This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infostealer.Snifula.B, viruses, internet loss. logs included

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Recently ive been having problems, I installed Norton a few days ago because my Mcafee subscription ran out, Norton detected a virus called Infostealer.Snifula.B and other viruses which I needed help removing. I ran Malwarebytes and it was unable to find anything in normal mode and safe mode. Then I tried Norton scan and it said it fixed 6 issues but the problem still remains. Please HELP!!

I was unable to install DDS because it is "Incompatible with my operating system." Im using Windows 7 and its not letting me run it as an administrator. I am going to post my Hijackthis logs and OTL logs now.

Hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:30:54 PM, on 7/14/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
C:\Windows\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Rizwan\Desktop\OTL.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe -A
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [c12033ab6] wscript "C:\Windows\System32\c12033ab6.eb3" //b //e:vbscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O23 - Service: McAfee Application Installer Cleanup (0240251277873153) (0240251277873153mcinstcleanup) - Unknown owner - C:\Users\Rizwan\AppData\Local\Temp\024025~1.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11055 bytes
OTL:

OTL logfile created on: 7/14/2010 5:19:02 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\Rizwan\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 76.00% Memory free
12.00 Gb Paging File | 11.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.41 Gb Total Space | 867.42 Gb Free Space | 94.65% Space Free | Partition Type: NTFS
Drive D: | 620.40 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RIZWAN-PC
Current User Name: Rizwan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Rizwan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe (IOI)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Rizwan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (PnkBstrB) – C:\Windows\SysNative\PnkBstrB.exe File not found
SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Greg_Service) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys File not found
DRV:64bit: - (DgiVecp) – C:\Windows\SysNative\Drivers\DgiVecp.sys File not found
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symtdiv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds64.sys (Symantec Corporation)
DRV:64bit: - (KeyScrambler) – C:\Windows\SysNative\drivers\keyscrambler.sys (QFX Software Corporation)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (SSPORT) – C:\Windows\SysNative\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100714.002\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100714.002\ENG64.SYS (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100709.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100713.001\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.5.4
FF - prefs.js..extensions.enabledItems: [removed]:2.6.0.0
FF - prefs.js..extensions.enabledItems: [removed]:2.0.7
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 49
FF - prefs.js..extensions.enabledItems: {7CB0C7E9-81C0-42A2-9E27-7E56BD1B9332}:1.9.1
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{7CB0C7E9-81C0-42A2-9E27-7E56BD1B9332}: C:\Users\Rizwan\AppData\Local\{7CB0C7E9-81C0-42A2-9E27-7E56BD1B9332} [2010/06/01 23:32:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/07/14 13:48:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/07/13 20:46:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/12 23:53:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/12 22:53:36 | 000,000,000 | —D | M]

[2010/07/06 15:03:21 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Extensions
[2010/07/06 15:03:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/07/14 01:05:30 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions
[2010/07/04 03:26:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/28 20:01:15 | 000,000,000 | —D | M] (No name found) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/12/29 16:56:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}
[2010/07/05 23:44:43 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/03 01:22:27 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/07/01 18:36:35 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\[removed]
[2010/01/18 20:03:56 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\[removed]
[2010/07/01 18:38:38 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\[removed]
[2010/07/13 23:48:14 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/07/12 12:10:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [c12033ab6] File not found
O4 - HKLM..\Run: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe (IOI)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9:64bit: - Extra 'Tools' menuitem : &KeyScrambler; Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler; Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [1998/12/13 01:43:32 | 000,000,040 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{05898bf2-b43b-11de-ab29-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{05898bf2-b43b-11de-ab29-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE – [1998/11/30 23:04:40 | 000,025,600 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: InfDfpmp - (C:\Windows\system32\iscsperf.dll) - C:\Windows\SysWOW64\iscsperf.dll ()
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/07/14 17:17:01 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Rizwan\Desktop\OTL.exe
[2010/07/14 16:42:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spyware Doctor
[2010/07/14 16:42:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2010/07/14 16:42:42 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/07/14 01:34:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/07/14 00:30:47 | 000,451,120 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symtdiv.sys
[2010/07/14 00:30:47 | 000,221,232 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa64.sys
[2010/07/14 00:30:46 | 000,615,040 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.sys
[2010/07/14 00:30:46 | 000,505,392 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.sys
[2010/07/14 00:30:46 | 000,433,200 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds64.sys
[2010/07/14 00:30:46 | 000,150,064 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\ironx64.sys
[2010/07/14 00:30:46 | 000,032,304 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.sys
[2010/07/14 00:30:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\0402000.00C
[2010/07/13 20:47:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2010/07/13 20:46:41 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/07/13 20:46:41 | 000,126,312 | R— | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2010/07/13 20:46:41 | 000,107,368 | R— | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2010/07/13 20:46:41 | 000,034,152 | R— | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/07/13 20:46:41 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/07/13 20:46:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/07/13 20:46:30 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/07/13 20:46:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64
[2010/07/13 20:46:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Security Suite
[2010/07/13 20:46:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2010/07/12 12:10:15 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/07/12 12:10:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/07/12 12:10:04 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/07/12 12:10:04 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/07/12 12:10:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/07/12 12:10:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/07/12 12:05:25 | 008,587,672 | —- | C] (Mozilla) – C:\Users\Rizwan\Desktop\Firefox Setup 3.6.4.exe
[2010/07/12 11:31:43 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\google-sitemap-generator
[2010/07/12 01:54:32 | 000,000,000 | R–D | C] – C:\Users\Rizwan\Desktop\WTF is this
[2010/07/12 01:52:45 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\IMM and SEO
[2010/07/06 15:03:20 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Roaming\Thunderbird
[2010/07/06 15:03:20 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Local\Thunderbird
[2010/07/01 16:59:05 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\Website stuff
[2010/07/01 13:51:31 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\Cool pictures
[2010/07/01 13:50:12 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\php_speedy_wp_0.5.2
[2010/06/29 22:45:16 | 000,000,000 | —D | C] – C:\Users\Rizwan\Documents\Symantec
[2010/06/25 13:41:44 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\top10_01
[2010/06/25 13:41:21 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\all-in-one-seo-pack
[2010/06/23 03:04:29 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010/06/23 03:04:29 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/06/23 03:04:29 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010/06/23 03:04:29 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/06/23 03:04:29 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/06/23 03:04:29 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/06/23 03:04:29 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/06/23 03:04:29 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010/06/22 17:50:15 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010/06/22 17:50:08 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/06/22 17:50:08 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/06/22 17:50:08 | 000,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2010/06/22 17:50:07 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/06/22 17:50:07 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/06/22 17:50:07 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/06/22 17:50:07 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/06/21 07:53:17 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Roaming\Facebook

========== Files - Modified Within 30 Days ==========

[2010/07/14 17:22:23 | 002,621,440 | -HS- | M] () – C:\Users\Rizwan\ntuser.dat
[2010/07/14 17:20:27 | 000,359,929 | —- | M] () – C:\Users\Rizwan\Desktop\dds.scr
[2010/07/14 17:19:46 | 001,159,318 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\Cat.DB
[2010/07/14 17:18:11 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/14 17:18:11 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/14 17:17:02 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Rizwan\Desktop\OTL.exe
[2010/07/14 17:15:31 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/14 17:15:31 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/14 17:15:31 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/14 17:10:32 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/14 17:10:19 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/14 17:10:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/14 17:10:09 | 509,456,383 | -HS- | M] () – C:\hiberfil.sys
[2010/07/14 16:37:43 | 012,482,490 | —- | M] () – C:\Users\Rizwan\Desktop\registry.reg
[2010/07/14 15:51:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/14 01:34:19 | 000,002,981 | —- | M] () – C:\Users\Rizwan\Desktop\HiJackThis.lnk
[2010/07/14 01:03:48 | 000,002,435 | —- | M] () – C:\Users\Public\Desktop\Norton Security Suite.lnk
[2010/07/13 20:46:30 | 000,173,104 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/07/13 20:46:30 | 000,007,440 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/07/13 20:46:30 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/07/13 20:46:06 | 000,001,372 | —- | M] () – C:\Users\Rizwan\Desktop\Norton Installation Files.lnk
[2010/07/13 20:38:15 | 000,006,069 | —- | M] () – C:\Windows\SysWow64\c12033ab6.eb3
[2010/07/13 00:37:35 | 000,030,662 | —- | M] () – C:\Users\Rizwan\Desktop\pokemon.JPG
[2010/07/12 22:58:58 | 000,005,442 | —- | M] () – C:\.htaccess
[2010/07/12 12:54:49 | 000,001,970 | —- | M] () – C:\Users\Rizwan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/12 12:54:49 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/12 12:05:38 | 008,587,672 | —- | M] (Mozilla) – C:\Users\Rizwan\Desktop\Firefox Setup 3.6.4.exe
[2010/07/12 11:31:22 | 000,002,007 | —- | M] () – C:\Users\Public\Desktop\FileZilla Client.lnk
[2010/07/06 13:24:24 | 000,044,032 | —- | M] () – C:\Users\Rizwan\Desktop\Amazon Codes Generator.exe
[2010/06/29 22:41:03 | 000,000,000 | —- | M] () – C:\Users\Rizwan\AppData\Local\Jgohanedev.bin
[2010/06/25 19:01:13 | 000,000,120 | —- | M] () – C:\Users\Rizwan\AppData\Local\Mbezivewavadej.dat
[2010/06/16 03:01:02 | 000,524,288 | -HS- | M] () – C:\Users\Rizwan\ntuser.dat{d0b77bc2-7471-11df-87c1-002511a5ba56}.TMContainer00000000000000000002.regtrans-ms
[2010/06/16 03:01:02 | 000,524,288 | -HS- | M] () – C:\Users\Rizwan\ntuser.dat{d0b77bc2-7471-11df-87c1-002511a5ba56}.TMContainer00000000000000000001.regtrans-ms
[2010/06/16 03:01:02 | 000,065,536 | -HS- | M] () – C:\Users\Rizwan\ntuser.dat{d0b77bc2-7471-11df-87c1-002511a5ba56}.TM.blf

========== Files Created - No Company Name ==========

[2010/07/14 17:20:27 | 000,359,929 | —- | C] () – C:\Users\Rizwan\Desktop\dds.scr
[2010/07/14 16:37:43 | 012,482,490 | —- | C] () – C:\Users\Rizwan\Desktop\registry.reg
[2010/07/14 01:34:19 | 000,002,981 | —- | C] () – C:\Users\Rizwan\Desktop\HiJackThis.lnk
[2010/07/14 01:03:04 | 001,159,318 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\Cat.DB
[2010/07/14 00:30:47 | 000,007,829 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa64.cat
[2010/07/14 00:30:47 | 000,007,787 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnetv64.cat
[2010/07/14 00:30:47 | 000,007,368 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnet64.cat
[2010/07/14 00:30:47 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa.inf
[2010/07/14 00:30:47 | 000,001,473 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnetv.inf
[2010/07/14 00:30:47 | 000,001,445 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnet.inf
[2010/07/14 00:30:46 | 000,007,414 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.cat
[2010/07/14 00:30:46 | 000,007,410 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.cat
[2010/07/14 00:30:46 | 000,007,406 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds64.cat
[2010/07/14 00:30:46 | 000,007,402 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\iron.cat
[2010/07/14 00:30:46 | 000,007,358 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.cat
[2010/07/14 00:30:46 | 000,002,793 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds.inf
[2010/07/14 00:30:46 | 000,001,838 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.inf
[2010/07/14 00:30:46 | 000,001,437 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.inf
[2010/07/14 00:30:46 | 000,001,421 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.inf
[2010/07/14 00:30:46 | 000,000,771 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\iron.inf
[2010/07/14 00:30:26 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\isolate.ini
[2010/07/13 20:46:41 | 000,007,440 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/07/13 20:46:41 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/07/13 20:46:27 | 000,002,435 | —- | C] () – C:\Users\Public\Desktop\Norton Security Suite.lnk
[2010/07/13 00:37:34 | 000,030,662 | —- | C] () – C:\Users\Rizwan\Desktop\pokemon.JPG
[2010/07/12 22:58:58 | 000,005,442 | —- | C] () – C:\.htaccess
[2010/07/10 02:36:51 | 000,001,970 | —- | C] () – C:\Users\Rizwan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/10 02:36:51 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/06 13:24:23 | 000,044,032 | —- | C] () – C:\Users\Rizwan\Desktop\Amazon Codes Generator.exe
[2010/06/29 22:43:26 | 000,001,372 | —- | C] () – C:\Users\Rizwan\Desktop\Norton Installation Files.lnk
[2010/06/01 23:31:13 | 000,040,960 | -H– | C] () – C:\Windows\SysWow64\iscsperf.dll
[2010/02/19 22:18:00 | 000,000,011 | —- | C] () – C:\Windows\SysWow64\KB.DLL
[2009/12/06 18:24:07 | 000,000,247 | —- | C] () – C:\Windows\w32dasm8.ini
[2009/12/03 01:06:39 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/06/14 00:26:01 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Babylon
[2010/06/21 07:53:18 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Facebook
[2010/07/12 23:03:57 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\FileZilla
[2009/12/06 15:30:46 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\G-Lock Software
[2009/12/03 18:43:03 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Packard Bell
[2009/12/13 01:12:10 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\TeamViewer
[2010/03/10 22:47:49 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Template
[2010/07/06 15:03:21 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Thunderbird
[2010/05/31 18:14:06 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\TS3Client
[2010/05/31 18:14:06 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Wippien
[2009/07/13 23:08:49 | 000,022,412 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 19:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 19:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 19:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 19:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 19:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 19:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 19:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 19:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009/06/04 04:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\OEM\Preload\Autorun\DRV\Intel Storage Generic Driver\IaStor.sys
[2009/06/04 04:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2009/06/04 04:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Windows\SysWow64\DriverStore\FileRepository\iastor.inf_amd64_neutral_c065a1006c648409\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/13 19:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 19:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 19:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 19:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 19:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 19:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 19:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 19:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 19:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 19:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 19:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 19:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
OTL Extras:

OTL Extras logfile created on: 7/14/2010 5:19:03 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\Rizwan\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 76.00% Memory free
12.00 Gb Paging File | 11.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.41 Gb Total Space | 867.42 Gb Free Space | 94.65% Space Free | Partition Type: NTFS
Drive D: | 620.40 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RIZWAN-PC
Current User Name: Rizwan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{30075A70-B5D2-440B-AFA3-FB2021740121}" = Backup Manager Advance
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40a87585-3dea-47d0-8aac-c7c19689b431}" = Nero 9 Essentials
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{81063354-9060-42B2-A000-1EBE96778AA9}" = iTunes
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner
"Fast Blog Finder 3_is1" = Fast Blog Finder 3
"Fast Blog Finder_is1" = Fast Blog Finder 2.60
"FileZilla Client" = FileZilla Client 3.3.3
"Gateway Photo Frame" = Gateway Photo Frame [removed]
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}" = Gateway MyBackup
"KeyScrambler" = KeyScrambler
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"N360" = Norton Security Suite
"Samsung CLX-3170 Series" = Samsung CLX-3170 Series
"Starcraft" = Starcraft
"StarCraft II Beta" = StarCraft II Beta
"WildTangent gateway Master Uninstall" = Gateway Games
"Wolfenstein - Enemy Territory" = Wolfenstein - Enemy Territory
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/3/2010 5:01:24 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 1024
Description =

Error - 7/3/2010 5:02:22 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 7/3/2010 5:02:22 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 7/3/2010 5:02:22 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 1024
Description =

Error - 7/3/2010 5:03:19 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 7/3/2010 5:03:19 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 7/3/2010 5:03:19 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 1024
Description =

Error - 7/3/2010 5:04:16 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 7/3/2010 5:04:16 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 7/3/2010 5:04:16 AM | Computer Name = Rizwan-PC | Source = MsiInstaller | ID = 1024
Description =

[ Media Center Events ]
Error - 1/23/2010 6:37:46 PM | Computer Name = Rizwan-PC | Source = MCUpdate | ID = 0
Description = 3:37:44 PM - Failed to retrieve SportsSchedule-2.enc (Error: HTTP
status 404: The requested URL does not exist on the server. )

Error - 2/1/2010 6:42:47 PM | Computer Name = Rizwan-PC | Source = MCUpdate | ID = 0
Description = 3:42:46 PM - Failed to retrieve SportsSchedule-2.enc (Error: HTTP
status 404: The requested URL does not exist on the server. )

Error - 2/3/2010 6:34:40 PM | Computer Name = Rizwan-PC | Source = MCUpdate | ID = 0
Description = 3:34:39 PM - Failed to retrieve SportsSchedule.enc (Error: HTTP status
404: The requested URL does not exist on the server. )

[ System Events ]
Error - 7/9/2010 5:03:34 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office PowerPoint 2007 (KB982158).

Error - 7/9/2010 5:04:29 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office InfoPath 2007 (KB979441).

Error - 7/9/2010 5:05:25 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office Excel 2007 (KB982308).

Error - 7/9/2010 5:06:21 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for the 2007 Microsoft Office System (KB982312).

Error - 7/9/2010 6:50:32 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for the 2007 Microsoft Office System (KB982331).

Error - 7/9/2010 6:51:27 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office Word 2007 (KB982135).

Error - 7/9/2010 6:52:22 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office PowerPoint 2007 (KB982158).

Error - 7/9/2010 6:53:18 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office InfoPath 2007 (KB979441).

Error - 7/9/2010 6:54:13 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office Excel 2007 (KB982308).

Error - 7/9/2010 6:55:09 AM | Computer Name = Rizwan-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for the 2007 Microsoft Office System (KB982312).


< End of report >
Hello, Jim786
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.





Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Did u even read my message? I already ran Malwarebytes… Anyway, since u guys took a while to respond to my message and I ran out of patience, I took some action myself and was able to remove the problems. Although I dont know if they still exist or not, that's why im replying here for additional help. Heres the MBAM log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4320 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 7/19/2010 12:23:49 AM mbam-log-2010-07-19 (00-23-49).txt Scan type: Quick scan Objects scanned: 131209 Time elapsed: 3 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) As for the log for ESET, I have it saved and everything but the log file didn't save for some reason but it said nothing malicious was found.

I took some action myself


What exactly ? :)

Please post back with a fresh OTL logfile.


Well I downloaded SuperAntiSpyware free edition and that was able to find and remove the virus that was hiding the real virus, then I used Malwarebytes and it was able to eliminate the rest.

Ill post the log here as soon as its done.
OTL logfile created on: 7/19/2010 9:16:04 PM - Run 2
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\Rizwan\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 5.00 Gb Available Physical Memory | 79.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.41 Gb Total Space | 867.69 Gb Free Space | 94.68% Space Free | Partition Type: NTFS
Drive D: | 620.40 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 74.37 Gb Total Space | 32.63 Gb Free Space | 43.88% Space Free | Partition Type: FAT32

Computer Name: RIZWAN-PC
Current User Name: Rizwan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Rizwan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe (IOI)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Rizwan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (PnkBstrB) – C:\Windows\SysNative\PnkBstrB.exe File not found
SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe (Symantec Corporation)
SRV - (TeamViewer5) – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Greg_Service) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (DgiVecp) – C:\Windows\SysNative\Drivers\DgiVecp.sys File not found
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SYMTDIv) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symtdiv.sys (Symantec Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (ccHP) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.sys (Symantec Corporation)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds64.sys (Symantec Corporation)
DRV:64bit: - (KeyScrambler) – C:\Windows\SysNative\drivers\keyscrambler.sys (QFX Software Corporation)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (SSPORT) – C:\Windows\SysNative\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100719.002\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20100719.002\ENG64.SYS (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100709.001\BHDrvx64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100716.001\IDSviA64.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e5v115k4861r237
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.5.4
FF - prefs.js..extensions.enabledItems: [removed]:2.6.0.0
FF - prefs.js..extensions.enabledItems: [removed]:2.0.7
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: {c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}:1.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 49
FF - prefs.js..extensions.enabledItems: {7CB0C7E9-81C0-42A2-9E27-7E56BD1B9332}:1.9.1
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{7CB0C7E9-81C0-42A2-9E27-7E56BD1B9332}: C:\Users\Rizwan\AppData\Local\{7CB0C7E9-81C0-42A2-9E27-7E56BD1B9332} [2010/06/01 23:32:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2010/07/14 13:48:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2010/07/13 20:46:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/12 23:53:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/12 22:53:36 | 000,000,000 | —D | M]

[2010/07/06 15:03:21 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Extensions
[2010/07/06 15:03:21 | 000,000,000 | —D | M] (No name found) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/07/19 18:12:53 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions
[2010/07/04 03:26:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/28 20:01:15 | 000,000,000 | —D | M] (No name found) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/12/29 16:56:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}
[2010/07/05 23:44:43 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/03 01:22:27 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/07/01 18:36:35 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\[removed]
[2010/01/18 20:03:56 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\[removed]
[2010/07/01 18:38:38 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Mozilla\Firefox\Profiles\vi4jfw81.default\extensions\[removed]
[2010/07/19 18:12:53 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/07/15 18:19:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/15 18:18:58 | 000,423,656 | —- | M] (Oracle) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.2.0.12\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Gateway Photo Frame] C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe (IOI)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9:64bit: - Extra 'Tools' menuitem : &KeyScrambler; Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\x64\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler; Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files (x86)\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [1998/12/13 01:43:32 | 000,000,040 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{05898bf2-b43b-11de-ab29-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{05898bf2-b43b-11de-ab29-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE – [1998/11/30 23:04:40 | 000,025,600 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: InfDfpmp - (C:\Windows\system32\iscsperf.dll) - C:\Windows\SysWow64\iscsperf.dll File not found
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/07/19 17:05:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\TeamViewer
[2010/07/17 16:28:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2010/07/17 00:49:12 | 000,679,936 | —- | C] (Generated by JEDI) – C:\Windows\SysWow64\D3DX81ab.dll
[2010/07/17 00:49:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cheat Engine
[2010/07/16 20:49:22 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Local\CrashDumps
[2010/07/16 20:48:41 | 000,000,000 | —D | C] – C:\MGtools
[2010/07/16 13:28:53 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Roaming\SUPERAntiSpyware.com
[2010/07/16 13:28:53 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/07/16 13:28:49 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/07/16 13:28:48 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/07/16 13:17:05 | 009,070,816 | —- | C] (SUPERAntiSpyware.com) – C:\Users\Rizwan\Desktop\SUPERAntiSpyware.exe
[2010/07/15 18:19:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/07/15 18:19:09 | 000,153,376 | —- | C] (Oracle) – C:\Windows\SysWow64\javaws.exe
[2010/07/15 18:19:09 | 000,145,184 | —- | C] (Oracle) – C:\Windows\SysWow64\javaw.exe
[2010/07/15 18:19:09 | 000,145,184 | —- | C] (Oracle) – C:\Windows\SysWow64\java.exe
[2010/07/15 18:18:15 | 016,066,336 | —- | C] (Oracle) – C:\Users\Rizwan\Desktop\jre-6u21-windows-i586.exe
[2010/07/14 17:17:01 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Rizwan\Desktop\OTL.exe
[2010/07/14 16:42:42 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/07/14 13:51:13 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010/07/14 01:34:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/07/14 00:30:47 | 000,451,120 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symtdiv.sys
[2010/07/14 00:30:47 | 000,221,232 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa64.sys
[2010/07/14 00:30:46 | 000,615,040 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.sys
[2010/07/14 00:30:46 | 000,505,392 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.sys
[2010/07/14 00:30:46 | 000,433,200 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds64.sys
[2010/07/14 00:30:46 | 000,150,064 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\ironx64.sys
[2010/07/14 00:30:46 | 000,032,304 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.sys
[2010/07/14 00:30:26 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64\0402000.00C
[2010/07/13 20:47:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Symantec Shared
[2010/07/13 20:46:41 | 000,173,104 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/07/13 20:46:41 | 000,126,312 | R— | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2010/07/13 20:46:41 | 000,107,368 | R— | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2010/07/13 20:46:41 | 000,034,152 | R— | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/07/13 20:46:41 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/07/13 20:46:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/07/13 20:46:30 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/07/13 20:46:15 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\N360x64
[2010/07/13 20:46:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Security Suite
[2010/07/13 20:46:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2010/07/12 12:10:15 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/07/12 12:10:04 | 000,423,656 | —- | C] (Oracle) – C:\Windows\SysWow64\deployJava1.dll
[2010/07/12 12:05:25 | 008,587,672 | —- | C] (Mozilla) – C:\Users\Rizwan\Desktop\Firefox Setup 3.6.4.exe
[2010/07/12 11:31:43 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\google-sitemap-generator
[2010/07/12 01:54:32 | 000,000,000 | R–D | C] – C:\Users\Rizwan\Desktop\WTF is this
[2010/07/12 01:52:45 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\IMM and SEO
[2010/07/06 15:03:20 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Roaming\Thunderbird
[2010/07/06 15:03:20 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Local\Thunderbird
[2010/07/01 16:59:05 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\Website stuff
[2010/07/01 13:51:31 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\Cool pictures
[2010/07/01 13:50:12 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\php_speedy_wp_0.5.2
[2010/06/29 22:45:16 | 000,000,000 | —D | C] – C:\Users\Rizwan\Documents\Symantec
[2010/06/25 13:41:44 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\top10_01
[2010/06/25 13:41:21 | 000,000,000 | —D | C] – C:\Users\Rizwan\Desktop\all-in-one-seo-pack
[2010/06/23 03:04:29 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2010/06/23 03:04:29 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/06/23 03:04:29 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2010/06/23 03:04:29 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/06/23 03:04:29 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/06/23 03:04:29 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/06/23 03:04:29 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/06/23 03:04:29 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2010/06/22 17:50:15 | 001,736,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2010/06/22 17:50:08 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2010/06/22 17:50:08 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2010/06/22 17:50:08 | 000,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2010/06/22 17:50:07 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2010/06/22 17:50:07 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2010/06/22 17:50:07 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/06/22 17:50:07 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/06/21 07:53:17 | 000,000,000 | —D | C] – C:\Users\Rizwan\AppData\Roaming\Facebook

========== Files - Modified Within 30 Days ==========

[2010/07/19 21:18:06 | 002,621,440 | -HS- | M] () – C:\Users\Rizwan\ntuser.dat
[2010/07/19 21:16:39 | 001,159,318 | —- | M] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\Cat.DB
[2010/07/19 21:10:10 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/19 21:10:09 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/19 16:38:32 | 000,001,859 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/19 16:38:10 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/19 16:38:10 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/19 16:38:10 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/19 16:37:32 | 000,003,006 | —- | M] () – C:\Windows\SysWow64\ZSNESW.CFG
[2010/07/19 12:19:19 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/19 12:19:19 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/19 01:25:36 | 000,067,069 | —- | M] () – C:\Users\Rizwan\Desktop\head_tracking.jpg
[2010/07/18 23:19:06 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/17 18:01:46 | 000,083,559 | —- | M] () – C:\Users\Rizwan\Desktop\mario.jpg
[2010/07/17 00:49:14 | 000,000,990 | —- | M] () – C:\Users\Rizwan\Desktop\Cheat Engine.lnk
[2010/07/16 22:29:31 | 000,205,178 | —- | M] () – C:\MGlogs.zip
[2010/07/16 17:58:17 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/16 17:58:11 | 509,456,383 | -HS- | M] () – C:\hiberfil.sys
[2010/07/16 17:57:29 | 002,256,998 | -H– | M] () – C:\Users\Rizwan\AppData\Local\IconCache.db
[2010/07/16 13:17:22 | 002,396,845 | —- | M] () – C:\Users\Rizwan\Desktop\MGtools.exe
[2010/07/16 13:17:06 | 009,070,816 | —- | M] (SUPERAntiSpyware.com) – C:\Users\Rizwan\Desktop\SUPERAntiSpyware.exe
[2010/07/15 18:30:01 | 000,002,479 | —- | M] () – C:\Users\Public\Desktop\Norton Security Suite.lnk
[2010/07/15 18:18:57 | 000,423,656 | —- | M] (Oracle) – C:\Windows\SysWow64\deployJava1.dll
[2010/07/15 18:18:57 | 000,153,376 | —- | M] (Oracle) – C:\Windows\SysWow64\javaws.exe
[2010/07/15 18:18:57 | 000,145,184 | —- | M] (Oracle) – C:\Windows\SysWow64\javaw.exe
[2010/07/15 18:18:57 | 000,145,184 | —- | M] (Oracle) – C:\Windows\SysWow64\java.exe
[2010/07/15 18:18:23 | 016,066,336 | —- | M] (Oracle) – C:\Users\Rizwan\Desktop\jre-6u21-windows-i586.exe
[2010/07/15 02:53:12 | 000,001,014 | —- | M] () – C:\Users\Rizwan\Desktop\CCleaner.lnk
[2010/07/14 17:20:27 | 000,359,929 | —- | M] () – C:\Users\Rizwan\Desktop\dds.scr
[2010/07/14 17:17:02 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Rizwan\Desktop\OTL.exe
[2010/07/14 16:37:43 | 012,482,490 | —- | M] () – C:\Users\Rizwan\Desktop\registry.reg
[2010/07/14 01:34:19 | 000,002,981 | —- | M] () – C:\Users\Rizwan\Desktop\HiJackThis.lnk
[2010/07/13 20:46:30 | 000,173,104 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2010/07/13 20:46:30 | 000,007,440 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/07/13 20:46:30 | 000,000,854 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/07/13 20:46:06 | 000,001,372 | —- | M] () – C:\Users\Rizwan\Desktop\Norton Installation Files.lnk
[2010/07/13 00:37:35 | 000,030,662 | —- | M] () – C:\Users\Rizwan\Desktop\pokemon.JPG
[2010/07/12 22:58:58 | 000,005,442 | —- | M] () – C:\.htaccess
[2010/07/12 12:54:49 | 000,001,970 | —- | M] () – C:\Users\Rizwan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/12 12:54:49 | 000,001,946 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/12 12:05:38 | 008,587,672 | —- | M] (Mozilla) – C:\Users\Rizwan\Desktop\Firefox Setup 3.6.4.exe
[2010/07/12 11:31:22 | 000,002,007 | —- | M] () – C:\Users\Public\Desktop\FileZilla Client.lnk
[2010/07/06 13:24:24 | 000,044,032 | —- | M] () – C:\Users\Rizwan\Desktop\Amazon Codes Generator.exe
[2010/06/29 22:41:03 | 000,000,000 | —- | M] () – C:\Users\Rizwan\AppData\Local\Jgohanedev.bin
[2010/06/25 19:01:13 | 000,000,120 | —- | M] () – C:\Users\Rizwan\AppData\Local\Mbezivewavadej.dat

========== Files Created - No Company Name ==========

[2010/07/19 16:37:32 | 000,003,006 | —- | C] () – C:\Windows\SysWow64\ZSNESW.CFG
[2010/07/19 01:25:35 | 000,067,069 | —- | C] () – C:\Users\Rizwan\Desktop\head_tracking.jpg
[2010/07/17 18:01:46 | 000,083,559 | —- | C] () – C:\Users\Rizwan\Desktop\mario.jpg
[2010/07/17 00:49:14 | 000,000,990 | —- | C] () – C:\Users\Rizwan\Desktop\Cheat Engine.lnk
[2010/07/17 00:49:12 | 001,970,176 | —- | C] () – C:\Windows\SysWow64\d3dx9.dll
[2010/07/16 20:48:48 | 000,205,178 | —- | C] () – C:\MGlogs.zip
[2010/07/16 13:28:49 | 000,001,859 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/16 13:17:22 | 002,396,845 | —- | C] () – C:\Users\Rizwan\Desktop\MGtools.exe
[2010/07/14 17:20:27 | 000,359,929 | —- | C] () – C:\Users\Rizwan\Desktop\dds.scr
[2010/07/14 16:37:43 | 012,482,490 | —- | C] () – C:\Users\Rizwan\Desktop\registry.reg
[2010/07/14 01:34:19 | 000,002,981 | —- | C] () – C:\Users\Rizwan\Desktop\HiJackThis.lnk
[2010/07/14 01:03:04 | 001,159,318 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\Cat.DB
[2010/07/14 00:30:47 | 000,007,829 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa64.cat
[2010/07/14 00:30:47 | 000,007,787 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnetv64.cat
[2010/07/14 00:30:47 | 000,007,368 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnet64.cat
[2010/07/14 00:30:47 | 000,003,373 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symefa.inf
[2010/07/14 00:30:47 | 000,001,473 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnetv.inf
[2010/07/14 00:30:47 | 000,001,445 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symnet.inf
[2010/07/14 00:30:46 | 000,007,414 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.cat
[2010/07/14 00:30:46 | 000,007,410 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.cat
[2010/07/14 00:30:46 | 000,007,406 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds64.cat
[2010/07/14 00:30:46 | 000,007,402 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\iron.cat
[2010/07/14 00:30:46 | 000,007,358 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.cat
[2010/07/14 00:30:46 | 000,002,793 | R— | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\symds.inf
[2010/07/14 00:30:46 | 000,001,838 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\cchpx64.inf
[2010/07/14 00:30:46 | 000,001,437 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtsp64.inf
[2010/07/14 00:30:46 | 000,001,421 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\srtspx64.inf
[2010/07/14 00:30:46 | 000,000,771 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\iron.inf
[2010/07/14 00:30:26 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\N360x64\0402000.00C\isolate.ini
[2010/07/13 20:46:41 | 000,007,440 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2010/07/13 20:46:41 | 000,000,854 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2010/07/13 20:46:27 | 000,002,479 | —- | C] () – C:\Users\Public\Desktop\Norton Security Suite.lnk
[2010/07/13 00:37:34 | 000,030,662 | —- | C] () – C:\Users\Rizwan\Desktop\pokemon.JPG
[2010/07/12 22:58:58 | 000,005,442 | —- | C] () – C:\.htaccess
[2010/07/10 02:36:51 | 000,001,970 | —- | C] () – C:\Users\Rizwan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/10 02:36:51 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/07/06 13:24:23 | 000,044,032 | —- | C] () – C:\Users\Rizwan\Desktop\Amazon Codes Generator.exe
[2010/06/29 22:43:26 | 000,001,372 | —- | C] () – C:\Users\Rizwan\Desktop\Norton Installation Files.lnk
[2010/02/19 22:18:00 | 000,000,011 | —- | C] () – C:\Windows\SysWow64\KB.DLL
[2009/12/06 18:24:07 | 000,000,247 | —- | C] () – C:\Windows\w32dasm8.ini
[2009/12/03 01:06:39 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/06/14 00:26:01 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Babylon
[2010/06/21 07:53:18 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Facebook
[2010/07/12 23:03:57 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\FileZilla
[2009/12/06 15:30:46 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\G-Lock Software
[2009/12/03 18:43:03 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Packard Bell
[2009/12/13 01:12:10 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\TeamViewer
[2010/03/10 22:47:49 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Template
[2010/07/06 15:03:21 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Thunderbird
[2010/05/31 18:14:06 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\TS3Client
[2010/05/31 18:14:06 | 000,000,000 | —D | M] – C:\Users\Rizwan\AppData\Roaming\Wippien
[2009/07/13 23:08:49 | 000,023,412 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 19:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 19:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 19:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 19:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 19:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 19:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 19:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 19:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009/06/04 04:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\OEM\Preload\Autorun\DRV\Intel Storage Generic Driver\IaStor.sys
[2009/06/04 04:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Windows\SysWow64\DriverStore\FileRepository\iaahci.inf_amd64_neutral_7fb62b08f6b7117a\iaStor.sys
[2009/06/04 04:54:36 | 000,408,600 | —- | M] (Intel Corporation) MD5=1D004CB1DA6323B1F55CAEF7F94B61D9 – C:\Windows\SysWow64\DriverStore\FileRepository\iastor.inf_amd64_neutral_c065a1006c648409\iaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/13 19:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 19:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 19:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 19:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 19:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 19:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 19:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 19:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 19:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 19:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 19:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 19:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/07/13 19:15:13 | 000,346,112 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\dxtmsft.dll
[2009/07/13 19:15:13 | 000,215,552 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\dxtrans.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Your logs getting clean again :thumbup:

So lets do the last few steps to clean up your system.

Step 1

We have to remove all tools that we have used to clean up your system.

Tool CleanUp

Restart OTL.
Doubleclick on the CleanUp Button on the Top.
Now most of our tools should been removed. If there are any tools or logs left over on your desktop please delete them and clean your recycler.


Step 2

Now it is a good time to clear your systemrestore- points because it is possible that some kind of malware backed up there.
If you restore your system back to an earlier point you could get reinfected.


Clear restore points
  • Right click on your desktop.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Restart your computer.

Turn ON System Restore after reboot. ( Important )


Step 3

Updates for Windows

Its essential to keep your PC up to date.
Lets have a look if the Windows Updates download automatically. This is the best way to get all securtiy patches and security fixes.

Click start –> settings –> Control Panel
Select Automatic Updates and set them to automatic.

Now choose a day and a time when you know that your computer will be connected to the internet


Step 4

To protect you for further infections we will install different tools.

  • SpywareBlaster
    A tutorial for Spywareblaster can be found here. If you wish, the commercial version provides automatic updating.

  • MalwareBytes Anti Malware
    This is one of the most important Anti Malware Tools i know. It is an on- demand scan tool that detects and removes most of the known malware. Update the tool and let it run one time a week.
    A tutorial can be found here.

  • Temp File Cleaner
    A powerfull tool which cleans temporary files from IE and Windows, emptied the recycle bin and more. It really helps you to speed up your computer.
    You can download TFC ( by OldTimer ) here

  • MVPs hosts file
    A tutorial for MVPs hosts file can be found here. For more information about Hosts file you can consult the Tutorial for Hosts files.

  • Keep your Windows up to date
    Often there are holes found in the Internet Explorer or Windows itself. These ned to be patched because attackers can use this holes to access to your computer.
    Therefor visit the Microsoft Update Site.

  • Keep your Software up to date
    The easiest way to check your software is to use the Secunia Online Software.

Step 5

Tipps for safer surfing

These are my tipps to keep away from infections while surfing.
Use a different browser than Internet Explorer.
i recommend Mozilla Firefox

For this browser there a serveral Add Ons to help you for a safer surfing.
  • NoScript
    This Add On blocks JavaScript, Java and Flash and other plugins to be executed only by trusted web sites of your choice.
  • AdblockPlus
    This Add On blocks mostly of the advertisements automatically. Only a rightclick on the banner and ad them to AdblockPlus and the banner will never download again.
  • WOT (Web of trust)
    This one warns you before you interact with a risky site.

Don't
  • click all you are able to click.
  • use peer to peer or filesharing.
  • use cracks, keygens, serials or other illegal software.
  • open untrusted emails or attachments.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI