This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC Infected

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I noticed earlier today that IE was behaving quite erratically - sometimes freezing, sometimes slow. Perhaps a coincidence but later in the day I received a spam/porn email from someone I do not know - I have never had this before.

I ran ATL Cleaner.

I ran MBAM and it detected infections. This is the log prior to reboot:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4352

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

26/07/2010 17:01:23
mbam-log-2010-07-26 (17-01-23).txt

Scan type: Quick scan
Objects scanned: 130707
Time elapsed: 3 minute(s), 21 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 3
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 12

Memory Processes Infected:
C:\Program Files (x86)\RelevantKnowledge\rlservice.exe (Adware.RelevantKnowledge) -> Unloaded process successfully.
C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (Adware.RelevantKnowledge) -> Unloaded process successfully.

Memory Modules Infected:
C:\Program Files (x86)\RelevantKnowledge\rlls.dll (Adware.RelevantKnowledge) -> Delete on reboot.
C:\Program Files (x86)\RelevantKnowledge\MSVCP71.DLL (Spyware.MarketScore) -> Delete on reboot.
C:\Program Files (x86)\RelevantKnowledge\MSVCR71.DLL (Spyware.MarketScore) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files (x86)\RelevantKnowledge (Spyware.MarketScore) -> Delete on reboot.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files (x86)\RelevantKnowledge\rlservice.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
C:\Program Files (x86)\RelevantKnowledge\rlls.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
C:\Program Files (x86)\RelevantKnowledge\MSVCP71.DLL (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Program Files (x86)\RelevantKnowledge\MSVCR71.DLL (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Program Files (x86)\RelevantKnowledge\rlls64.dll (Spyware.MarketScore) -> Delete on reboot.
C:\Program Files (x86)\RelevantKnowledge\rloci.bin (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\Program Files (x86)\RelevantKnowledge\rlvknlg64.exe (Spyware.MarketScore) -> Delete on reboot.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Support.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.


After rebooting I ran MBAM again. This is the log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4352

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

26/07/2010 17:08:23
mbam-log-2010-07-26 (17-08-23).txt

Scan type: Quick scan
Objects scanned: 130583
Time elapsed: 3 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Although apparantly clear, can you please review the following logs and let me know if I should take any further action>

OTL log:

OTL logfile created on: 26/07/2010 17:12:43 - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\Family\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.50 Gb Total Space | 599.67 Gb Free Space | 64.38% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FAMILY-PC
Current User Name: Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Users\Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (TomTomHOMEService) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (pcouffin) – C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AnyDVD) – C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV:64bit: - (silabser) – C:\Windows\SysNative\drivers\silabser.sys (Silicon Laboratories)
DRV:64bit: - (silabenm) – C:\Windows\SysNative\drivers\silabenm.sys (Silicon Laboratories, Inc.)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys ()
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcuxd) – C:\Windows\SysNative\drivers\vpcuxd.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (61883) – C:\Windows\SysNative\drivers\61883.sys (Microsoft Corporation)
DRV:64bit: - (Avc) – C:\Windows\SysNative\drivers\avc.sys (Microsoft Corporation)
DRV:64bit: - (MSDV) – C:\Windows\SysNative\drivers\msdv.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\Windows\SysNative\drivers\RTKVAC64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (SiFilter) – C:\Windows\SysNative\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV:64bit: - (Si3114r5) – C:\Windows\SysNative\drivers\Si3114r5.sys (Silicon Image, Inc)
DRV:64bit: - (SiRemFil) – C:\Windows\SysNative\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (AnyDVD) – C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9F 7F 0F 61 16 DC CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/25 15:07:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/25 15:07:32 | 000,000,000 | —D | M]

[2010/05/23 19:12:36 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Mozilla\Extensions
[2010/05/23 19:12:36 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/06/25 09:30:04 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Mozilla\Firefox\Profiles\rm0w36gb.default\extensions
[2010/05/26 09:42:54 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/26 09:42:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/26 09:42:37 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/01 17:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/01 17:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/01 17:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/01 17:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\pdf24\pdf24.exe (Geek Software GmbH)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &ieSpell; Options - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: Check &Spelling; - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: Lookup on Merriam Webster - C:\Program Files (x86)\ieSpell\Merriam Webster.HTM ()
O8:64bit: - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files (x86)\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/62.06/uploader2.cab (UploadListView Class)
O16 - DPF: {6F0892F7-0D44-41C3-BF07-7599873FAA04} https://go.girlguiding.org.uk/crystalreport…tiveXViewer.cab (Crystal ActiveX Report Viewer Control 11.5)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/14 18:52:03 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/07/26 16:55:12 | 000,000,000 | —D | C] – C:\Users\Family\AppData\Roaming\Malwarebytes
[2010/07/26 16:55:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/07/26 16:55:05 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/07/26 16:55:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/07/26 16:55:05 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/07/26 16:53:17 | 006,153,384 | —- | C] (Malwarebytes Corporation ) – C:\Users\Family\Desktop\mbam-setup.exe
[2010/07/26 16:46:19 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\Family\Desktop\ATF_Cleaner.exe
[2010/07/26 16:32:24 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Family\Desktop\OTL.exe
[2010/07/26 16:29:13 | 000,000,000 | —D | C] – C:\Users\Family\Desktop\Trend Micro
[2010/07/23 00:16:27 | 000,000,000 | —D | C] – C:\Users\Family\Documents\Leawo
[2010/07/23 00:16:22 | 000,000,000 | —D | C] – C:\Users\Family\AppData\Roaming\Leawo
[2010/07/23 00:15:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\K-Lite Codec Pack
[2010/07/23 00:14:45 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2010/07/23 00:14:45 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2010/07/23 00:14:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Leawo
[2010/07/22 23:29:34 | 000,000,000 | —D | C] – C:\Users\Public\Documents\1Click DVD Converter
[2010/07/22 23:17:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\VSO Burning SDK
[2010/07/22 21:53:39 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/07/22 21:51:31 | 000,000,000 | —D | C] – C:\ProgramData\1Click DVD Converter
[2010/07/22 21:39:26 | 000,082,816 | —- | C] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2010/07/22 21:39:26 | 000,082,816 | —- | C] (VSO Software) – C:\Users\Family\AppData\Roaming\pcouffin.sys
[2010/07/22 21:39:25 | 000,000,000 | —D | C] – C:\Users\Family\Documents\PcSetup
[2010/07/22 21:39:24 | 000,000,000 | —D | C] – C:\Users\Family\AppData\Roaming\Vso
[2010/07/22 21:39:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\LG Software Innovations
[2010/07/22 08:16:40 | 000,000,000 | —D | C] – C:\Users\Family\Documents\Midi Files
[2010/07/20 13:03:53 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/07/20 13:03:52 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/07/20 13:03:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/07/19 16:10:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\ieSpell
[2010/07/15 17:41:06 | 000,013,048 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/07/14 23:56:30 | 004,514,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vpc.exe
[2010/07/14 23:56:30 | 002,264,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\VPCWizard.exe
[2010/07/14 23:56:30 | 000,360,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\vpcvmm.sys
[2010/07/14 23:56:29 | 001,210,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\VMWindow.exe
[2010/07/14 23:54:28 | 000,000,000 | R–D | C] – C:\Users\Family\Virtual Machines
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\zh-TW
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\zh-CN
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Virtual PC
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\tr-TR
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\th-TH
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\sv-SE
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\ru-RU
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\ro-RO
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\pt-PT
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\pt-BR
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\pl-PL
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\nl-NL
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\nb-NO
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\ko-KR
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\ja-JP
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\it-IT
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\hu-HU
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\he-IL
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\fr-FR
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\fi-FI
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\es-ES
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\el-GR
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\de-DE
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\da-DK
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\cs-CZ
[2010/07/14 23:50:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\ar-SA
[2010/07/14 23:49:07 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pl-PL\vpchbus.sys.mui
[2010/07/14 23:49:07 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\de-DE\vpchbus.sys.mui
[2010/07/14 23:49:07 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\cs-CZ\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\vpcuxd.sys
[2010/07/14 23:49:06 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vpchbuspipe.dll
[2010/07/14 23:49:06 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\el-GR\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tr-TR\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sv-SE\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ru-RU\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ro-RO\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-PT\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-BR\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nl-NL\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nb-NO\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\it-IT\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hu-HU\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fr-FR\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fi-FI\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\es-ES\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\da-DK\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\th-TH\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ko-KR\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ja-JP\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\he-IL\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ar-SA\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-TW\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-CN\vpchbus.sys.mui
[2010/07/14 23:49:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ru-RU\vpcuxd.sys.mui
[2010/07/14 23:49:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\cs-CZ\vpcuxd.sys.mui
[2010/07/14 23:49:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ru-RU\vpcusb.sys.mui
[2010/07/14 23:49:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\cs-CZ\vpcusb.sys.mui
[2010/07/14 23:49:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nl-NL\vpcnfltr.sys.mui
[2010/07/14 23:49:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\el-GR\vpcnfltr.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-CN\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\th-TH\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sv-SE\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nb-NO\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ko-KR\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ja-JP\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\he-IL\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\de-DE\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\da-DK\vpcuxd.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-TW\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-CN\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tr-TR\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\th-TH\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sv-SE\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nb-NO\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ko-KR\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ja-JP\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\he-IL\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fi-FI\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\de-DE\vpcusb.sys.mui
[2010/07/14 23:49:05 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ar-SA\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\el-GR\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tr-TR\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\th-TH\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ru-RU\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ro-RO\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-PT\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-BR\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pl-PL\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nl-NL\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nb-NO\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\it-IT\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hu-HU\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fr-FR\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fi-FI\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\es-ES\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\de-DE\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\da-DK\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\cs-CZ\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ar-SA\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-TW\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-CN\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sv-SE\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ko-KR\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ja-JP\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\he-IL\vpcvmm.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pl-PL\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hu-HU\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fi-FI\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\el-GR\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pl-PL\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nl-NL\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hu-HU\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\el-GR\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-TW\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tr-TR\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ro-RO\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-PT\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-BR\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nl-NL\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\it-IT\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fr-FR\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\es-ES\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ar-SA\vpcuxd.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ro-RO\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-PT\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-BR\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\it-IT\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fr-FR\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\es-ES\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\da-DK\vpcusb.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-TW\vpcnfltr.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\zh-CN\vpcnfltr.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pl-PL\vpcnfltr.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ko-KR\vpcnfltr.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hu-HU\vpcnfltr.sys.mui
[2010/07/14 23:49:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ar-SA\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tr-TR\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\th-TH\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sv-SE\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ru-RU\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ro-RO\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-PT\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pt-BR\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\nb-NO\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\ja-JP\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\it-IT\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\he-IL\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fr-FR\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fi-FI\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\es-ES\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\de-DE\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\da-DK\vpcnfltr.sys.mui
[2010/07/14 23:48:59 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\cs-CZ\vpcnfltr.sys.mui
[2010/07/14 23:48:57 | 000,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\vpchbus.sys
[2010/07/14 23:48:57 | 000,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\vpcusb.sys
[2010/07/14 23:48:56 | 001,369,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\VPCSettings.exe
[2010/07/14 23:48:56 | 000,793,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vmsal.exe
[2010/07/14 23:48:56 | 000,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\VMCPropertyHandler.dll
[2010/07/14 23:48:56 | 000,066,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\vpcnfltr.sys
[2010/07/14 23:48:55 | 000,936,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vmsal.exe
[2010/07/14 23:35:40 | 000,000,000 | —D | C] – C:\Program Files\Windows XP Mode
[2010/07/13 20:30:33 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010/06/29 18:05:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\pdf24

========== Files - Modified Within 30 Days ==========

[2010/07/26 17:14:00 | 003,407,872 | -HS- | M] () – C:\Users\Family\NTUSER.DAT
[2010/07/26 17:10:45 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/26 17:10:45 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/26 17:03:37 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/26 17:03:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/26 17:03:20 | 1610,260,480 | -HS- | M] () – C:\hiberfil.sys
[2010/07/26 17:02:04 | 006,291,456 | -H– | M] () – C:\Users\Family\AppData\Local\IconCache.db
[2010/07/26 16:55:08 | 000,001,009 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/26 16:53:17 | 006,153,384 | —- | M] (Malwarebytes Corporation ) – C:\Users\Family\Desktop\mbam-setup.exe
[2010/07/26 16:46:19 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Family\Desktop\ATF_Cleaner.exe
[2010/07/26 16:32:27 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Family\Desktop\OTL.exe
[2010/07/26 09:42:59 | 062,495,418 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/24 20:27:22 | 000,720,082 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/24 20:27:22 | 000,625,478 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/24 20:27:22 | 000,110,452 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/23 23:35:20 | 000,001,401 | —- | M] () – C:\Users\Family\Application Data\Microsoft\Internet Explorer\Quick Launch\1Click DVD Converter.lnk
[2010/07/23 23:35:20 | 000,001,377 | —- | M] () – C:\Users\Family\Desktop\1Click DVD Converter.lnk
[2010/07/23 00:14:46 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Leawo Free MP4 Converter.lnk
[2010/07/22 23:29:35 | 000,000,045 | -H– | M] () – C:\Users\Public\Documents\system.ini
[2010/07/22 21:39:26 | 000,099,384 | —- | M] () – C:\Users\Family\AppData\Roaming\inst.exe
[2010/07/22 21:39:26 | 000,082,816 | —- | M] (VSO Software) – C:\Windows\SysNative\drivers\pcouffin.sys
[2010/07/22 21:39:26 | 000,082,816 | —- | M] (VSO Software) – C:\Users\Family\AppData\Roaming\pcouffin.sys
[2010/07/22 21:39:26 | 000,007,859 | —- | M] () – C:\Users\Family\AppData\Roaming\pcouffin.cat
[2010/07/22 21:39:26 | 000,001,167 | —- | M] () – C:\Users\Family\AppData\Roaming\pcouffin.inf
[2010/07/20 13:04:05 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/07/15 17:41:07 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 17:41:06 | 000,013,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 17:40:27 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/14 13:45:29 | 000,000,732 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/07/04 13:48:57 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/29 18:05:26 | 000,001,868 | —- | M] () – C:\Users\Public\Desktop\PDF24 Editor.lnk
[2010/06/29 12:39:47 | 000,009,309 | —- | M] () – C:\Users\Family\AppData\Roaming\Comma Separated Values (Windows).EML

========== Files Created - No Company Name ==========

[2010/07/26 16:55:08 | 000,001,009 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/23 00:15:06 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/07/23 00:14:46 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Leawo Free MP4 Converter.lnk
[2010/07/22 21:41:00 | 000,000,034 | —- | C] () – C:\Users\Family\AppData\Roaming\pcouffin.log
[2010/07/22 21:39:26 | 000,099,384 | —- | C] () – C:\Users\Family\AppData\Roaming\inst.exe
[2010/07/22 21:39:26 | 000,007,859 | —- | C] () – C:\Users\Family\AppData\Roaming\pcouffin.cat
[2010/07/22 21:39:26 | 000,001,167 | —- | C] () – C:\Users\Family\AppData\Roaming\pcouffin.inf
[2010/07/22 21:39:21 | 000,001,401 | —- | C] () – C:\Users\Family\Application Data\Microsoft\Internet Explorer\Quick Launch\1Click DVD Converter.lnk
[2010/07/22 21:39:21 | 000,001,377 | —- | C] () – C:\Users\Family\Desktop\1Click DVD Converter.lnk
[2010/07/20 13:04:05 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/06/29 18:05:26 | 000,001,868 | —- | C] () – C:\Users\Public\Desktop\PDF24 Editor.lnk
[2010/06/29 12:39:47 | 000,009,309 | —- | C] () – C:\Users\Family\AppData\Roaming\Comma Separated Values (Windows).EML
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/14 07:45:20 | 000,154,144 | —- | C] () – C:\Windows\SysWow64\RTLCPAPI.dll

========== LOP Check ==========

[2010/07/23 00:16:22 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Leawo
[2010/05/21 15:58:03 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Scan2PDF
[2010/04/14 22:57:23 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\SkyGolf
[2010/05/23 19:12:33 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\TomTom
[2010/05/06 09:11:14 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Uniblue
[2010/07/23 23:35:22 | 000,000,000 | —D | M] – C:\Users\Family\AppData\Roaming\Vso
[2010/06/26 10:02:53 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: ADP3132.SYS >
[2007/07/09 09:00:26 | 000,313,856 | —- | M] (Adaptec, Inc.) MD5=103D0B6150D2ECD127122E359C2B4A0E – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\ADA\ADP3132.sys
[2007/07/09 09:00:26 | 000,313,856 | —- | M] (Adaptec, Inc.) MD5=103D0B6150D2ECD127122E359C2B4A0E – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\ADA\ADP3132.sys

< MD5 for: AGP440.SYS >
[2009/07/14 02:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: AHCIX86.SYS >
[2007/03/07 11:47:30 | 000,119,808 | —- | M] (ATI Technologies Inc.) MD5=F1B9E3A223CA684D98BB91FD82157601 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\AT\ahcix86.sys
[2007/03/07 11:47:30 | 000,119,808 | —- | M] (ATI Technologies Inc.) MD5=F1B9E3A223CA684D98BB91FD82157601 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\AT\ahcix86.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS.0\system32\drivers\atapi.sys
[2008/04/14 01:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\Windows.old\Windows\system32\drivers\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/14 02:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/14 02:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/14 02:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2008/04/14 06:41:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS.0\system32\dllcache\eventlog.dll
[2008/04/14 06:41:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS.0\system32\eventlog.dll
[2008/04/14 06:41:54 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\Windows.old\Windows\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/09/29 22:03:12 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\I3\IaStor.sys
[2007/09/29 22:03:12 | 000,308,248 | —- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\I3\IaStor.sys

< MD5 for: IASTORV.SYS >
[2009/07/14 02:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 02:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/04/17 05:50:11 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=06CF9EEDB7E827205C6948C9DAF56974 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Hotfixes and Patches\netlogon.dll
[2008/04/17 05:50:11 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=06CF9EEDB7E827205C6948C9DAF56974 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Hotfixes and Patches\netlogon.dll
[2008/04/17 05:50:11 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=06CF9EEDB7E827205C6948C9DAF56974 – C:\WINDOWS.0\system32\dllcache\netlogon.dll
[2008/04/17 05:50:11 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=06CF9EEDB7E827205C6948C9DAF56974 – C:\WINDOWS.0\system32\netlogon.dll
[2008/04/17 05:50:11 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=06CF9EEDB7E827205C6948C9DAF56974 – C:\Windows.old\Windows\system32\netlogon.dll
[2009/07/14 02:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/14 02:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVATA.SYS >
[2005/05/17 10:45:08 | 000,092,800 | R— | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\20100413 Backups\New Folder\Drivers and Software\Drive Grabber\DriverGrabber\Drivers\hdc\NVIDIA nForce4 Parallel ATA Controller\nvata.sys
[2005/05/17 10:45:08 | 000,092,800 | R— | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\20100413 Backups\New Folder\Drivers and Software\Drive Grabber\DriverGrabber\Drivers\hdc\NVIDIA nForce4 Serial ATA Controller\nvata.sys
[2005/05/17 10:45:08 | 000,092,800 | R— | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\Users\Family\My Documents\Drivers and Software\Drive Grabber\DriverGrabber\Drivers\hdc\NVIDIA nForce4 Parallel ATA Controller\nvata.sys
[2005/05/17 10:45:08 | 000,092,800 | R— | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\Users\Family\My Documents\Drivers and Software\Drive Grabber\DriverGrabber\Drivers\hdc\NVIDIA nForce4 Serial ATA Controller\nvata.sys
[2008/11/30 14:44:02 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS.0\NLDRV\002\nvata.sys
[2008/11/30 14:44:02 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS.0\NLDRV\003\nvata.sys
[2008/11/30 14:44:02 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS.0\system32\drivers\nvata.sys
[2008/11/30 14:44:02 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\Windows.old\Windows\NLDRV\002\nvata.sys
[2008/11/30 14:44:02 | 000,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\Windows.old\Windows\NLDRV\003\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/02/26 16:21:18 | 000,089,856 | —- | M] (NVIDIA Corporation) MD5=83F0275A21D9772B51CEF57E35AFAE61 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\123\NVATABUS.sys
[2006/02/26 16:21:18 | 000,089,856 | —- | M] (NVIDIA Corporation) MD5=83F0275A21D9772B51CEF57E35AFAE61 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\123\NVATABUS.sys
[2006/04/24 16:52:28 | 000,100,736 | —- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\TM\NVATABUS.sys
[2006/04/24 16:52:28 | 000,100,736 | —- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\TM\NVATABUS.sys

< MD5 for: NVGTS.SYS >
[2007/07/27 21:16:02 | 000,105,984 | —- | M] (NVIDIA Corporation) MD5=4BC4BAAED05161E0D331627E90A10745 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\6\nvgts.sys
[2007/07/27 21:16:02 | 000,105,984 | —- | M] (NVIDIA Corporation) MD5=4BC4BAAED05161E0D331627E90A10745 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\6\nvgts.sys

< MD5 for: NVRD32.SYS >
[2007/07/27 21:15:56 | 000,116,736 | —- | M] (NVIDIA Corporation) MD5=77AC69AC4F07BD9D29528B8FCC71FB49 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\6\nvrd32.sys
[2007/07/27 21:15:56 | 000,116,736 | —- | M] (NVIDIA Corporation) MD5=77AC69AC4F07BD9D29528B8FCC71FB49 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\N\6\nvrd32.sys

< MD5 for: NVSTOR.SYS >
[2009/07/14 02:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 02:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 02:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/14 02:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/14 02:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS.0\system32\dllcache\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS.0\system32\scecli.dll
[2008/04/14 06:42:06 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\Windows.old\Windows\system32\scecli.dll

< MD5 for: SYMMPI.SYS >
[2006/01/27 09:26:58 | 000,093,056 | —- | M] (LSI Logic) MD5=164FCA8F1489278A6D5A41F8CF99D295 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\L4\SYMMPI.sys
[2006/01/27 09:26:58 | 000,093,056 | —- | M] (LSI Logic) MD5=164FCA8F1489278A6D5A41F8CF99D295 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\L4\SYMMPI.sys
[2007/02/10 00:05:00 | 000,104,496 | —- | M] (LSI Logic) MD5=4CCED1D8EC90FC7008EA8C742F1278F2 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\D2\SYMMPI.SYS
[2007/02/10 00:05:00 | 000,104,496 | —- | M] (LSI Logic) MD5=4CCED1D8EC90FC7008EA8C742F1278F2 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\D2\SYMMPI.SYS
[2007/02/10 00:06:00 | 000,100,096 | —- | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\D1\symmpi.sys
[2007/02/10 00:06:00 | 000,100,096 | —- | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\D1\symmpi.sys

< MD5 for: VIAMRAID.SYS >
[2008/01/22 19:02:24 | 000,117,248 | —- | M] (VIA Technologies inc,.ltd) MD5=3A82A61E312ADDB3BE8F1FE3481842B1 – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\V\viamraid.sys
[2008/01/22 19:02:24 | 000,117,248 | —- | M] (VIA Technologies inc,.ltd) MD5=3A82A61E312ADDB3BE8F1FE3481842B1 – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\V\viamraid.sys

< MD5 for: VIPRT.SYS >
[2008/04/03 20:42:34 | 000,053,248 | —- | M] (VIA Technologies, Inc.) MD5=682D704CA5B1FEDE6C4BEF0E2188745C – C:\20100413 Backups\New Folder\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\V4\VIPRT.SYS
[2008/04/03 20:42:34 | 000,053,248 | —- | M] (VIA Technologies, Inc.) MD5=682D704CA5B1FEDE6C4BEF0E2188745C – C:\Users\Family\My Documents\Drivers and Software\MS Service Pack 3 Mass Storage\DP_MassStorage_wnt5_x86-32_805\D\M\V4\VIPRT.SYS

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< >
< End of report >


I was not able to find Extras.txt

This is the Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:24:40, on 26/07/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\SOUNDMAN.EXE
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\pdf24\pdf24.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Users\Family\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files (x86)\pdf24\pdf24.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: &ieSpell; Options - res://C:\Program Files (x86)\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling; - res://C:\Program Files (x86)\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files (x86)\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files (x86)\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/62.06/uploader2.cab
O16 - DPF: {6F0892F7-0D44-41C3-BF07-7599873FAA04} (Crystal ActiveX Report Viewer Control 11.5) - https://go.girlguiding.org.uk/crystalreport…tiveXViewer.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files (x86)\RelevantKnowledge\rlservice.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9939 bytes


DDS would not run - wrong Operation System?

Many thanks for your help
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT




**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan.
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Thank for your help. Requested logs as follows: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default User: Default User User: Family ->Flash cache emptied: 3175 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Family ->Temp folder emptied: 644932 bytes ->Temporary Internet Files folder emptied: 9275876 bytes ->Java cache emptied: 1855343 bytes ->FireFox cache emptied: 35590712 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 67572 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 1484544 bytes Total Files Cleaned = 47.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 07312010_074826 Files\Folders moved on Reboot… C:\Users\Family\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, July 31, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, July 31, 2010 12:14:23 Records in database: 4184415 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 155553 Threats found: 1 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 04:42:36 File name / Threat / Threats count C:\20100413 Backups\New Folder\Drivers and Software\Driver Cleaner\DCProSetup_13.zip Infected: Trojan.Win32.Agent.djrk 1 C:\Users\Family\Documents\Drivers and Software\Driver Cleaner\DCProSetup_13.zip Infected: Trojan.Win32.Agent.djrk 1 Selected area has been scanned. Regards, Mike
Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\20100413 Backups\New Folder\Drivers and Software\Driver Cleaner\DCProSetup_13.zip 
    C:\Users\Family\Documents\Drivers and Software\Driver Cleaner\DCProSetup_13.zip 
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Please re-run your MalwareBytes program, update the definitions, see if it finds anything more,

allow it to remove anything it finds.

NEXT

Please advise how the computer is running and if there are any outstanding issues.
Logs as requested: All processes killed ========== FILES ========== C:\20100413 Backups\New Folder\Drivers and Software\Driver Cleaner\DCProSetup_13.zip moved successfully. C:\Users\Family\Documents\Drivers and Software\Driver Cleaner\DCProSetup_13.zip moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default User: Default User User: Family ->Flash cache emptied: 456 bytes User: Public Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Family ->Temp folder emptied: 108333752 bytes ->Temporary Internet Files folder emptied: 3353430 bytes ->Java cache emptied: 128094 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 608 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 107.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08012010_031211 Files\Folders moved on Reboot… C:\Users\Family\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… And ….. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4375 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 01/08/2010 03:21:06 mbam-log-2010-08-01 (03-21-06).txt Scan type: Quick scan Objects scanned: 131638 Time elapsed: 3 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) The PC seems to be running fine with no issues.
Just some housekeeping to do now then,

Please do the following:

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.



    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thank you very much for your help. All now complete. However, it occured to me that I have an external drive I use for backups but I did not have it connected when I was carrying out the scans. What do you suggest I do? Regards,
Thanks. Log as follows: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, August 2, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, August 02, 2010 11:45:41 Records in database: 4162047 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - Folder: F:\ Scan statistics: Objects scanned: 6 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 00:06:46 No threats found. Scanned area is clean. Selected area has been scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI