This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

32788R22FWJFW folder

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not too long ago I got a pop up that wouldn't let me leave a website when I pressed X or back on firefox. Usually when I get these which is rare I just alt tab delete and be done with it. This time I got lazy and hit cancel. The website closed and I went on with what I was doing. Shortly after I started getting virus warnings like crazy. I unplugged my modem from the computer and rebooted into safemode and ran my antivirus/malware programs. These programs are AVG, SuperAntiSpyware and malwarebytes. What ever my computer was infected with it was completely locked me out of all programs and infecting every program I had running. I did some scans and reboots and thought I got it all. Today I found a folder called 32788R22FWJFW and did some google searches on some names of people and programs I found within the folder/text files. All my scanners come up clean so I'm here to find out if they are correct. I deleted the 32788R22FWJFW folder before I decided to seek outside help.

I would love know how to disable these popups that do not let you leave a website. I can tell it's something implemented by the browsers that the websites are using to trick you. Seems like you hit cancel and it's like you just gave it permission to do something. I'd like to be able to click back or just click the x and be done without closing all tabs. I've been using firefox until very recent and normally when I alt-ctrl-delete when I would open firefox up again the page would just load it's old tabs and I'd be stuck with the same popup. Since I've started using Chrome I haven't had the misfortune of visiting any of these websites to know what happens. Any information on this would be very much appreciated. While it's not very often I come across a website that's doing this is is very annoying when I do.

.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:38:06 AM, on 8/5/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\PowerMenu\PowerMenu.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5643
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files (x86)\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [jgyo0w] C:\Users\LunaTiK\AppData\Local\Temp\19aqp.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: PowerMenu.lnk = C:\Program Files (x86)\PowerMenu\PowerMenu.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\LunaTiK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15111/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SCM_Service - Unknown owner - C:\Windows\SysWOW64\WinService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: STSService - Unknown owner - C:\Program Files (x86)\SoundTaxi Media Suite\STSService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9208 bytes
Hello BillyJB and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.


Before we begin I would like to take a closer look at your system. Please work your way throught the following steps. If you encounter any difficulties come back and let me know.


  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then Right click on the OTL.exe icon and select "Run as Administrator" to run the program.
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to your desktop.
    • Right click on GMER.exe and select "Run as Administrator" to run the program. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


In your next reply please provide the OTL logs and the GMER log.

Note: You may need to make more than one post to fit all of the required information in.
I ran extracted and ran GMER as admin I got an error C:\windows\system32\config\system the process can no access the file because it's being used by another proccess.
I must go until tonight but I will reboot and see if I can run this later.

After I just clicked off the error a very short scan happened and it came up and said no system modification has been detected. No log was produced when I saved.
I'm also going to post some pictures of my AVG antivirus vault later unless you decide it is irrelevant before I do.

OTL logfile created on: 8/5/2010 6:32:38 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\USERNAME\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 74.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 69.25 Gb Total Space | 11.09 Gb Free Space | 16.01% Space Free | Partition Type: NTFS
Drive D: | 4.12 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 37.23 Gb Total Space | 2.45 Gb Free Space | 6.57% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ðê
Current User Name: §ð§
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/08/05 18:30:21 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\USERNAME\Downloads\OTL.exe
PRC - [2010/08/04 14:04:19 | 000,218,464 | —- | M] () – C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2010/07/22 18:02:16 | 000,945,720 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2010/07/20 16:14:29 | 002,065,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010/07/20 16:14:24 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/20 16:14:00 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010/07/20 16:13:58 | 000,723,296 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/26 10:19:57 | 000,075,064 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/06/02 20:50:58 | 001,144,104 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/05/07 11:48:46 | 008,596,234 | —- | M] () – C:\android\android-sdk-windows\tools\emulator.exe
PRC - [2010/04/03 16:59:00 | 000,240,232 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010/02/18 13:43:20 | 000,490,728 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/01/15 08:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/12/17 19:14:06 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWOW64\java.exe
PRC - [2009/12/10 12:00:32 | 000,522,760 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
PRC - [2009/08/29 02:56:10 | 000,164,864 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Media Player\wmplayer.exe
PRC - [2009/07/13 21:14:15 | 000,301,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\cmd.exe
PRC - [2009/02/23 15:43:54 | 000,307,200 | —- | M] (Creative Technology Ltd) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2007/03/29 20:42:44 | 000,180,224 | —- | M] () – C:\Windows\SysWOW64\WinService.exe
PRC - [2002/12/19 19:17:56 | 000,057,344 | —- | M] (Thong Nguyen) – C:\Program Files (x86)\PowerMenu\PowerMenu.exe
PRC - [2001/09/06 21:37:09 | 000,049,152 | —- | M] () – C:\Program Files (x86)\Alarm Clock\Alarm Clock.exe


========== Modules (SafeList) ==========

MOD - [2010/08/05 18:30:21 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\USERNAME\Downloads\OTL.exe
MOD - [2009/07/13 21:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/13 21:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
MOD - [2002/12/19 19:16:50 | 000,073,728 | —- | M] (Thong Nguyen) – C:\Program Files (x86)\PowerMenu\PowerMenuHook.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Running] – C:\Windows\SysNative\PnkBstrB.exe – (PnkBstrB)
SRV:64bit: - File not found [Auto | Running] – C:\Windows\SysNative\PnkBstrA.exe – (PnkBstrA)
SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE – (!SASCORE)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/08/04 14:04:19 | 000,218,464 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrB.exe – (PnkBstrB)
SRV - [2010/07/20 16:14:24 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/07/20 16:14:00 | 000,921,952 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/06/26 10:19:57 | 000,075,064 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2010/04/03 16:59:00 | 000,240,232 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2010/01/15 08:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2009/12/24 21:20:00 | 000,079,360 | —- | M] (Creative Labs) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe – (Creative Audio Engine Licensing Service)
SRV - [2009/07/16 19:04:16 | 000,316,664 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2009/02/23 15:43:54 | 000,307,200 | —- | M] (Creative Technology Ltd) [Auto | Running] – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe – (CTAudSvcService)
SRV - [2007/03/29 20:42:44 | 000,180,224 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\WinService.exe – (SCM_Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/07/20 16:14:29 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2010/07/20 16:13:59 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010/06/05 10:52:13 | 000,035,536 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2010/02/25 20:57:10 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2010/02/25 20:44:32 | 000,033,344 | —- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hamachi.sys – (hamachi)
DRV:64bit: - [2010/02/18 11:42:30 | 000,056,832 | —- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\vrtaucbl.sys – (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)
DRV:64bit: - [2010/02/17 14:23:05 | 000,014,920 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2010/02/17 14:23:05 | 000,012,360 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2009/12/21 18:34:24 | 000,046,112 | —- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\tbhsd.sys – (tbhsd)
DRV:64bit: - [2009/11/23 19:38:00 | 000,016,008 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LGVirHid.sys – (LGVirHid)
DRV:64bit: - [2009/11/23 19:37:50 | 000,022,408 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LGBusEnum.sys – (LGBusEnum)
DRV:64bit: - [2009/11/19 21:04:32 | 000,033,336 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\SndTAudio.sys – (SndTAudio)
DRV:64bit: - [2009/11/11 20:44:26 | 000,034,160 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\point64k.sys – (Point64)
DRV:64bit: - [2009/07/29 13:21:58 | 000,717,312 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netr7364.sys – (netr7364)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvm62x64.sys – (NVENETFD)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/06 06:34:52 | 000,639,512 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\t3.sys – (t3)
DRV:64bit: - [2009/03/27 03:23:54 | 000,019,432 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\cpuz132_x64.sys – (cpuz132)
DRV:64bit: - [2007/02/12 02:09:52 | 000,243,200 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wg111v2.sys – (RTL8187)
DRV:64bit: - [2007/01/18 14:24:24 | 000,025,312 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\SCMNdisP.sys – (SCMNdisP)
DRV - [2008/07/26 23:30:36 | 000,014,544 | —- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] – C:\realtemp\WinRing0x64.sys – (WinRing0_1_2_0)
DRV - [2007/02/07 14:27:46 | 000,014,104 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | Boot | Running] – C:\Windows\SysWOW64\speedfan.sys – (speedfan)
DRV - [2005/05/25 09:39:14 | 000,007,168 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\RMClock\RTCore64.sys – (RTCore64)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4C 87 8C 2F E0 27 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5643

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.0.1
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {A3419A78-4C62-4C26-BF60-D0212B186AE3}:1.9.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{A3419A78-4C62-4C26-BF60-D0212B186AE3}: C:\Users\USERNAME\AppData\Local\{A3419A78-4C62-4C26-BF60-D0212B186AE3} [2010/07/27 07:04:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2010/07/20 21:47:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/28 02:23:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/24 06:12:47 | 000,000,000 | —D | M]

[2010/05/19 04:13:03 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\Mozilla\Extensions
[2010/05/19 04:13:03 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/08/05 00:37:19 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\roib5qi7.default\extensions
[2010/07/28 02:23:53 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\roib5qi7.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/02/14 09:50:04 | 000,000,000 | —D | M] (No name found) – C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\roib5qi7.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/07/28 02:40:59 | 000,001,196 | —- | M] () – C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\roib5qi7.default\searchplugins\winamp-search.xml
[2010/08/05 00:15:59 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/03/31 12:13:37 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/07/12 12:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
[2010/07/26 08:38:42 | 000,002,076 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml

O1 HOSTS File: ([2010/07/27 07:02:48 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files (x86)\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerMenu.lnk = C:\Program Files (x86)\PowerMenu\PowerMenu.exe (Thong Nguyen)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: jgyo0w = C:\Users\USERNAME\AppData\Local\Temp\19aqp.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15111/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (RtlGina2.dll) - File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell - "" = AutoRun
O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell\directx\command - "" = F:\DirectX9\dxsetup.exe – File not found
O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell\setup\command - "" = F:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: drivsetx - (C:\Windows\system32\contDism.dll) - C:\Windows\SysWow64\contDism.dll File not found
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/05 00:26:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\COMODO
[2010/08/05 00:03:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/04 19:23:28 | 000,000,000 | —D | C] – C:\Users\USERNAME\AppData\Local\Winamp Toolbar
[2010/08/02 03:15:03 | 000,000,000 | —D | C] – C:\Users\USERNAME\AppData\Roaming\DivX
[2010/08/02 03:14:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PX Storage Engine
[2010/08/02 03:14:40 | 000,000,000 | —D | C] – C:\Program Files\DivX
[2010/08/02 03:14:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DivX Shared
[2010/08/02 03:13:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\DivX
[2010/08/02 03:13:23 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2010/07/28 02:23:49 | 000,000,000 | —D | C] – C:\ProgramData\Winamp Toolbar
[2010/07/28 02:23:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Winamp Toolbar
[2010/07/27 21:53:26 | 000,000,000 | —D | C] – C:\Users\USERNAME\.android
[2010/07/27 21:53:07 | 000,000,000 | —D | C] – C:\android
[2010/07/27 09:24:14 | 000,000,000 | —D | C] – C:\Users\USERNAME\AppData\Roaming\SUPERAntiSpyware.com
[2010/07/27 09:24:14 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/07/27 09:24:10 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/07/27 09:24:08 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/07/27 08:42:26 | 000,000,000 | —D | C] – C:\Users\USERNAME\AppData\Roaming\Malwarebytes
[2010/07/27 08:42:20 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/07/27 08:42:20 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/07/27 08:42:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/07/27 08:42:20 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/07/27 07:04:28 | 000,000,000 | —D | C] – C:\Users\USERNAME\AppData\Local\{A3419A78-4C62-4C26-BF60-D0212B186AE3}
[2010/07/27 07:03:03 | 000,000,000 | —D | C] – C:\Users\USERNAME\AppData\Local\pvlnflfey
[2010/07/27 07:02:55 | 000,000,000 | —D | C] – C:\ProgramData\Update
[2010/07/20 16:14:28 | 000,013,048 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/07/20 16:14:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\avg
[2010/07/14 07:31:52 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2010/07/08 21:43:03 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2010/07/08 21:43:03 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2010/07/08 21:42:41 | 002,615,400 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2010/07/08 21:42:41 | 002,601,816 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib.dll
[2010/07/08 21:42:41 | 001,987,176 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2010/07/08 21:42:41 | 001,216,104 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2010/07/08 21:42:41 | 001,146,984 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2010/07/08 21:42:41 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2010/07/08 21:42:41 | 000,476,264 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2010/07/08 21:42:41 | 000,372,936 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2010/07/08 21:42:41 | 000,332,392 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2010/07/08 21:42:41 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2010/07/08 21:42:41 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2010/07/08 21:42:41 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2010/07/08 21:42:41 | 000,201,928 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2010/07/08 21:42:41 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2010/07/08 21:42:41 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2010/07/08 21:42:41 | 000,149,608 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2010/07/08 21:42:41 | 000,099,016 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2010/07/08 21:42:41 | 000,076,488 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2010/07/08 21:42:41 | 000,071,272 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInst64.dll
[2010/07/08 21:42:40 | 002,197,264 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ.dll
[2010/07/08 21:42:40 | 001,736,536 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek.dll
[2010/07/08 21:42:40 | 001,325,328 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2010/07/08 21:42:40 | 001,178,384 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2010/07/08 21:42:40 | 001,110,800 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2010/07/08 21:42:40 | 000,504,592 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2010/07/08 21:42:40 | 000,489,744 | —- | C] (DTS) – C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2010/07/08 21:42:40 | 000,474,896 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2010/07/08 21:42:40 | 000,335,192 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO30.dll
[2010/07/08 21:42:40 | 000,334,680 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2010/07/08 21:42:40 | 000,330,656 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2010/07/08 21:42:40 | 000,318,808 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010/07/08 21:42:40 | 000,315,152 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2010/07/08 21:42:40 | 000,268,560 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2010/07/08 21:42:40 | 000,265,488 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2010/07/08 21:42:40 | 000,168,288 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2010/07/08 21:42:40 | 000,124,176 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2010/07/08 21:42:40 | 000,123,664 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2010/07/08 21:42:40 | 000,123,152 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPONS64.dll
[2010/07/08 21:42:40 | 000,108,960 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2010/07/08 21:42:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2010/07/08 21:42:36 | 001,251,872 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2010/07/08 21:42:36 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/05 18:34:29 | 002,359,296 | -HS- | M] () – C:\Users\USERNAME\NTUSER.DAT
[2010/08/05 18:24:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/05 15:24:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/05 12:49:40 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/05 12:49:40 | 000,013,440 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/05 11:36:21 | 000,000,630 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010/08/05 11:26:24 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/05 00:37:26 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/05 00:37:26 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/05 00:37:26 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/05 00:31:27 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/05 00:31:12 | 3220,074,496 | -HS- | M] () – C:\hiberfil.sys
[2010/08/05 00:30:19 | 001,988,521 | -H– | M] () – C:\Users\USERNAME\AppData\Local\IconCache.db
[2010/08/05 00:27:00 | 000,000,472 | —- | M] () – C:\Windows\tasks\COMODO System Cleaner Update.job
[2010/08/05 00:26:32 | 000,001,112 | —- | M] () – C:\Users\Public\Desktop\COMODO System - Cleaner.lnk
[2010/08/05 00:03:25 | 000,002,985 | —- | M] () – C:\Users\USERNAME\Desktop\HiJackThis.lnk
[2010/08/04 14:04:19 | 000,218,464 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010/08/04 14:04:19 | 000,218,464 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010/08/02 03:15:11 | 000,001,573 | —- | M] () – C:\Users\USERNAME\Desktop\DivX Movies.lnk
[2010/08/02 03:14:56 | 000,001,112 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/08/02 03:14:37 | 000,001,152 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2010/07/30 10:52:21 | 000,002,340 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/07/30 10:52:21 | 000,002,239 | —- | M] () – C:\Users\USERNAME\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/28 18:21:06 | 062,698,084 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/28 02:48:06 | 002,816,354 | —- | M] () – C:\Users\USERNAME\corehound.png
[2010/07/28 02:23:53 | 000,001,003 | —- | M] () – C:\Users\USERNAME\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2010/07/27 09:24:09 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/27 08:42:23 | 000,001,033 | —- | M] () – C:\Users\USERNAME\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/07/27 08:42:23 | 000,001,009 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/27 07:04:29 | 000,000,120 | —- | M] () – C:\Users\USERNAME\AppData\Local\Egasu.dat
[2010/07/27 07:04:29 | 000,000,000 | —- | M] () – C:\Users\USERNAME\AppData\Local\Blejera.bin
[2010/07/27 07:02:59 | 000,000,150 | —- | M] () – C:\zrpt.xml
[2010/07/20 16:14:29 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/20 16:14:28 | 000,013,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\avgrssta.dll
[2010/07/20 16:13:59 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/20 05:06:18 | 000,000,199 | —- | M] () – C:\Users\USERNAME\Desktop\Alien Swarm.url
[2010/07/09 15:04:40 | 000,041,872 | —- | M] () – C:\Windows\SysWow64\xfcodec.dll
[2010/07/09 15:04:40 | 000,027,536 | —- | M] () – C:\Windows\SysNative\xfcodec64.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/05 00:26:36 | 000,000,472 | —- | C] () – C:\Windows\tasks\COMODO System Cleaner Update.job
[2010/08/05 00:26:32 | 000,001,112 | —- | C] () – C:\Users\Public\Desktop\COMODO System - Cleaner.lnk
[2010/08/05 00:03:25 | 000,002,985 | —- | C] () – C:\Users\USERNAME\Desktop\HiJackThis.lnk
[2010/08/02 03:15:11 | 000,001,573 | —- | C] () – C:\Users\USERNAME\Desktop\DivX Movies.lnk
[2010/08/02 03:14:56 | 000,001,112 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Player.lnk
[2010/08/02 03:14:37 | 000,001,152 | —- | C] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2010/07/28 02:48:06 | 002,816,354 | —- | C] () – C:\Users\USERNAME\corehound.png
[2010/07/27 09:24:09 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/07/27 08:42:23 | 000,001,033 | —- | C] () – C:\Users\USERNAME\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/07/27 08:42:23 | 000,001,009 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/27 07:02:59 | 000,000,150 | —- | C] () – C:\zrpt.xml
[2010/07/20 05:06:17 | 000,000,199 | —- | C] () – C:\Users\USERNAME\Desktop\Alien Swarm.url
[2010/07/09 15:04:40 | 000,041,872 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2010/07/09 15:04:40 | 000,027,536 | —- | C] () – C:\Windows\SysNative\xfcodec64.dll
[2010/06/16 11:35:42 | 000,007,168 | —- | C] () – C:\Windows\SysWow64\RTCore64.sys
[2010/02/25 21:28:12 | 000,000,122 | —- | C] () – C:\Windows\WA.INI
[2009/12/24 23:43:45 | 000,484,352 | —- | C] () – C:\Windows\SysWow64\lame_enc.dll
[2009/12/24 22:24:05 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2009/12/24 21:19:42 | 000,148,480 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/12/24 21:19:42 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/11/25 14:40:50 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/08/26 09:29:28 | 000,150,016 | —- | C] () – C:\Windows\SysWow64\OemSpiE.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/03/02 12:33:32 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/01/14 06:47:24 | 000,001,436 | —- | C] () – C:\Windows\CfgHPSp.ini
[2009/01/14 06:47:24 | 000,001,434 | —- | C] () – C:\Windows\Cfg05Sp.ini
[2009/01/14 06:47:24 | 000,001,434 | —- | C] () – C:\Windows\Cfg04Sp.ini
[2009/01/14 06:47:24 | 000,001,091 | —- | C] () – C:\Windows\Cfg03Sp.ini
[2009/01/14 06:47:24 | 000,001,091 | —- | C] () – C:\Windows\Cfg02Sp.ini
[2009/01/14 06:47:24 | 000,001,000 | —- | C] () – C:\Windows\Cfg01Sp.ini
[2009/01/14 06:47:24 | 000,000,932 | —- | C] () – C:\Windows\CfgHPHp.ini
[2009/01/14 06:47:24 | 000,000,932 | —- | C] () – C:\Windows\CfgHPDO.ini
[2009/01/14 06:47:24 | 000,000,932 | —- | C] () – C:\Windows\Cfg05DO.ini
[2009/01/14 06:47:24 | 000,000,932 | —- | C] () – C:\Windows\Cfg04DO.ini
[2009/01/14 06:47:24 | 000,000,930 | —- | C] () – C:\Windows\Cfg05Hp.ini
[2009/01/14 06:47:24 | 000,000,930 | —- | C] () – C:\Windows\Cfg04Hp.ini
[2009/01/14 06:47:24 | 000,000,818 | —- | C] () – C:\Windows\Cfg01APR.ini
[2009/01/14 06:47:24 | 000,000,725 | —- | C] () – C:\Windows\Cfg03Hp.ini
[2009/01/14 06:47:24 | 000,000,725 | —- | C] () – C:\Windows\Cfg03DO.ini
[2009/01/14 06:47:24 | 000,000,725 | —- | C] () – C:\Windows\Cfg02Hp.ini
[2009/01/14 06:47:24 | 000,000,725 | —- | C] () – C:\Windows\Cfg02DO.ini
[2009/01/14 06:47:24 | 000,000,725 | —- | C] () – C:\Windows\Cfg01Hp.ini
[2009/01/14 06:47:24 | 000,000,725 | —- | C] () – C:\Windows\Cfg01DO.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\CfgHPRMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\CfgHPRLI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\CfgHPFMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\CfgHPDI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg05RMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg05RLI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg05FMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg05DI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg04RMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg04RLI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg04FMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg04DI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg03RMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg03RLI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg03FMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg03DI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg02RMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg02RLI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg02FMi.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg02DI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg01Mic.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg01LI.ini
[2009/01/14 06:47:24 | 000,000,453 | —- | C] () – C:\Windows\Cfg01DI.ini

========== LOP Check ==========

[2010/02/10 20:44:03 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\Acoustica
[2010/02/10 21:09:02 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\Antares
[2010/06/05 18:11:54 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\AVG9
[2010/02/20 05:01:13 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\com.comcast.access.13A1FA90F0FC9DC009FB0956ADD0F13F8608561B.1
[2010/05/20 21:27:18 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\com.oxygenxml
[2010/02/25 21:01:10 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\DAEMON Tools Lite
[2010/05/06 10:59:00 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\GetRightToGo
[2010/01/16 10:22:33 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\gtk-2.0
[2010/01/16 20:17:07 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\SumatraPDF
[2010/05/18 16:10:00 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\uTorrent
[2010/03/27 08:25:29 | 000,000,000 | —D | M] – C:\Users\USERNAME\AppData\Roaming\Vivox
[2010/05/31 19:04:32 | 000,032,556 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/13 21:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/13 21:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/13 21:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/13 21:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 21:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 21:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/13 21:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/13 21:48:04 | 000,410,688 | —- | M] (Intel Corporation) MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/13 21:41:52 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=956D030D375F207B22FB111E06EF9C35 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\SysWOW64\netlogon.dll
[2009/07/13 21:16:02 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/13 21:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/13 21:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation) MD5=477DC4D6DEB99BE37084C9AC6D013DA1 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/13 21:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 21:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\SysWOW64\scecli.dll
[2009/07/13 21:16:13 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll
[2009/07/13 21:41:53 | 000,232,448 | —- | M] (Microsoft Corporation) MD5=398712DDDAEFB85EDF61DF6A07B65C79 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/08/29 02:59:32 | 011,406,336 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\SysWOW64\wmp.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >
< End of report >
Ok when I run GMER as admin the program comes up but it gives me an error C:\windows\system32\config\system: The system cannot find the file speficied. By default the only thing checked is services, registry, files (C:\), ADS Everything that isn't checked you can't check even I wanted to (just letting you know) I run scan the same error comes up but says the same thing as before accept changes the msg to "The process cannot access the file specified.." This time it's running a scan though. This is all it produced in the log. 1415T-CVH6R-WPF1V I just realised I didn't post both text files of the first program so I'll get on top of that. I've triple checked everything you wrote and I only get 1 text file from OTL.
Hello BillyJB

Please do not edit your posts as I do not receive e mail notification about it. Just start a new reply in the thread and I will get back to you when I can :)

Thank you for the logs.

Please work your way through the following steps. if you ewncounter any difficulties come back and let me know.


  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I can see evidence of uTorrent. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" and select "Control Panel".
    • Next, click on "Programs" and then on "Programs and Features".
    • Find the "uTorrent" program, click on it once and then click on the "Uninstall" button.
    • Follow any prompts you receive.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Please open OTL


    • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

      :OTL
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5643
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: jgyo0w = C:\Users\USERNAME\AppData\Local\Temp\19aqp.exe File not found
      O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell - "" = AutoRun
      O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
      O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell\directx\command - "" = F:\DirectX9\dxsetup.exe – File not found
      O33 - MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\Shell\setup\command - "" = F:\setup.exe – File not found
      O36 - AppCertDlls: drivsetx - (C:\Windows\system32\contDism.dll) - C:\Windows\SysWow64\contDism.dll File not found
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      
      :Files
      C:\Users\USERNAME\AppData\Local\Temp\19aqp.exe
      C:\Users\USERNAME\AppData\Local\pvlnflfey
      C:\Users\USERNAME\AppData\Local\Egasu.dat
      C:\Users\USERNAME\AppData\Local\Blejera.bin
      C:\zrpt.xml
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [start explorer]
      [Reboot]
    • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
    • Allow the program to run unhindered.
    • Your machine will re-start itself. This is normal.
    • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the OTL log and ther MBAM log in your next reply.

    Also, please let me know how your machine is behaving now and if you are still having problems.
All processes killed Error: Unable to interpret in the current context! ========== OTL ========== No active process named explorer.exe was found! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\jgyo0w deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. File F:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. File F:\DirectX9\dxsetup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0138ec2e-2272-11df-8b12-00044b153da5}\ not found. File F:\setup.exe not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\\drivsetx:C:\Windows\system32\contDism.dll deleted successfully. C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP\WiseCustomCalla.dll deleted successfully. C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP\WiseData.ini deleted successfully. C:\Windows\DEA314C409294250BC9298E4C105F28D.TMP folder deleted successfully. ========== FILES ========== File\Folder C:\Users\USERNAME\AppData\Local\Temp\19aqp.exe not found. C:\Users\USERNAME\AppData\Local\pvlnflfey folder moved successfully. C:\Users\USERNAME\AppData\Local\Egasu.dat moved successfully. C:\Users\USERNAME\AppData\Local\Blejera.bin moved successfully. C:\zrpt.xml moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: USERNAME ->Temp folder emptied: 578981 bytes ->Temporary Internet Files folder emptied: 248312 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 5910225 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 6.00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: USERNAME ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08062010_074417 Files\Folders moved on Reboot… C:\Users\USERNAME\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot… Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4397 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 8/6/2010 8:30:13 AM mbam-log-2010-08-06 (08-30-13).txt Scan type: Full scan (C:\|E:\|) Objects scanned: 285612 Time elapsed: 32 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello BillyJB

Thank you for the logs.

Please work your way through the following steps:


  • Please perform the following scan:


  • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.

  • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
  • DO NOT surf the net while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.

  • NOTES:
  • Before performing this online scan you must open your Internet Browser as Administrator. To do this, Right Click on your Internet Browser icon and select "Run as Administrator".
  • Once the scan is complete and you have saved the log produced, close your browser.
  • For all other browsing, open your browser by left clicking in the normal way.


  • Please perform a Kaspersky Online Scan of your computer by clicking here or here.


  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run (at times it may appear to stall).
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

  • Once the scan is complete, click on View scan report. To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
  • If you need help performing the above steps, an animated tutorial can be found here.

Please post the Kaspersky Online Scan log in your next reply.

Also, please let me know if you are still having problems <==== Very important
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, August 6, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, August 06, 2010 15:17:22 Records in database: 4134525 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 163520 Threats found: 3 Infected objects found: 3 Suspicious objects found: 0 Scan duration: 01:14:26 File name / Threat / Threats count C:\from cd\chris ledoux - greate~0068.wma Infected: Trojan-Downloader.WMA.Wimad.n 1 C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml Infected: Trojan.Win32.Clicker.hd 1 C:\sdf\Mixcraft 4.2\Acoustica-Mixcraft-4-Installer.exe Infected: Trojan.Win32.Pasta.dpb 1 Selected area has been scanned. I haven't been having any problems since I did my own scanning and quarantining. Between Avast, MBAM, superantispyware I found a lot of stuff when everything started acting weird after my girlfriend was attempting to watch an online streaming movie. It was a few days later maybe a week I noticed this new folder and when I researched some of the text in text files talking about cURL and some guy from a group called HAXX i decided to seek outside help as I do have some gaming accounts worth quit a bit that I don't play regularly and months could go by without noticing that they have been stolen. I immediately logged onto my linux system and started changing all my online passwords.
Hello BillyJB

Thank you for the log.

I immediately logged onto my linux system and started changing all my online passwords.

Changing your passwords regulary is always a good idea :thumbup:

The Kaspersky scan has detected a number of infected files on your system. We will take care of them in the steps below:


  • Please open OTL


  • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL (NOTE: Do NOT Copy and Paste the word "CODE").

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    
    :Files
    C:\from cd\chris ledoux - greate~0068.wma 
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml 
    C:\sdf\Mixcraft 4.2\Acoustica-Mixcraft-4-Installer.exe 
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]

  • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
  • Allow the program to run unhindered.
  • Your machine will re-start itself. This is normal.
  • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

Please post the OTL log from the fix, and a new OTL scan log in your next reply.
All processes killed ========== OTL ========== No active process named explorer.exe was found! ========== FILES ========== C:\from cd\chris ledoux - greate~0068.wma moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml moved successfully. C:\sdf\Mixcraft 4.2\Acoustica-Mixcraft-4-Installer.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: USERNAME ->Temp folder emptied: 106324783 bytes ->Temporary Internet Files folder emptied: 740580 bytes ->Java cache emptied: 128130 bytes ->FireFox cache emptied: 59069926 bytes ->Google Chrome cache emptied: 337400052 bytes ->Flash cache emptied: 18764 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 65748 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 480.00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: USERNAME ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08072010_112443 Files\Folders moved on Reboot… C:\Users\USERNAME\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot…
Hello BillyJB

Thank you for the log.

Provided you are no longer having any issues I think we are almost done :)

Please work your way through the following steps:


  • Please perform the following cleanup procedure


    • Double click on the OTL.exe icon on your desktop to run the program. (Note: If you are running Vista/Windows 7, right-click on the file and choose Run As Administrator).
    • Once OT has opened, click on the "CleanUp!" button.
    • Follow any prompts that you receive.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
I appreciate the time you took to help me with my troubles. I might have been responsible for one of those infected files lol shhhh. In any case see you next time I let my G/F on the computer again! lol Thank you, Billy!

I appreciate the time you took to help me with my troubles.

You are Very Welcome BillyJB.

I might have been responsible for one of those infected files lol shhhh. In any case see you next time I let my G/F on the computer again! lol

:D I would'nt want to be in your shoes if she finds this thread!

Best wishes
JonTom
Since this problem appears to be resolved this topic is now closed. Glad we could help :) If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic. Best wishes JonTom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI