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/29 22:44:18 | 000,606,988 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/29 22:44:18 | 000,108,236 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/29 11:15:32 | 000,002,191 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/06/17 22:54:55 | 000,000,941 | —- | M] () – C:\Users\Public\Desktop\aTube Catcher.lnk
[2010/06/17 22:54:54 | 000,000,965 | —- | M] () – C:\Users\Johnry\Application Data\Microsoft\Internet Explorer\Quick Launch\aTube Catcher.lnk
[2010/06/16 23:16:57 | 000,001,859 | —- | M] () – C:\Users\Public\Desktop\The Sims™ 3.lnk
[2010/06/09 17:08:05 | 001,683,544 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/06/09 12:52:18 | 000,000,275 | —- | M] () – C:\Windows\win.ini
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Johnry\Documents\*.tmp files -> C:\Users\Johnry\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/08 18:31:45 | 2145,570,816 | -HS- | C] () – C:\hiberfil.sys
[2010/06/16 23:16:57 | 000,001,859 | —- | C] () – C:\Users\Public\Desktop\The Sims™ 3.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2010/02/19 00:55:53 | 000,290,904 | —- | C] () – C:\Windows\System32\vc6-re200l.dll
[2009/11/16 17:33:38 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2009/10/20 17:06:15 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/06/07 12:27:20 | 000,073,728 | —- | C] () – C:\Windows\System32\vbzlib1.dll
[2009/01/19 18:30:36 | 000,045,056 | —- | C] () – C:\Windows\System32\DLPRMON.DLL
[2009/01/19 18:30:36 | 000,032,768 | —- | C] () – C:\Windows\System32\DLPMONUI.DLL
[2009/01/19 18:28:58 | 000,274,432 | —- | C] () – C:\Windows\System32\dlcxinst.dll
[2009/01/19 18:28:57 | 000,454,656 | —- | C] () – C:\Windows\System32\dlcxutil.dll
[2009/01/19 18:28:55 | 000,176,128 | —- | C] () – C:\Windows\System32\dlcxinsb.dll
[2009/01/19 18:28:55 | 000,139,264 | —- | C] () – C:\Windows\System32\dlcxjswr.dll
[2009/01/19 18:28:55 | 000,106,496 | —- | C] () – C:\Windows\System32\dlcxinsr.dll
[2009/01/19 18:28:54 | 000,188,416 | —- | C] () – C:\Windows\System32\dlcxgrd.dll
[2009/01/19 18:28:54 | 000,176,128 | —- | C] () – C:\Windows\System32\dlcxins.dll
[2009/01/19 18:28:53 | 000,086,016 | —- | C] () – C:\Windows\System32\dlcxcub.dll
[2009/01/19 18:28:52 | 000,073,728 | —- | C] () – C:\Windows\System32\dlcxcu.dll
[2009/01/19 18:28:52 | 000,036,864 | —- | C] () – C:\Windows\System32\dlcxcur.dll
[2009/01/19 18:28:50 | 000,073,728 | —- | C] () – C:\Windows\System32\DLCXcfg.dll
[2007/10/06 15:31:47 | 000,278,984 | —- | C] () – C:\Windows\System32\drivers\atksgt.sys
[2007/10/06 15:31:46 | 000,025,416 | —- | C] () – C:\Windows\System32\drivers\lirsgt.sys
[2007/09/12 17:57:00 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2007/09/12 17:56:34 | 000,000,321 | —- | C] () – C:\Windows\game.ini
[2007/09/11 16:32:42 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2007/09/11 16:32:41 | 000,000,158 | —- | C] () – C:\Windows\wininit.ini
[2007/09/01 15:31:59 | 000,000,097 | —- | C] () – C:\Windows\lexstat.ini
[2007/08/30 20:40:11 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/07/31 02:08:41 | 000,101,376 | —- | C] () – C:\Windows\System32\APOMngr.dll
[2007/07/31 02:08:41 | 000,066,560 | —- | C] () – C:\Windows\System32\CmdRtr.dll
[2007/07/31 02:08:41 | 000,000,628 | —- | C] () – C:\Windows\System32\PCI_VEN_1102&DEV;_FF05&SUBSYS;_00001102.ini
[2006/11/07 20:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 08:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/10/28 11:31:44 | 000,344,064 | —- | C] () – C:\Windows\System32\dlcxcoin.dll
[2006/09/22 08:42:38 | 000,065,536 | —- | C] () – C:\Windows\System32\dlcxcaps.dll
[2006/09/16 23:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 23:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/08/08 16:58:04 | 000,692,224 | —- | C] () – C:\Windows\System32\dlcxdrs.dll
[2006/06/23 10:09:34 | 000,019,968 | R— | C] () – C:\Windows\System32\cpuinf32.dll
[2006/04/24 16:09:58 | 000,040,960 | —- | C] () – C:\Windows\System32\dlcxvs.dll
[2006/03/19 20:03:04 | 000,061,440 | —- | C] () – C:\Windows\System32\dlcxcnv4.dll
[2006/02/13 08:56:04 | 000,000,438 | —- | C] () – C:\Windows\System32\dlcxplc.ini
[2005/08/31 16:12:40 | 000,925,696 | —- | C] () – C:\Windows\System32\Flpcad.dll
[2004/02/27 17:36:18 | 000,015,498 | —- | C] () – C:\Windows\snpstd3.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI

========== LOP Check ==========

[2008/04/19 12:32:25 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Atari
[2008/05/25 20:20:53 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\AVSMedia
[2008/04/19 21:21:40 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\BitZipper
[2008/08/26 20:30:39 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Blender Foundation
[2009/09/07 15:01:36 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\com.zipeg
[2008/07/05 20:35:17 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2008/06/25 23:31:17 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Command & Conquer 3 Tiberium Wars Demo
[2007/11/17 18:18:11 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\GetRightToGo
[2010/06/07 09:18:03 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\gtk-2.0
[2008/02/21 12:27:56 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Imperium Romanum
[2008/04/19 15:11:26 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\LimeWire
[2007/11/16 19:40:37 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\ParetoLogic
[2008/12/28 21:21:12 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Red Alert 3
[2010/02/26 21:42:51 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\SystemRequirementsLab
[2007/08/22 22:39:03 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Template
[2009/03/06 15:21:10 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\The Creative Assembly
[2009/03/23 17:07:21 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Thunderbird
[2010/02/22 17:53:07 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Tropico 3
[2009/11/14 21:47:39 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\TuneUp Software
[2010/04/14 21:46:57 | 000,000,000 | —D | M] – C:\Users\Johnry\AppData\Roaming\Zipeg
[2009/11/15 02:57:21 | 000,000,352 | —- | M] () – C:\Windows\Tasks\McDefragTask.job
[2010/07/01 01:00:03 | 000,000,354 | —- | M] () – C:\Windows\Tasks\McQcTask.job
[2010/07/08 19:23:25 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/07/08 21:50:23 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{31A8A415-450C-4E20-BE1A-A30144560375}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2008/09/11 15:52:51 | 003,778,594 | —- | M] (Deakin University ) – C:\bluejsetup-221.exe
[2008/09/11 15:53:30 | 081,208,728 | —- | M] () – C:\jdk-6u7-windows-i586-p.exe


< MD5 for: AGP440.SYS >
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_51b95d75\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/19 08:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2007/07/31 09:43:20 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\System32\drivers\AGP440.sys
[2007/07/31 09:43:20 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_8ed06b47\AGP440.sys
[2007/07/31 09:43:20 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=8B10CE1C1F9F1D47E4DEB1A547A00CD4 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.16400_none_b82caac9c18a4e3b\AGP440.sys
[2007/07/31 09:43:19 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=BF34B4A0E0B64440C5389AA6B902F4AD – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6000.20496_none_b85af81edaeb8461\AGP440.sys
[2006/11/02 10:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/11 07:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\drivers\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
[2009/04/11 07:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 08:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/19 08:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 10:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007/07/31 09:43:59 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2007/07/31 09:43:50 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_5a9555b4\atapi.sys
[2007/07/31 09:43:50 | 000,021,688 | —- | M] (Microsoft Corporation) MD5=9E7E85EC61D1C9C3171CC08427108863 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20509_none_dbe4850d3d78c736\atapi.sys
[2007/07/31 09:43:59 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2007/07/31 09:43:59 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2008/02/14 00:35:17 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/02/14 00:35:17 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/02/14 00:35:16 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_64dfd8ea\atapi.sys
[2008/02/14 00:35:16 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 10:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 10:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2007/04/26 11:41:38 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Drivers\storage\R154092\iastor.sys
[2007/04/26 11:41:38 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Windows\System32\drivers\iaStor.sys
[2007/04/26 11:41:38 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Windows\System32\DriverStore\FileRepository\iaahci.inf_3a63e5a6\iaStor.sys
[2007/04/26 11:41:38 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Windows\System32\DriverStore\FileRepository\iastor.inf_5f6e7be5\iaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/19 08:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/19 08:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 10:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 10:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 10:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 07:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\System32\netlogon.dll
[2009/04/11 07:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 08:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 10:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 10:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 08:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/19 08:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 08:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 10:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/11 07:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\System32\scecli.dll
[2009/04/11 07:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/04/11 07:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 07:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 11:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 11:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
< End of report >



OTL Extras logfile created on: 08/07/2010 21:41:25 - Run 1
OTL by OldTimer - Version 3.2.8.1 Folder = C:\Users\Johnry\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.78 Gb Total Space | 93.17 Gb Free Space | 41.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.04 Gb Free Space | 60.36% Space Free | Partition Type: NTFS
Drive E: | 5.56 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SKEENOMAN
Current User Name: Johnry
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with &IrfanView;] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2596006179-2880176558-4285030344-1001]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0831E4E6-ED05-4213-ABCA-E163C22CB57E}" = lport=3390 | protocol=6 | dir=in | app=system |
"{0FF62BF8-98AB-43B6-BDF6-D710CB2F5DEC}" = rport=10244 | protocol=6 | dir=out | app=system |
"{1E788518-4E0D-4B22-805E-ECDD8F3B2E88}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{33A5EC7F-E855-4989-BF45-D3609FC124FC}" = lport=56086 | protocol=6 | dir=in | name=pando p2p tcp listening port |
"{36061718-6261-4821-BC2D-A4E89DD01FE0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{506E2E10-1728-4851-86AD-CE44DC6FF95F}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{56CBE537-F1B3-45A0-A14C-B0384D67C0D3}" = lport=3390 | protocol=6 | dir=in | app=system |
"{585859F4-4CD1-4000-A005-D625D3B20F19}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{6EAC6085-E4CA-46BB-B1BB-42C4DCE48154}" = lport=56086 | protocol=17 | dir=in | name=pando p2p udp listening port |
"{720FD548-6720-461D-92F3-3B8AED97B6D6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{761820CB-0202-4F18-AFB5-39F0B62B9D78}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{86D957E2-61BB-4DA7-8BBA-8F310451BDDC}" = lport=1900 | protocol=17 | dir=in | name=intel® viiv™ media server upnp discovery |
"{8D94BC9C-795D-4790-AC7F-93F49DB14E2A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9A19836F-4F3C-4CDA-A872-78ACA75C53F3}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A2F6C559-180A-4C74-9293-79806EE5D381}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A92EF9D6-2162-48E5-A54C-B7CAA6B0DC55}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AB0CBC07-A681-468D-AE97-CCF7C77F5DFA}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{B034D978-D9DE-40FC-97E2-94A32F0CABE8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B8292CD5-8038-4138-A7E8-A491CAAE54F0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BFB0D336-6ADB-4725-B151-10C30D001AFC}" = lport=10244 | protocol=6 | dir=in | app=system |
"{D4813E5C-C1C5-427C-BC9C-B3A002175B22}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E11B7D9A-52B0-4B22-8F14-7770B2CA10F6}" = rport=10244 | protocol=6 | dir=out | app=system |
"{E1493583-EFDD-4C3D-A69B-6FB2E6FEB528}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E4686AE9-6467-4BC6-A555-42311D90CA68}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EE834A21-021A-45DE-B88E-00474A10E311}" = lport=10244 | protocol=6 | dir=in | app=system |
"{F2237222-D808-4338-92A1-EF3AEBB6A75E}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{F465B18F-D805-4234-9834-FC7E3C278D18}" = lport=9442 | protocol=17 | dir=in | name=intel® viiv™ media server discovery |
"{F4BCCC26-C7CB-43BD-A97B-898419E01C52}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F613A5E2-5BD5-4817-AAD3-6EE83BA9F262}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F7597FB2-9286-4B3A-9BFE-E6BED8C1C4E4}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02D65ECC-0D46-4075-A083-E06EDD4BBDB2}" = protocol=6 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxmon.exe |
"{04FFECFB-943F-47C5-9772-3824430BF77B}" = protocol=6 | dir=in | app=c:\program files\thq\gas powered games\supreme commander\bin\supremecommander.exe |
"{0501E275-3ABF-4A0A-A24D-B99AD367551C}" = protocol=6 | dir=in | app=c:\windows\system32\dlcxcoms.exe |
"{08EA1F82-0341-4AC3-87DF-9E8D0ECB374F}" = protocol=17 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxaiox.exe |
"{09756117-59B3-4463-BCC0-08D3A07548CF}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{0BBB8AFE-0F23-4A5F-B68E-6EC4551639AD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0C92BA4A-0FC3-41EF-BF1D-45CFA4F68077}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{0EE72AC3-84A6-41B8-A041-A8F41058C40B}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{1589AB3D-72AC-4353-8919-47E9F5E40772}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{1714B3F5-5903-453C-B83C-3D4FF66B8F59}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{1847B6F4-B4E2-4F7C-9B50-723053AEDFE8}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{19573AA1-63FE-4CB5-8DFE-A771E06CF4C6}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{1961C61D-4764-454C-A96D-8C9AB9DB2A03}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{19854AF2-81AF-4AAB-BE83-34A020404022}" = protocol=17 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxmon.exe |
"{19DC3D53-C6B1-488E-A2B3-57DA39F59B30}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dawn of war 2\dow2.exe |
"{1AF12F0C-23D8-454B-BE1F-EB36ABCB3A59}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\shells\remote ui service.exe |
"{1D2C657D-19D0-4065-8F07-938026434147}" = protocol=6 | dir=in | app=c:\program files\ubisoft\the settlers 7 - paths to a kingdom\data\base\_dbg\bin\release\settlers7r.exe |
"{1EE352B6-0E70-4E42-8C4D-65A6B7577BD0}" = protocol=17 | dir=in | app=c:\windows\system32\dlcxcoms.exe |
"{1F973ACF-619B-47EA-8FC9-D2BBD0133C26}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{23AB83E3-49EC-4B8C-B655-62E919E26381}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\shattered_horizon\client_exe\shattered_horizon.exe |
"{2550ABD6-C256-47A3-8AF3-29E3409AF887}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{27B380DB-8F06-4866-83F4-31D14E021DBD}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2FC0E51C-B83B-4FE1-B909-F0D60E193547}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{311243E9-DF30-4E45-BA49-BA18BDD44BF9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\shattered_horizon\client_exe\shattered_horizon.exe |
"{35584576-1CD4-4AB9-85CB-AF2E7778EFD0}" = protocol=17 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxmon.exe |
"{369B199B-1025-4D7C-967E-2611D78D63C0}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{37D41170-0BC5-432C-BE1E-DDEE74968906}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{37DBCEED-EC6B-41E4-80C9-5BF18AAB2068}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{3AD12F96-FC71-4B87-B08F-95B46A977A91}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{3D2D4A73-E211-4571-BA89-485B5B4F580F}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{4105A75B-D2CC-488B-8A3A-53BF29C23947}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{45759295-3E81-407F-AFF5-78CFFE1BDCD1}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{4B31426A-7059-49D4-A514-09B538298DD2}" = protocol=6 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxaiox.exe |
"{4E1028CE-57E6-4481-A972-94DF16CC745A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tropico 3\tropico3.exe |
"{53966F69-284B-4AE0-91A2-77E41039C466}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{5844B574-71B8-47B4-B858-B7DD93DCF4A6}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\tshwmdtcp.exe |
"{5957FB4B-DE96-41FE-B9AB-0D2E395DAF94}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{5B4EA1CE-ADE8-4331-8DED-016E372C84EB}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{5D8E4B45-7B02-4E37-AD78-106C4A9F6BAB}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{5FBB6906-C9CA-4094-BE01-77A54097C250}" = dir=in | app=c:\program files\common files\microsoft shared\xna\xnatrans\v3.0\xnatransx.exe |
"{61DA51B6-291D-49DA-8D8F-6977E6EC5BE6}" = protocol=17 | dir=in | app=c:\windows\system32\dlcxcoms.exe |
"{68469854-7D3D-4DA5-9016-B99B7DA7FEE6}" = protocol=17 | dir=in | app=c:\program files\thq\gas powered games\gpgnet\gpg.multiplayer.client.exe |
"{6B55A4A8-7DC3-4C13-9874-51D3DEADEEE4}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{70B65917-BAE0-422F-8446-4A5F42A9DCA6}" = protocol=17 | dir=in | app=c:\program files\thq\gas powered games\supreme commander\bin\supremecommander.exe |
"{72C7FBE5-B9A5-4379-8B81-0F2E89A49CAC}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{7339421F-8A24-45BB-84F2-CA94C0BF616F}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{73D38AFE-E110-4996-90D8-269E1C883E36}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\mediaserver.exe |
"{759A6443-ED3A-4218-B9B6-0944ECF4D9AE}" = dir=in | app=c:\program files\microsoft xna\xna game studio\v3.1\bin\xnaliveproxy.exe |
"{7B6FC01C-25D3-41E4-98F5-6569D2E0575E}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{7D375FB0-CECA-4ACF-8462-C1B2883C1B32}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{7F6E7A2C-1169-4FDC-AA86-741C8CB93AA4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{81822F40-D3DD-4300-ADBA-232CD51C260F}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{8C709EDC-5F59-4D05-B29D-7D5C00474173}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{9036BA33-D142-4A11-823F-9911E715EB52}" = protocol=17 | dir=in | app=c:\program files\ubisoft\the settlers 7 - paths to a kingdom\data\base\_dbg\bin\release\settlers7r.exe |
"{90A36644-0517-41E1-94D9-B55513021085}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{92FBA8CE-3648-41D5-9AF8-6D529806FC45}" = protocol=6 | dir=in | app=c:\program files\thq\gas powered games\gpgnet\gpg.multiplayer.client.exe |
"{93A721A7-5778-46EC-92FB-FCDEFD8467BA}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{9456AB02-508E-4CB2-8834-7FED1F10774C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{95ACD4CD-6BA3-41BE-A54E-80531166DF87}" = protocol=17 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\tshwmdtcp.exe |
"{98154A20-B020-47EF-A9D1-AD36D6A2E5D8}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\shells\remote ui service.exe |
"{9A6CD295-A235-433D-BA54-3A005845685D}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{9D73E2AF-8CDD-42B7-BEA4-28A3C7D9E65D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9DBCEB40-CCB5-4A32-B4E0-7E7E2FF30DD0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{AA25DF69-65F3-4F5B-BCF1-1017F52487E2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{AB5317F6-9BFB-4380-BD02-6FC11BCD76B4}" = protocol=6 | dir=in | app=c:\windows\system32\dlcxcoms.exe |
"{BE267E98-2105-4C49-99E7-620A89ECBA47}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\empire total war\empire.exe |
"{BFA18124-4CF0-436A-9ED4-F90191A3F840}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{C05D9B27-0DAA-493E-8815-702819C6FDE8}" = protocol=6 | dir=in | app=c:\program files\intel\inteldh\intel media server\media server\bin\mediaserver.exe |
"{C319863C-2F47-4253-BEAC-E2D65A6C8812}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{C3742987-48C5-45B5-947B-F3DDB15923F5}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{C6BC1748-6671-4FEA-B8C1-B5A6F5BC44A9}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{CB0370F5-CC72-4F75-803A-E9C0716B757D}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{CE7A9F1A-7633-420D-8E24-D0A0FCB42F87}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\empire total war\empire.exe |
"{CFFD0BC0-9654-4457-8868-A2F59DAC83FE}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{D26341E4-EDB9-4189-9197-E94B250FE599}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{D58D3DCE-B44B-48BB-8C5F-6A5E2D7DDB64}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{D6335647-B9B0-4417-AD33-A61E6A770158}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tropico 3\tropico3.exe |
"{DD244C6C-5205-4184-94FD-F3656C10C3FA}" = protocol=17 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxaiox.exe |
"{DD662B43-294A-4586-A994-F63DB127F673}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dawn of war 2\dow2.exe |
"{E43AF0EB-F3C7-43E5-B419-28EE15F00332}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{E6238FA8-B8D0-45F2-A9AA-AFA496988C5E}" = protocol=6 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxaiox.exe |
"{F0F8DE5D-8EF0-4C0F-A036-C24D8130C181}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{F1EFB473-0C54-4915-B7A8-50174C7C72BF}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{F2E85F04-A111-4E75-BBC9-A6D807C6484F}" = protocol=6 | dir=in | app=c:\program files\dell photo aio printer 926\dlcxmon.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00405945-70C1-4B1D-9A3C-45A2883366AF}" = PS_AIO_05_C4600_Software_Min
"{007BECB0-17DD-4230-9D2F-185287262B14}" = Microsoft XNA Game Studio 3.1 (Platformer)
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0DAA5653-60D4-44C1-AD10-EC7D4FA4D820}" = Intel® Viiv™ Software
"{0DC16794-7E69-4534-82FA-9DD0500FF338}" = Microsoft XNA Game Studio 3.1 (Redists)
"{0FA7B858-E0E1-400B-B5C0-1285F7D6FE5E}" = 926plv32
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1296CAF3-F007-4813-A95F-AD153F978DF1}" = AVRStudio4
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{14C35072-D7D0-4B29-B5BF-C94E426D77E9}" = Sky Broadband
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{26A24AE4-039D-4CA4-87B4-2F83216014F0}" = Java™ 6 Update 14
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = SetPoint
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java™ SE Development Kit 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java™ SE Development Kit 6 Update 14
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3BA37E38-B53D-4520-B8DA-1DD62AD3A74E}" = Microsoft XNA Game Studio 3.1 (VCSExpress)
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{44C81D1A-0520-49BB-B510-98B8DD414EA1}" = HP Photosmart C4600 All-In-One Driver Software 13.0 Rel .5
"{48DE8338-F3D2-44C5-A0F5-81C27B9FA451}" = Programming Editor
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.11.0
"{7CDD7C4C-5224-40E4-951F-51C12FEAB8AB}" = C4600
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{7FD30AE7-281D-455F-AF9F-0C6C5E334EAD}" = Microsoft XNA Game Studio 3.1 Documentation
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}" = CDDRV_Installer
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9060B698-2B29-4A1F-B876-BEAC4C0A25D5}" = KhalSetup
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{9C916142-C18C-429D-BFED-40094A7E0BEB}" = The Settlers 7 - Paths to a Kingdom
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A4418082-E601-3954-805B-D56A2B50EC8B}" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.5
"{AC76BA86-7AD7-1033-7B44-A81300000003}_814" = KB408682
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{AF9BDE67-11A5-449A-B9F0-BE572A093DDB}" = Microsoft XNA Game Studio 3.1 (Shared Components)
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}" = Dell Support Center
"{B946D46E-1302-48B4-84EE-B74C3191D975}" = Corel Painter Essentials 2
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BED4CEEC-863F-4AB3-BA23-541764E2D2CE}" = Microsoft XNA Game Studio Platform Tools
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C69405BB-27AF-4940-B3DA-04910B4DFD23}_is1" = aTube Catcher 1.0
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{D5D88F8F-FDA4-4CF4-9F3E-3F40118C2120}" = AVRStudio4
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DFB81F19-ED3A-4DA5-AFE4-1B999E2A8DC5}" = Microsoft XNA Game Studio 3.1 (XnaLiveProxy)
"{E10DB5DA-E576-40EA-A7FC-1CB2A7B283A6}" = NVIDIA PhysX
"{E1D78366-91DA-4AD0-B417-28155743CC22}" = Microsoft XNA Game Studio 3.1 (ARP entry)
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"aTube Catcher" = aTube Catcher
"BlueJ_is1" = BlueJ 2.2.1
"CCleaner" = CCleaner
"Company of Heroes" = Company of Heroes
"Dell PC Fax" = Dell PC Fax
"Dell Photo AIO Printer 926" = Dell Photo AIO Printer 926
"FMCODEC" = FM Screen Capture Codec (Remove Only)
"Google Desktop" = Google Desktop
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"Intel® Configuration Center" = Intel® Viiv™ Software
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Visual C# 2008 Express Edition with SP1 - ENU" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"mpegable DS" = mpegable DS decoder
"MSC" = McAfee SecurityCenter
"MS-MPEG4" = Microsoft MPEG-4 VKI Video Codec V1/V2/V3
"nbi-nb-base-6.5.1.0.200903060201" = NetBeans IDE 6.5.1
"NVIDIA Drivers" = NVIDIA Drivers
"Pen Tablet Driver" = Pen Tablet
"PROSetDX" = Intel® PRO Network Connections 12.1.11.0
"Shop for HP Supplies" = Shop for HP Supplies
"Steam App 10500" = Empire: Total War
"Steam App 10600" = Empire: Total War - Special Forces Unit
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"Steam App 20570" = Warhammer 40,000: Dawn of War II - Chaos Rising
"Steam App 23490" = Tropico 3: Steam Special Edition
"Steam App 40100" = Supreme Commander 2
"SystemRequirementsLab" = System Requirements Lab
"VLC media player" = VLC media player 1.0.0
"Wacom Tablet Driver" = Wacom Tablet
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1
"XNA Game Studio 3.1" = Microsoft XNA Game Studio 3.1
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"YInstHelper" = Yahoo! Install Manager
"Zipeg" = Zipeg

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26/03/2009 13:30:13 | Computer Name = Skeenoman | Source = VSS | ID = 8194
Description =

Error - 29/03/2009 07:55:32 | Computer Name = Skeenoman | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 2352 (0x930) Thread address : 0x77989A94 Thread message : Build VSCORE.14.0.0.414
/ 5301.4018 Object being scanned = \Device\HarddiskVolume3\Users\Johnry\Documents\My
Games\Company of Heroes\Patch\EN_140_2101_Patch.exe by C:\Program Files\AVG\AVG8\avgcsrvx.exe

4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)


Error - 30/03/2009 10:44:11 | Computer Name = Skeenoman | Source = Application Error | ID = 1000
Description = Faulting application AUDIODG.EXE, version 6.0.6001.18000, time stamp
0x47919284, faulting module CTAPO32.dll, version 1.0.0.310, time stamp 0x468b125c,
exception code 0xc0000005, fault offset 0x0001f6b5, process id 0x538, application
start time 0x01c9b145e171ece2.

Error - 04/04/2009 17:59:14 | Computer Name = Skeenoman | Source = Application Error | ID = 1000
Description = Faulting application gimp-2.4.exe, version 0.0.0.0, time stamp 0x48af3778,
faulting module libgdk-win32-2.0-0.dll, version 2.12.11.0, time stamp 0x48af3b59,
exception code 0xc0000005, fault offset 0x00034625, process id 0x168, application
start time 0x01c9b53d2bb12430.

Error - 05/04/2009 07:58:32 | Computer Name = Skeenoman | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 2264 (0x8d8) Thread address : 0x77939A94 Thread message : Build VSCORE.14.0.0.414
/ 5301.4018 Object being scanned = \Device\HarddiskVolume3\Users\Johnry\Documents\My
Games\Company of Heroes\Patch\EN_140_2101_Patch.exe by C:\Program Files\AVG\AVG8\avgcsrvx.exe

4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)


Error - 06/04/2009 11:13:59 | Computer Name = Skeenoman | Source = Application Hang | ID = 1002
Description = The program Empire.exe version 1.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: b54 Start Time: 01c9b6afec64d0df Termination Time: 1935

Error - 08/04/2009 08:52:59 | Computer Name = Skeenoman | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 3960 (0xf78) Thread address : 0x77DB9A94 Thread message : Build VSCORE.14.0.0.414
/ 5301.4018 Object being scanned = \Device\HarddiskVolume3\Users\Johnry\Documents\My
Games\Company of Heroes\Patch\EN_140_2101_Patch.exe by C:\Program Files\AVG\AVG8\avgcsrvx.exe

4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)


Error - 10/04/2009 12:33:50 | Computer Name = Skeenoman | Source = VSS | ID = 8194
Description =

Error - 10/04/2009 12:34:21 | Computer Name = Skeenoman | Source = System Restore | ID = 8193
Description =

Error - 12/04/2009 08:11:33 | Computer Name = Skeenoman | Source = McLogEvent | ID = 5051
Description = A thread in process C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe took
longer than 90000 ms to complete a request. The process will be terminated. Thread
id : 2180 (0x884) Thread address : 0x770F9A94 Thread message : Build VSCORE.14.0.0.414
/ 5301.4018 Object being scanned = \Device\HarddiskVolume3\Users\Johnry\Documents\My
Games\Company of Heroes\Patch\EN_140_2101_Patch.exe by C:\Program Files\AVG\AVG8\avgcsrvx.exe

4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)


[ IntelDH Events ]
Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

Error - 03/08/2007 14:56:30 | Computer Name = Johnry-PC | Source = AlertService | ID = 15
Description = A CCU internal function detected an error: XMLDoc::LoadXML failed
with reason: XML document must have a top level element.

[ Media Center Events ]
Error - 26/04/2008 17:24:41 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerAccumulate failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 23/05/2008 15:46:12 | Computer Name = Skeenoman | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 25/05/2008 14:29:10 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 26/05/2008 05:46:24 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 13/08/2008 10:43:40 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 18/08/2008 12:55:27 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerAccumulate failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 08/11/2008 18:43:29 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.WaitForUploadComplete failed. Please
try to ping www.msn.com prior to filing a bug.; Win32 GetLastError returned 10000109
Process: DefaultDomain Object Name: Media Center Guide

Error - 20/02/2009 10:10:43 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 18/04/2009 07:26:34 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

Error - 04/06/2009 15:12:54 | Computer Name = Skeenoman | Source = Media Center Guide | ID = 0
Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

[ System Events ]
Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:20:05 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =

Error - 08/07/2010 14:21:56 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7032
Description =

Error - 08/07/2010 14:21:56 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7032
Description =

Error - 08/07/2010 14:47:13 | Computer Name = Skeenoman | Source = Service Control Manager | ID = 7031
Description =


< End of report >



I ran GMER but it stopped working while it was scanning and closed down.
Hello skeeno

Thank you for the OTL log.

I manage to run a MBAM scan and I quarantined and removed the stuff that scan found

Please post the MBAM log that was created when you performed the scan (It can be found by opening MBAM and clicking on the "Logs" tab).

I ran GMER but it stopped working while it was scanning and closed down.

Lets try this:


  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".


    • If GMER fails to compete, please try RootRepeal:

  • RootRepeal


    • Please download RootRepeal to your desktop
    • Physically disconnect your machine from the internet as your system will be unprotected.
    • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
    • Click the Report tab at the bottom and then the Scan button.
    • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
    • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
    • The scan will take a little while to run, so let it go unhindered.
    • Once it is done, click the "Save Report" button, call it RepealScan and save the log to your desktop.
    • Reconnect to the internet.

    Please provide the GMER/Rootrepeal log in your next reply. If you are still having trouble, come back and let me know.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4144 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18928 08/07/2010 19:22:25 mbam-log-2010-07-08 (19-22-25).txt Scan type: Quick scan Objects scanned: 158397 Time elapsed: 12 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\efopi (Trojan.Agent.U) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vgotodu (Trojan.Agent.U) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Users\Johnry\Favorites\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\Users\Johnry\Desktop\nudetube.com.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Users\Johnry\Desktop\pornotube.com.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Users\Johnry\Desktop\youporn.com.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Users\Johnry\AppData\Local\owonexilahetil.dll (Trojan.Agent.U) -> Delete on reboot. C:\Users\Johnry\AppData\Local\wmsmir.dll (Trojan.Agent.U) -> Delete on reboot. C:\Users\Johnry\AppData\Local\Temp\0.09394617122084892.exe (Trojan.Dropper) -> Quarantined and deleted successfully. manage to scan using GMER by unchecking everything but the two you listed, but after i saved it onto the desktop i got a blue screen and my pc rebooted. 📎Gmer.txt I have a question, when i run GMER there it does a kind of quick scan is that normal?
Hello skeeno

I have a question, when i run GMER there it does a kind of quick scan is that normal?

GMER will perform a quick "pre-scan" before asking you if you want to perform a full scan. This is normal.

Unfortunately, the GMER log you attached is empty. If you were unable to save the log (or if no data was created in it) please try RootRepeal.
Back again. After I posted the MBAM log my PC slowed down for a few seconds and the task bar and the menu changed to the safe mode theme and went back to the vista theme. A message popped up saying "Host Process to windows services stopped working and was closed". I used Rootrepeal but while scanning an empty pop up window appeared, which I closed which made rootrepeal stop responding and it closed. I only switched of my anti-spyware,anti virus and firewall but left other parts of mcAfee on like phising protection,identity protection,systemguards,window protection,spam protection, email protection and IM protection. Should I close all of these as well? and retry rootrepeal?
Hello skeeno

Should I close all of these as well? and retry rootrepeal?

Please do, then re-enable all of your security once the scan has finished :)

If it still fails to complete let me know.
tried again with everything switched off and the same thing happened a small transparent window showed up, I closed it and rootrepeal stoped responding.
Hello skeeno

Thank you for letting me know.

It looks as though we are going to have to do without an ARK scan for the moment. Please work your way through the following steps:


  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O4 - HKLM..\Run: [] File not found
      O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe File not found
      O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - File not found
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
      O33 - MountPoints2\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\Shell - "" = AutoRun
      O33 - MountPoints2\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      [1 C:\Users\Johnry\Documents\*.tmp files -> C:\Users\Johnry\Documents\*.tmp -> ]
      
      :Files
      C:\Users\Johnry\AppData\Roaming\LimeWire
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • MalwareBytes AntiMalware:


    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.


Please post the OTL log and the MBAM log in your next reply.

Also, please describe how your machine is behaving now. Are you still experiencing symptoms?
All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08E730A4-FB02-45BD-A900-01E4AD8016F6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08E730A4-FB02-45BD-A900-01E4AD8016F6}\ not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\Windows\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{981f0c1f-137e-11dd-89b8-001aa08e5b0c}\ not found. File H:\LaunchU3.exe not found. C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP\WiseCustomCalla.dll deleted successfully. C:\Windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP folder deleted successfully. C:\Users\Johnry\Documents\~WRL2818.tmp deleted successfully. ========== FILES ========== C:\Users\Johnry\AppData\Roaming\LimeWire\xml\schemas folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\xml\misc folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\xml\data folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\xml folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\themes\windows_theme folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\themes folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\.NetworkShare folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire\.AppSpecialShare folder moved successfully. C:\Users\Johnry\AppData\Roaming\LimeWire folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 83 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: IUSR_NMPR ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Johnry ->Temp folder emptied: 2801496 bytes ->Temporary Internet Files folder emptied: 304396 bytes ->Java cache emptied: 77466452 bytes ->FireFox cache emptied: 54889788 bytes ->Flash cache emptied: 6542 bytes User: Mcx1 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 36322542 bytes ->Flash cache emptied: 526 bytes User: Mcx2 ->Temp folder emptied: 1340 bytes ->Temporary Internet Files folder emptied: 4861216 bytes ->Flash cache emptied: 83 bytes User: Public User: skeenoman %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 43737 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 169.00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: IUSR_NMPR User: Johnry ->Flash cache emptied: 0 bytes User: Mcx1 ->Flash cache emptied: 0 bytes User: Mcx2 ->Flash cache emptied: 0 bytes User: Public User: skeenoman Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.8.1 log created on 07092010_220512 Files\Folders moved on Reboot… File\Folder C:\Windows\temp\mcmsc_71AfjomOSjE77fU not found! File\Folder C:\Windows\temp\mcmsc_PjCaZDL3qa8NLUa not found! File\Folder C:\Windows\temp\sqlite_A521kOBwm4eELa9 not found! File\Folder C:\Windows\temp\sqlite_FzibbbeN4YldA6x not found! File\Folder C:\Windows\temp\sqlite_K2Wik0EQ3gDpTTV not found! File\Folder C:\Windows\temp\sqlite_QXAbUgxQmRcZpvj not found! Registry entries deleted on Reboot… Im running the MBAM scan now and it might take a while. I havent seen anything suspicious since the time I posted the last MBAM log, as I've been switched my pc off and only turning it on to look at this thread as i'm a bit paranoid :P is that ok? or should I let in run like i would normaly do which is basicly the whole day.
sorry for double posting but while scanning some of the symptoms came back again such as the window telling me that Host Process to windows services stopped working and was closed and the computer randomly slowed down for a few seconds and the vista theme fo the taskbar turning white and the browser window blacking out for a second and going back to normal again
Hello skeeno

Is MBAM still scanning?

If you are able to continue with the scan please post the log that is created. If MBAM is prevented from completing its run, please let me know and we will try a different approach.
Yeah its still running however my desktop refreshed itself and task bar has been changed from the vista theme into a white one with blue font MBAM finnaly finished. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4298 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18928 10/07/2010 00:17:53 mbam-log-2010-07-10 (00-17-53).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 330841 Time elapsed: 1 hour(s), 59 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello skeeno

Thanks for the log.

Please work your way through the following steps. If you encounter any difficulties come back and let me know.


  • Download Combofix and RE-NAME it BEFORE saving


  • Download Combofix from either of the links below. You must rename it to skeeno.exe before saving it.
  • Save it to your desktop. Change the "save as file type" to "all files".
  • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.


  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.


  • Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI